This Privacy Policy explains what personal information Unattached Limited ("PolyQuantLab", "we", "us") collects when you use www.polyquantlab.com and the related services (the "Service"), how we use it, who we share it with, and the rights you have over it.
Short version: we collect as little as we can to operate the Service. We don't sell your data. We don't run third-party advertising trackers. Payments are handled by Stripe; we never see or store your card details.
1. Information we collect
1.1 Account information
- Email address — supplied when you sign up via Supabase Auth. Used to identify your account, send transactional messages (signup confirmation, magic-link sign-in, billing receipts, security notices), and respond to support requests.
- Authentication credentials — managed by Supabase; we do not store your password.
1.2 Billing information
- Stripe customer ID, subscription tier, and billing status — we receive these from Stripe via signed webhooks so we can gate features by tier.
- We never see or store your full credit-card number, CVC, or bank details. All payment data is collected and stored by Stripe under their PCI-DSS Level 1 compliance.
1.3 Product usage data
- API usage counters — request counts per key, kept in Redis for rate-limiting and tier-limit enforcement. These are pseudonymous (tied to your API key, not your person).
- Saved strategies, backtests, paper-trading runs, registered webhooks — content you explicitly create in the dashboard. Stored to provide the feature; deleted when you delete them.
- Server logs — IP address, user-agent, timestamp, path, and response code for each request to the API or dashboard. Retained for up to 30 days for abuse prevention, debugging, and security investigation, then rotated out.
1.4 Cookies and similar technologies
- Authentication cookies set by Supabase to keep you signed in. Strictly necessary; the Service does not work without them.
- Theme preference (light/dark) stored in localStorage so the UI doesn't flash on reload.
- Microsoft Clarity analytics. Anonymous behavioural analytics — heatmaps, click counts, scroll depth, and aggregated session replay so we can see where our UI confuses people. Clarity assigns a first-party session identifier but does not link sessions across different sites. We have IP masking and personal-data masking enabled in the Clarity dashboard so form inputs, email addresses, and other PII are never recorded.
- Google Analytics 4. Aggregate pageview, session, and conversion-funnel statistics. GA sets a first-party
_gacookie that identifies your browser as the same browser across visits to polyquantlab.com, and Google can in theory associate that cookie with a Google identity if you are signed in to a Google product. We do not pass any personal identifiers (email, user ID, etc.) into GA — only anonymous event counts. - We do not use advertising tracking pixels (Facebook Pixel, Reddit Pixel, etc.), browser fingerprinting, or any technique to identify the same user across unrelated third-party websites.
1.5 Email
Outbound transactional email (signup confirmation, magic link, billing receipts, optional product updates) is sent through Supabase's configured email provider. Marketing email is opt-in only and you can unsubscribe in every message.
2. How we use the information
- Provide, maintain, and improve the Service.
- Authenticate you, gate features by tier, and enforce rate limits.
- Process subscription payments via Stripe and send billing receipts.
- Detect, prevent, and respond to abuse, fraud, security incidents, and breaches of our Terms.
- Send important transactional messages about your account (e.g. payment failure, password reset).
- Comply with legal obligations.
3. Who we share data with (sub-processors)
We rely on a small number of third-party providers to deliver the Service. Each is contractually bound to use your data only on our instructions and to maintain appropriate security measures.
- Supabase — authentication and email delivery.
- Stripe — payment processing, customer portal, subscription billing.
- Vercel — hosts the marketing site and dashboard frontend.
- Hetzner — hosts the API, worker processes, and databases (EU data center).
- Cloudflare — DNS, TLS termination, and edge caching for the API and docs.
- Sentry — error monitoring on the dashboard. Captures stack traces and the URL where an error occurred. We scrub email addresses and authentication tokens from error payloads before they leave the browser.
- Microsoft Clarity — anonymous behavioural analytics (heatmaps, scroll depth, masked session replay). IP masking and PII masking are enabled in the Clarity dashboard. Data is retained by Microsoft for up to 13 months and used only to render the analytics dashboards described above.
- Google Analytics 4 — aggregate pageview and conversion-funnel reporting. Standard GA4 retention (14 months) applies. We do not pass any personal identifiers into GA; we only see aggregate counts in the dashboard.
We do not sell, rent, or trade your personal information to third parties for advertising or marketing purposes.
4. Legal disclosure
We may disclose information if required to do so by law, by court order, or by a binding government request, or if disclosure is necessary to investigate fraud, protect our rights, or protect the safety of any person. Where we are permitted to do so, we will notify you before disclosing.
5. Data retention
- Account, subscription, and dashboard-created content (strategies, backtests, webhooks, paper trading runs): retained while your account is active.
- Server logs: up to 30 days, then automatically rotated.
- Stripe billing records and tax-relevant data: as long as required by applicable tax and accounting law (typically 6+ years).
- On account deletion: account email, dashboard-created content, and API keys are removed within 30 days. Stripe billing records and minimal anti-abuse records may be retained as required by law.
6. Security
We use TLS for all data in transit, secrets stored in environment variables (not in source control), HMAC-signed webhooks, and hashed API key storage. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you and the relevant authorities within the timeframes required by applicable law.
7. International transfers
Our infrastructure is hosted primarily in the EU (Hetzner Nuremberg). Some sub-processors (Stripe, Sentry, Cloudflare, Microsoft Clarity, Google Analytics, Vercel) operate globally and may process data outside the EEA. We rely on Standard Contractual Clauses or equivalent mechanisms for these transfers where required.
8. Your rights
Depending on where you live (GDPR in the EU/UK, CCPA in California, and similar laws elsewhere), you have rights including:
- Access — request a copy of the data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your account and associated data, subject to the retention exceptions in §5.
- Portability — receive your data in a machine-readable format.
- Objection / restriction — limit how we process your data.
- Withdraw consent for any processing based on consent (currently this only covers optional marketing email).
To exercise any of these, email contact@polyquantlab.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
9. Children
The Service is not intended for users under 18. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with information, please email us and we will delete it.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated by email and/or a notice in the dashboard at least 14 days before they take effect.
11. Contact
Questions about this Policy or our data practices? Email contact@polyquantlab.com.
Governed by the laws of Singapore; see the Terms of Service for full governing-law and dispute-resolution terms.