Privacy Policy
Last updated · June 1, 2026
This Privacy Policy explains what personal data Vanguard Signals collects, how we use it, with whom we share it, and the rights you have over it. We are committed to handling your data lawfully, transparently and securely.
01Data We Collect
Account data: email address, hashed password, display name, subscription tier and billing identifiers.
Usage data: pages viewed, signals interacted with, API call patterns, device, browser and IP address.
Optional data: connected exchange API keys (encrypted at rest with envelope encryption), portfolio metadata and notification preferences.
02How We Use Your Data
We process your data to operate the platform, authenticate you, deliver signals and alerts, prevent fraud, improve our models in aggregate, and meet legal obligations. We do not sell your personal data to third parties under any circumstances.
03Legal Bases (GDPR)
We rely on contract performance for account and subscription processing, legitimate interest for analytics and fraud prevention, consent for marketing communications, and legal obligation for tax and accounting records.
04Sharing & Sub-processors
We share data only with vetted sub-processors that support the service: cloud hosting (AWS, Cloudflare), authentication (Supabase), payments (Stripe), email delivery (Resend), and product analytics. A current list is available on request.
05Data Retention
Account data is retained for the life of your account plus 30 days after closure. Billing records are retained for 7 years to comply with tax law. Anonymised analytics may be retained indefinitely.
06Your Rights
You have the right to access, correct, export and delete your personal data, and to object to or restrict processing. EU and UK residents may lodge a complaint with their data protection authority. California residents have additional rights under the CCPA. Submit requests to privacy@vanguardsignals.app.
07Security
We apply industry-standard safeguards including TLS 1.3 in transit, AES-256 encryption at rest, role-based access control, continuous monitoring and annual third-party penetration tests. No system is perfectly secure; we will notify affected users without undue delay in the event of a qualifying breach.
08Cookies
We use a minimal set of strictly-necessary cookies for authentication and session management, and optional analytics cookies that you can disable in your account settings.