Privacy Policy

1. Overview

We collect the minimum data needed to connect your accounts, route the orders you initiate, enforce regional and risk controls, and keep an auditable record of activity. Our position is simple: we connect, route, and govern the instructions you make — we do not custody money or assets, do not make trading decisions for you, and do not use your orders or strategies for proprietary trading or to train models.

2. What we collect

  • Account data — name, email, organisation, and billing details.
  • Connectivity data — venue/broker credentials and tokens (encrypted at rest), region preferences, and IP allowlists.
  • Eligibility & location signals — see Section 3.
  • Order & instruction data — order parameters, fills, positions, and the audit record of each instruction (see Section 6).
  • Telemetry — request logs, latency traces, error rates, connection-health events, and platform metrics needed to operate, secure, and audit the Service.
  • Support content — messages, screenshots, or sample payloads you send to our support channels.

We do not require government identity documents, proof of address, or source-of-funds for self-serve sign-up. Where a feature, partner, or law requires identity verification, we will tell you before collecting it.

3. Eligibility, location & compliance data

To decide which features are available to you — in particular live order routing — and to meet our legal and sanctions obligations, we process:

  • Location signals: declared country of residence, billing country, payment country, phone-number country, and the country inferred from your IP address.
  • Customer type: individual or organisation, and self-serve or partner-onboarded.
  • Account facts: your attestation that you own or are authorised to control a connected account, and whether the venue permits third-party access.
  • Screening: checks against sanctions and restricted-party lists.

We use these signals to apply regional availability (for example, live order routing is not offered in mainland China, Hong Kong, or Macau), to prevent prohibited use, and to keep an evidence record of each eligibility decision (decision identifier, policy version, the fields evaluated, the outcome, and a reason code). Wherever possible we keep country codes, risk flags, and decision reasons rather than collecting identity documents.

4. How we use data

We use data to: authenticate you and your API keys; connect your accounts and route the orders you or your automation initiate; determine feature eligibility and enforce regional, permission, and risk controls; operate, secure, debug, and audit the Service; provide support; and handle billing. We do not build advertising profiles, and we do not sell personal data.

5. Legal bases

Where data-protection law applies, we rely on: performance of our contract with you (providing the Service); our legitimate interests (security, fraud and abuse prevention, eligibility enforcement, and service improvement); compliance with legal obligations (including sanctions screening and record-keeping); and your consent where specifically requested (such as non-essential communications).

6. Order, instruction & audit records

Order parameters, fills, positions, and PnL pass through MarketCortex as part of the Service. For each instruction — including those generated by your scripts, webhooks, or AI agents — we keep an audit record such as an instruction identifier, the account and API-key identifiers, the parameters, the permission and risk decision, and the venue's response. These records exist to operate, secure, and audit the Service and to support disputes. We do not use the substance of your orders or strategies for proprietary trading or to train models.

7. How we share

We share data only as needed to run the Service:

  • Venues and brokers you connect to — the orders, fills, and account-level limits required to act on your accounts.
  • Payment processor — billing details only, to take payment (our payment processor acts as merchant of record for card processing).
  • Infrastructure and tooling sub-processors — hosting, logging, and support tools, under data-processing agreements.

We do not sell your data. Disclosure to law enforcement requires a valid legal request, and we will notify you unless prohibited by law.

8. International transfers

Our infrastructure is operated in Singapore. By using the Service you accept that your data may be processed there. Where we transfer personal data across borders, we use the safeguards required by applicable law. Customers on FABRIC may pin processing to a specific region under contract.

9. Retention

  • Operational logs: 90 days.
  • Order, instruction, and audit records: 24 months from the instruction date, then deleted or anonymised.
  • Eligibility and sanctions-screening decision records: up to 5 years, kept in minimised form (country codes, risk flags, and reason codes).
  • Billing and tax records: 7 years, as required by company-law record-keeping rules.
  • Account data: while your account is active and for 12 months after closure, unless law requires longer.

10. Security

We encrypt data at rest and in transit using current industry-standard algorithms (AES-256 at rest, TLS 1.3+ in transit). Venue and broker credentials are encrypted with dedicated keys and isolated from general application data. Access to production systems is restricted on a least-privilege basis, requires multi-factor authentication, and is logged and audited. No system is perfectly secure, and you are responsible for protecting your own credentials and API keys.

11. Your rights

Subject to your local law, you may request access to, correction of, or deletion of your personal data; object to or restrict certain processing; and, where applicable, request a copy in a portable format. Email privacy@marketcortex.io from your account-owner address; we respond within 30 days. If you are in a region with a data-protection authority, you also have the right to complain to it.

12. Cookies

We use only first-party cookies — for sign-in, CSRF protection, and language preference. We do not use cookies for advertising or cross-site tracking. Our payment processor may set its own cookies when you make a payment, governed by its policy.

13. Children's data

The Service is not directed to anyone under 18. We do not knowingly collect data from minors. If you believe a minor's data has been provided to us, contact privacy@marketcortex.io and we will delete it.

14. Changes

Material changes to this policy will be announced at least 30 days in advance by email and an in-console banner. Minor edits are reflected in the Last updated date above.

15. Contact

Privacy questions: privacy@marketcortex.io.