Privacy Policy

This beta privacy notice explains the types of data OrderFabric may process to provide trading operations workflows.

Version: privacy-2026-07-19Effective: July 19, 2026

Data We Process

OrderFabric may process account profile data, broker connection metadata, encrypted OAuth tokens, strategy settings, TradingView webhook payloads, signals, approvals, orders, audit events, and performance records.

OAuth tokens and sensitive broker credentials should be stored encrypted at rest and used only for authorized broker workflows.

Webhook payloads and approval records may include trading symbols, prices, indicators, model scores, user settings, broker account identifiers, and timestamps.

How Data Is Used

Data is used to authenticate users, connect broker accounts, receive signals, evaluate risk settings, create approval requests, submit approved orders, reconcile broker state, and provide audit history.

OrderFabric may use aggregated, de-identified, or customer-authorized operational data to improve reliability, model evaluation, and continuous-learning workflows.

Customer-specific trading data should not be used for model training outside the app's guarded learning process unless the customer has authorized that use or the data has been de-identified according to applicable requirements.

Model-learning contribution is off by default. When enabled, only eligible completed outcomes may enter the pseudonymized, filtered candidate dataset; disabling it stops future collection and does not change trading or approval settings.

Security

Access to customer workflows should be restricted by role and authenticated sessions.

Users should protect their login credentials and review broker permissions before approving a connection.

Third Parties

Broker connections, market data providers, email/SMS/push providers, and AI providers may process data needed to perform their services.

Users should review the policies and permissions of connected brokers and third-party services before authorizing access.

AI providers may receive signal context or decision-support data when AI analysis is enabled. Do not put unnecessary sensitive personal information into TradingView alert payloads.

User Choices

Users can choose paper or live mode, adjust strategy settings, disable subscriptions, disconnect broker permissions through the broker, and request export, deletion, or correction of account information from Profile where applicable.

An authenticated customer data export is generated from explicit field allowlists. Password and MFA secrets, session credentials, OAuth state and access credentials, encrypted broker credentials, TradingView webhook credentials, push endpoint credentials, and internal administrator or security notes are excluded.

A deletion request immediately pauses enabled trading routes and starts a reviewed removal or anonymization process. Audit-critical, trading, financial, security, and compliance records may be retained or anonymized under the applicable retention policy.

Profile corrections are limited to full name and phone data and require reviewed identity verification before application. Sign-in email changes use a separate support and account-security workflow.

Users can also disable notification preferences, rotate TradingView webhook credentials, use the kill switch, and disconnect broker OAuth access from the broker account portal.