Orbyx

Privacy Policy

Last updated: March 5, 2026

1. Introduction

ORBYX ("we", "us", "our", or the "Platform") is a cryptocurrency trading analysis and execution platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website, services, APIs, and related applications (collectively, the "Services").

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of the Services immediately.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address, username, and password hash when you create an account.
  • Profile Information: Display name, preferred language, timezone, and notification preferences.
  • API Keys: Encrypted exchange API keys and secrets you provide for trading functionality. These are stored using AES-256 encryption at rest.
  • Agreement Records: Timestamps, IP addresses, and signatures when you accept Terms of Service or other agreements.
  • Support Communications: Messages, attachments, and metadata from support tickets.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, analysis requests, backtest runs, and strategy configurations.
  • Device & Browser Information: Browser type, operating system, screen resolution, and device identifiers.
  • IP Address: Collected for security, fraud prevention, and agreement signing records.
  • Cookies & Local Storage: Authentication tokens, UI preferences, and session data.

2.3 Information from Third Parties

  • Telegram: If you link a Telegram account, we receive your Telegram user ID, first name, and username.
  • Cryptocurrency Exchanges: Market data, order history, and position information retrieved via your API keys.
  • Payment Processors: Transaction confirmation details for subscription payments (we do not store full payment credentials).

3. How We Use Your Information

  • Provide, maintain, and improve the Services.
  • Process trading signals, backtests, and strategy matching.
  • Execute trades on your behalf through connected exchange APIs.
  • Send transactional notifications (trade proposals, position updates, alerts).
  • Respond to support requests and communicate with you.
  • Detect, prevent, and address security issues and fraud.
  • Enforce our Terms of Service and other agreements.
  • Analyze platform usage to improve features and user experience.
  • Comply with legal obligations and regulatory requirements.

4. How We Share Your Information

We do not sell your personal information. We may share data in these limited cases:

  • Exchange APIs: Your API keys are used to communicate with exchanges on your behalf. We transmit only the data necessary to execute your trades.
  • Infrastructure Providers: We use DigitalOcean for hosting and Supabase for authentication. These providers process data under contractual data processing agreements.
  • Legal Requirements: We may disclose information if required by law, legal process, or governmental request.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.

5. Data Security

We implement industry-standard security measures including:

  • AES-256 encryption for API keys stored at rest.
  • TLS 1.2+ encryption for all data in transit.
  • JWT-based authentication with short-lived access tokens.
  • Row-Level Security (RLS) policies in our database.
  • Regular security audits and dependency updates.
  • IP-based rate limiting and abuse detection.

While we strive to protect your data, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and exchange API keys.

6. Data Retention

  • Account Data: Retained for as long as your account is active. Deleted within 30 days of account deletion request.
  • Trading History: Retained for the duration of your account plus 90 days for audit purposes.
  • Agreement Records: Retained indefinitely for legal compliance and audit trail.
  • Server Logs: Automatically purged after 90 days.
  • Backtest Results: Retained for the duration of your account.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate personal data.
  • Erasure: Request deletion of your personal data, subject to legal retention requirements.
  • Data Portability: Receive your data in a structured, machine-readable format.
  • Withdrawal of Consent: Withdraw consent for data processing at any time (this may limit your ability to use certain features).
  • Objection: Object to processing based on legitimate interests.

To exercise any of these rights, please contact us at [email protected] or submit a request through our support page.

8. Cookies & Tracking Technologies

We use the following types of cookies and local storage:

  • Essential: Authentication tokens and session management. Required for the platform to function.
  • Preferences: Theme selection, chart settings, and UI state. Stored in local storage.
  • Analytics: Anonymous usage statistics to improve the platform. Can be disabled in your account settings.

We do not use third-party advertising cookies. You can manage cookies through your browser settings.

9. International Data Transfers

Our Services are hosted on infrastructure located in various global regions. By using the Services, you consent to the transfer of your data to servers outside your country of residence. We ensure appropriate safeguards are in place through contractual obligations with our infrastructure providers.

10. Children's Privacy

Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the Services after changes constitutes acceptance of the revised policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy, contact us: