Verstige LogoVERSTIGE
TradingEcosystemPartnersUpdates
LoginGet Started
VERSTIGETermsTrading DisclaimerSupport

Privacy Policy

Effective: August 30, 2026 ยท Last updated: August 30, 2026 ยท Verstige Marketing and Technology

1. Introduction

Verstige Marketing and Technology ("Verstige," "we," "us," or "our") operates the Verstige trading platform, accessible via verstige.io and through our mobile applications on iOS and Android (the "Platform"). This Privacy Policy explains what data we collect, how we use it, when we share it, and what choices you have. By using the Platform, you agree to the practices described here.

This policy applies to all users worldwide, including users in the European Economic Area, the United Kingdom, and California. Where local law provides additional rights, those rights apply in addition to what is described below.

2. Information We Collect

Account information. When you create an account we collect your name, email address, optional profile photo (avatar), optional bio, and authentication credentials. Authentication is provided by Supabase; we never see or store your password in plaintext.

Trading activity. When you place trades through the Platform (either in demo mode or through a connected brokerage account), we record the trade signal, entry price, exit price, side, quantity, instrument symbol, timestamps, and realized profit or loss. This is product core data โ€” we use it to compute your account history, OS points, and leaderboard rank.

Connected brokerage data. If you connect a brokerage account (TradeLocker, DXTrade, or others), we receive only the access token and account ID needed to fetch your account balance, equity, open positions, and trade history on your behalf. We do not see or store your brokerage password.

Social activity. Messages you send in the Community tab, leaderboard rank, public profile fields, and engagement metrics (likes, reactions) are stored on our infrastructure.

Payment data. If you subscribe to a paid product, payment is processed by Stripe. We receive the subscription ID, plan tier, and last 4 digits of your card โ€” never the full card number. Card data is held by Stripe under their own privacy policy.

Device and usage data. We collect IP address, user agent string, approximate geographic region (city / country), platform type (web, iOS app, Android app), and aggregate usage telemetry. We do not collect advertising identifiers (IDFA, GAID) for cross-app tracking.

Cookies and local storage. We use essential cookies and localStorage for authentication, language preference, and theme preference. We do not use third-party advertising cookies.

3. How We Use Your Information

  • Provide, operate, and maintain the Platform and its features
  • Authenticate your account and process logins across web and mobile
  • Compute your OS points ledger, leaderboard rank, and trade journal
  • Connect to your brokerage on your behalf when you explicitly authorize it, solely to display the data you have asked us to show
  • Process subscription payments via Stripe and send related billing communications
  • Send service notifications, security alerts, and platform updates (you can opt out of marketing messages at any time)
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations and respond to lawful requests
  • Improve product quality through aggregated, de-identified analytics

4. Legal Basis for Processing (GDPR / UK GDPR)

If you are in the European Economic Area or the United Kingdom, our legal basis for processing your data under the General Data Protection Regulation is:

  • Contract โ€” to provide the Platform you've signed up for
  • Legitimate interest โ€” to prevent fraud, secure the Platform, and improve features
  • Consent โ€” for marketing communications and optional data sharing (e.g. connecting a brokerage)
  • Legal obligation โ€” to comply with financial record-keeping and tax laws

5. Information Sharing

We do not sell, trade, or rent your personal information. We share data only with these limited parties:

  • Supabase (auth + Postgres + realtime) โ€” hosts authentication, profile data, trading data, and social activity. supabase.com/privacy
  • Stripe (payments) โ€” processes subscription payments and stores the associated billing data. stripe.com/privacy
  • Cloud hosting providers โ€” the Platform runs on cloud infrastructure (e.g. Railway, Vercel, AWS). These providers are bound by data processing agreements.
  • Connected brokerage providers โ€” when you authorize a connection, your data flows between the brokerage and our Platform per that provider's terms (e.g. TradeLocker).
  • Email service providers (Resend) โ€” for transactional emails (signup confirmation, password reset, important account notices).
  • Analytics โ€” aggregated, de-identified analytics may be processed by third-party analytics providers. We do not share raw personal data with analytics services.
  • Legal โ€” when required by valid law, court order, or to protect the safety, rights, or property of Verstige or others.
  • Business transfers โ€” in connection with a merger, acquisition, or sale of assets, with prior notice to affected users.

6. International Data Transfers

Verstige is operated from the United States. By using the Platform, you understand that your data may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. We rely on Standard Contractual Clauses and equivalent safeguards to protect international transfers, where required by applicable law.

