# Privacy Policy — ZeroAlgo **Effective**: To be set on go-live **Version**: 2025-05 **Operator**: To be filled in (Sole Proprietor / LLP / Pvt Ltd name + GST/PAN) This policy describes how ZeroAlgo ("we", "the platform") collects, uses, and protects your personal data in compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act). ## 1. What we collect | Category | Examples | Why we collect it | |---|---|---| | Identity | Email, display name, password (hashed) | Account creation and login | | Broker integration | Zerodha API key, API secret, daily access token | To execute the trades you instruct the platform to make on YOUR Zerodha account. **Stored encrypted at rest** with a key the platform operator controls. | | Trading activity | Orders, fills, positions, strategy parameters, backtest history | Core product functionality | | Communication preferences | Telegram chat ID, enabled flag | Sending you trade alerts you opt into | | Technical | IP address, browser user-agent, login timestamps | Security (detect compromised accounts) | | Subscription / billing | Plan tier, payment dates, GST invoice details | Billing and compliance | ## 2. What we do NOT collect - Your Zerodha login password (you log in directly with Zerodha; we never see it) - Bank account numbers, card numbers, or UPI IDs (Razorpay handles billing; we receive only payment confirmations) - Your trading at brokers other than Zerodha - Your personal financial worth, PAN, Aadhaar, or KYC documents ## 3. How we use your data - **Provide the service**: run your strategies, store your trade history, show your P&L - **Account security**: detect unusual logins, alert you to suspicious activity - **Service operations**: send transactional emails (verification, billing receipts), platform alerts you've opted into - **Legal**: respond to government / SEBI requests where legally required We do **NOT**: - Sell your data to anyone - Share your trading strategy parameters with other users or third parties - Use your data to train AI models without explicit, separate opt-in - Run ads on the platform ## 4. Where your data lives - **Application database** (SQLite on AWS Mumbai region) — for your trade history, strategies, account - **Encrypted broker credentials** (same database, encrypted with a key controlled by the platform operator) - **Backups** (Backblaze B2, encrypted in transit and at rest) - **Telegram message history** (in Telegram's infrastructure, governed by Telegram's own policy) All servers are hosted in India (AWS Mumbai region) by default. We do not transfer data outside India. ## 5. Your rights under DPDP You can exercise these rights at any time via the dashboard or by emailing the contact below: | Right | How to exercise | |---|---| | **Access** your data | Dashboard → Settings → Privacy → Download my data (`/api/privacy/export`) | | **Correct** inaccurate data | Dashboard → Settings (edit display name etc.); email for anything else | | **Erase** your data | Dashboard → Settings → Delete account (initiates a 30-day grace period before permanent deletion) | | **Withdraw consent** | Logging out is not consent withdrawal; use the Delete flow. We will stop processing your data within 7 days and complete deletion within 30 days. | | **Grievance** | Email `grievance@` | ## 6. Data retention - **Account data**: kept while your account is active - **Trade history**: kept for 7 years (matches Zerodha's regulatory retention) - **Logs**: 90 days - **Backups**: rolling 90 days - **After account deletion**: 30-day grace period (so accidental deletions can be reversed), then permanent erasure. Financial records that we are legally required to retain (audit trail of trades) are anonymized — the trade rows stay, your identifying data is wiped. ## 7. Security - Passwords hashed with bcrypt (industry standard) - Broker credentials encrypted at rest with Fernet (transitioning to AWS KMS in production) - HTTPS-only access via Cloudflare - 2FA required on operator accounts that access production - Daily backups, monthly restore drills We will notify you within 72 hours of becoming aware of any data breach affecting your data (DPDP Section 8(6)). ## 8. Cookies We use one cookie: a session cookie carrying your signed JWT after login. - HttpOnly (not accessible to JavaScript) - Secure (HTTPS only) - SameSite=Lax (CSRF protection) - Expires 7 days after issue No third-party trackers, no analytics cookies, no ad cookies. ## 9. Children Algo trading is restricted to adults (18+) with a Zerodha account, which itself enforces KYC. We do not knowingly accept accounts from minors. ## 10. Changes to this policy We will email you 7 days before any material change to this policy. Continued use after that date constitutes acceptance. ## 11. Contact | Purpose | Contact | |---|---| | Privacy questions | `privacy@` | | Grievance officer (DPDP) | `grievance@` | | Security disclosure | `security@` | | General support | `support@` | --- *This policy is provided as a starting template. Have it reviewed by an Indian lawyer specializing in technology/fintech before going live with paying customers.*