Privacy Policy

Effective date: 25 June 2026

1. Who we are

Polyradar is operated by Matto (sole proprietor), Italy. Data controller contact: [email protected]

2. Data we collect

From you directly

  • Account: email, hashed password (bcrypt), display name
  • Wallet (optional): Polygon funder address, private key (AES-256 encrypted at rest; never logged in plaintext)
  • Strategies: parameters and filters you configure
  • Payment: handled entirely by Stripe; we receive only customer ID and subscription status (no card data)

Automatically

  • Usage logs: page views, API calls, trades placed (server-side)
  • IP address: for rate limiting and abuse prevention (stored max 90 days)
  • Cookies: see our Cookie Policy at /legal/cookie

3. Legal basis (GDPR)

  • Contract performance: providing the Service
  • Legitimate interest: security, fraud prevention, service improvement
  • Consent: marketing emails (opt-in)
  • Legal obligation: tax records (kept 10 years per Italian law)

4. Sub-processors

We share data only with these providers, all bound by data processing agreements:

  • Stripe (payments) — Ireland
  • Railway (frontend + backend hosting) — USA
  • Cloudflare (CDN / DNS proxy) — USA, global edge
  • Resend (transactional email) — USA
  • Polymarket (when you opt into real trading) — USA

5. Your rights (GDPR)

You have the right to:

  • Access: request a copy of your data
  • Rectify: correct inaccurate data
  • Erase: request deletion ("right to be forgotten")
  • Restrict: limit processing
  • Portability: receive data in machine-readable format
  • Object: object to processing based on legitimate interest
  • Complain: to your national data protection authority (in Italy: Garante Privacy)

Exercise your rights: [email protected]. We respond within 30 days.

6. Data retention

  • Account data: until deletion, +30 days
  • Trading history: 10 years (tax/audit)
  • Logs: 90 days
  • Backups: 7 days

7. Security

  • TLS/HTTPS on all traffic
  • Passwords hashed with bcrypt (10 rounds)
  • Private keys encrypted with AES-256-CBC, decrypted only in isolated worker threads
  • JWT auth tokens, 7-day expiry
  • Rate limiting + CSRF protection
  • Regular security audits

8. International transfers

Some sub-processors operate outside the EU/EEA. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for these transfers.

9. Changes

We notify material changes 30 days in advance via email.

10. Contact

[email protected]