7. Data Retention

We retain different categories of data for different periods:

  • Account data: for the life of your account plus up to 30 days after deletion to allow recovery. After that, your account row is removed from our primary databases.
  • Trade history: 7 years per financial record-keeping requirements. After this period, trade rows are anonymized for aggregate analytics.
  • OS points ledger: for the life of your account. Reset only if the entire account is deleted.
  • Support emails: 3 years from last contact.
  • Server logs: 90 days.
  • Backup snapshots: 90 days, then permanently deleted.

8. Your Rights

You have the following rights regarding your personal data. To exercise any of these, use the in-app controls or email us at the address in the Contact section below.

  • Access: request a copy of the personal data we hold about you
  • Correction: correct inaccurate or incomplete data โ€” most fields are editable from your Settings page
  • Deletion: delete your account and all associated personal data via Settings โ†’ Delete account, or by emailing us
  • Export: export your trade history, OS points ledger, and profile data in JSON or CSV format
  • Restriction: ask us to pause processing while a dispute is being resolved
  • Portability: take your data to another service (GDPR right to data portability)
  • Object: object to processing based on legitimate interest
  • Withdraw consent: at any time, where processing is based on consent
  • Lodge a complaint: with your local data protection authority (e.g. the ICO in the UK, a CNIL in France, the FTC in the US)

We respond to verified requests within 30 days. If we need more time, we will tell you why and how much more time we need.

9. California-Specific Rights (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:

  • Right to know what personal information we collect, share, and sell โ€” see Sections 2 and 5 above
  • Right to delete โ€” see Section 8
  • Right to opt out of the sale or sharing of personal information โ€” we do not sell personal information
  • Right to non-discrimination for exercising your rights
  • Right to limit the use of sensitive personal information โ€” we do not collect sensitive personal information as defined by the CPRA

California residents may exercise these rights by emailing us at the address below. We will not discriminate against you for exercising any of these rights.

10. Children's Privacy

The Platform is not directed to children under 18 (or under 13 in the United States under COPPA). We do not knowingly collect personal information from anyone under these ages. If we learn that we have collected data from a child, we will delete it as soon as possible. If you believe a child has created an account, please contact us at the address below.

11. Security

We implement industry-standard safeguards to protect your data, including:

  • TLS 1.2+ for all data in transit
  • Encryption at rest for all production databases
  • OAuth 2.0 authentication via Supabase โ€” passwords are hashed and never stored in plaintext
  • Row-level security (RLS) policies on every Supabase table so users can only read their own data
  • Role-based access control (RBAC) for our team โ€” production data access is limited to engineers on a need-to-know basis with audit logs
  • Regular third-party security scans and penetration tests

No system is perfectly secure. You are responsible for keeping your own account credentials confidential, using a strong unique password, and signing out of shared devices.

12. Automated Decision-Making and Profiling

The Platform uses automated systems to compute your OS points tier, leaderboard rank, and trade journal analytics. These systems do not produce legal effects or otherwise significantly affect you โ€” they are informational only. We do not use automated systems for credit decisions, employment, or housing.

If you believe an automated decision has incorrectly affected you, you have the right to request human review.

13. Third-Party Services and Links

The Platform may contain links to third-party websites, brokerage platforms, or partner services that we do not operate. We are not responsible for the privacy practices of those services. We encourage you to read their privacy policies before sharing personal information with them.

Connected brokerage providers (TradeLocker, DXTrade, and others) have their own privacy policies that govern the data flowing through their APIs. We do not control what those providers do with the data you send them directly.

14. Do Not Track

We honor Do Not Track (DNT) and Global Privacy Control (GPC) signals. If your browser sends a DNT or GPC header, we treat it as a request to opt out of any non-essential tracking or analytics. We do not track users across other apps or websites, so this opt-out has limited practical effect, but we honor it nonetheless.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will:

  • Update the "Last updated" date at the top of this page
  • For material changes, notify you via email or an in-app banner at least 30 days before the change takes effect
  • For minor changes, post the updated policy on this page

Continued use of the Platform after a material change constitutes acceptance of the updated policy. If you do not agree to a material change, you may delete your account before the change takes effect.

16. Contact

For questions, requests, or complaints about this Privacy Policy or how your data is handled, contact:

Verstige Marketing and Technology โ€” Privacy Team
Email: support@verstige.io
Response time: within 30 days

EU/UK representative and Data Protection Officer details can be added here once we establish those roles. Until then, please use the email above.

17. Account Deletion

You can delete your account and all associated personal data at any time:

  • In-app: Settings โ†’ Delete account (Apple App Store Review Guideline 5.1.1 compliance path)
  • By email: send a deletion request to support@verstige.io from the email address on your account

Deletion is permanent. We will delete your profile, trade history, OS points, social messages, and authentication credentials. Some data may be retained in anonymized form for aggregate analytics, and trade records may be retained for up to 7 years per financial record-keeping laws. See Section 7 for full retention details.