Overview
This policy applies to website visitors, account holders, and authorized team users accessing ZENITH services.
It should be read together with our Terms of Service and Cookie Policy.
Information We Collect
We collect data only where needed for account access, platform operation, compliance, and product reliability.
- Personal identification data: Name, email address, username, and account profile information.
- Access-request data: An email address submitted for limited access, its invitation lifecycle, and email-free administrative audit identifiers. Turnstile tokens, challenge metadata, raw IP addresses, and user agents are not retained with an access request.
- Financial and account data: Broker account identifiers, API credentials, exchange permissions, and subscription plan metadata.
- Usage and device data: Session logs, browser/device metadata, IP address, crash diagnostics, and activity telemetry.
- Third-party data: Market data and account state synced from integrated broker or exchange partners that you authorize.
How We Use Data
- Operate account authentication, bot configuration, order routing, and notifications.
- Detect abuse, fraud, unauthorized access, and operational failures.
- Meet legal, regulatory, accounting, and audit obligations.
- Improve reliability, user experience, and feature quality using aggregated analytics.
- Send product or marketing updates only where permitted, with opt-out controls.
Your Rights
Depending on jurisdiction, you may have rights to access, correct, delete, or restrict use of your personal data.
- Request a copy of personal information we hold.
- Request correction of inaccurate or outdated data.
- Request deletion where retention is not legally required.
- Object to certain processing, including direct marketing.
- Withdraw consent where processing relies on consent.
Submit privacy requests through the contact channel published in ZENITH or on ZENITH's website. Use your registered account email where possible so we can verify the request.
Security And Retention
- Data in transit uses TLS encryption, and sensitive credentials are encrypted at rest.
- Access to production systems is restricted through role-based controls and logging.
- Retention periods are set by legal obligations, fraud prevention needs, and service requirements.
- When data is no longer required, it is deleted or irreversibly anonymized.
- Access-request email data is deleted 90 days after its latest lifecycle activity, including untouched pending requests. Early erasure invalidates active invitation delivery without restoring a consumed access credit.
International Transfers
Where data is transferred across borders, ZENITH applies contractual and organizational safeguards, including standard contractual clauses where required.
Users can request additional transfer safeguard details through the privacy contact channel.
Policy Updates
We may update this policy to reflect legal, technical, or product changes.
If updates are material, we provide notice through the app, website, or account email before the revised policy takes effect.
Continued use of ZENITH after the effective date means the updated policy applies.
Contact
Privacy questions or requests must be submitted through the privacy contact channel published in ZENITH or on ZENITH's website.
ZENITH is operated by ZENITH Trader, LLC, a Delaware limited liability company.