Privacy Policy
Effective date: 25 June 2026
1. Who we are
Polyradar is operated by Matto (sole proprietor), Italy. Data controller contact: [email protected]
2. Data we collect
From you directly
- Account: email, hashed password (bcrypt), display name
- Wallet (optional): Polygon funder address, private key (AES-256 encrypted at rest; never logged in plaintext)
- Strategies: parameters and filters you configure
- Payment: handled entirely by Stripe; we receive only customer ID and subscription status (no card data)
Automatically
- Usage logs: page views, API calls, trades placed (server-side)
- IP address: for rate limiting and abuse prevention (stored max 90 days)
- Cookies: see our Cookie Policy at /legal/cookie
3. Legal basis (GDPR)
- Contract performance: providing the Service
- Legitimate interest: security, fraud prevention, service improvement
- Consent: marketing emails (opt-in)
- Legal obligation: tax records (kept 10 years per Italian law)
4. Sub-processors
We share data only with these providers, all bound by data processing agreements:
- Stripe (payments) — Ireland
- Railway (frontend + backend hosting) — USA
- Cloudflare (CDN / DNS proxy) — USA, global edge
- Resend (transactional email) — USA
- Polymarket (when you opt into real trading) — USA
5. Your rights (GDPR)
You have the right to:
- Access: request a copy of your data
- Rectify: correct inaccurate data
- Erase: request deletion ("right to be forgotten")
- Restrict: limit processing
- Portability: receive data in machine-readable format
- Object: object to processing based on legitimate interest
- Complain: to your national data protection authority (in Italy: Garante Privacy)
Exercise your rights: [email protected]. We respond within 30 days.
6. Data retention
- Account data: until deletion, +30 days
- Trading history: 10 years (tax/audit)
- Logs: 90 days
- Backups: 7 days
7. Security
- TLS/HTTPS on all traffic
- Passwords hashed with bcrypt (10 rounds)
- Private keys encrypted with AES-256-CBC, decrypted only in isolated worker threads
- JWT auth tokens, 7-day expiry
- Rate limiting + CSRF protection
- Regular security audits
8. International transfers
Some sub-processors operate outside the EU/EEA. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for these transfers.
9. Changes
We notify material changes 30 days in advance via email.