Privacy Policy
Version 0.1.0-draft · Last updated
This policy explains what personal data f8 Capital collects, why, who processes it with us, how long we keep it, and what you can ask us to do with it.
The controller's legal identity, the EU/UK representative where one is required, the lead
supervisory authority and the transfer mechanism for each processor must be confirmed by counsel
before launch — see docs/legal-review.md.
1. What we collect
You give us:
| Data | When | Why | | ---------------------------------------------------------------------- | -------------------------------------------- | ----------------------------------------------------- | | Email address, name, profile image | Sign-up, through our authentication provider | To create and secure your account, and to contact you | | Country of residence, date of birth | Onboarding | Eligibility, age check and sanctions screening | | Trading experience, market interest | Onboarding | To set the right defaults and content | | Marketing preference | Onboarding and Settings | To know whether you want offers | | Identity document, selfie, extracted name, country and document number | Identity verification, before a first reward | Legal obligation and fraud prevention | | Payout destination (e.g. a wallet address) | Before a withdrawal | To pay the reward you earned | | Support messages and attachments | When you open a ticket | To answer you |
We generate:
- Your orders, positions, deals, journal notes, account statistics and rule events — the record of the evaluation itself.
- Notifications and their read state, and the emails we sent you.
- An append-only audit log of every state change on accounts, orders, rewards, withdrawals, identity verification, roles and program versions.
- Risk flags where automated checks find a pattern that needs review.
We receive automatically:
- Technical data from your browser (IP address, user agent) at our hosting edge, used for security, abuse prevention and the country-level availability check.
- Delivery, bounce and complaint events from our email provider.
We do not use advertising trackers, and we do not sell personal data.
2. Why we are allowed to use it
| Purpose | Basis | | --------------------------------------------------------------------- | --------------------------------- | | Running your account and the evaluation you bought | Performance of a contract | | Identity verification, sanctions screening, record keeping | Legal obligation | | Fraud, abuse and multi-account detection; securing the platform | Legitimate interests | | Transactional email you cannot turn off (security, money, compliance) | Performance of a contract | | Offers and product news | Consent, withdrawable at any time | | Defending or bringing legal claims | Legitimate interests |
3. Who processes it with us
We use a small number of processors. Each one is bound by a data processing agreement and may use your data only on our instructions.
| Processor | Role | Data it sees | | ------------------------------ | ------------------------------------------ | -------------------------------------------------------------- | | Clerk | Authentication and session management | Email, name, profile image, sign-in events | | Convex | Application database and server functions | Everything in section 1 except raw identity documents | | Vercel | Web hosting and edge network | Request metadata, including IP address and approximate country | | Resend | Transactional and marketing email delivery | Email address, name, message content | | Identity verification provider | Document and biometric checks | Identity document, selfie, extracted identity fields | | Payment provider | Taking the program fee | Email address, amount, payment reference |
Raw identity documents and biometric data stay with the verification provider. We store its decision, the extracted name and country, and a one-way hash of the document number used to detect the same document across accounts — never the document number itself.
The verification and payment providers are selected per deployment and must be named here by product name before launch (ROADMAP D-05, D-06).
4. International transfers
Our processors operate in the United States and, for some, the European Union. Where data leaves your region, the transfer relies on the mechanism in that processor's data processing agreement, normally the European Commission's Standard Contractual Clauses together with the UK addendum.
5. How long we keep it
| Data | Retention | | ------------------------------------------------------------------------- | -------------------------------------------------------------- | | Account, profile and preferences | While the account is open, then 12 months | | Evaluation records: orders, positions, deals, statistics, rule events | 7 years from the account closing | | Financial records: orders, payments, rewards, withdrawals, ledger entries | 7 years, as accounting and anti-money-laundering rules require | | Identity verification decisions and extracted fields | 5 years after the relationship ends | | Audit log | 7 years; it is append-only and never edited | | Support tickets and attachments | 3 years from resolution | | Notifications and email delivery events | 24 months |
Closing your account anonymises your profile: your name and email are removed and the records above are retained in a form that can no longer identify you directly, because we still have to be able to show a regulator or an auditor what happened on an account.
6. Your rights
Subject to the law where you live, you can ask us to:
- give you a copy of your personal data, in a portable format;
- correct data that is wrong — note that a name verified at identity verification is locked, so changing it requires re-verification;
- delete your data, except records we must keep under section 5;
- restrict or object to processing based on our legitimate interests;
- withdraw consent to marketing, at any time, from Settings or the link in any marketing email.
Ask through support in the app or at support@f8ware.com. We answer within 30 days. If you are not satisfied you can complain to your data protection authority.
7. Security
Access to production data is limited to staff who need it for their role, and every staff action on your records is written to the audit log. Sessions use signed tokens validated on the server; every authorisation decision is made server-side. Withdrawals and payout-method changes require a one-time code sent to your email, and a new payout method cannot be used for a cooling-off period.
No system is perfectly secure. If a breach affects your data and is likely to present a risk to you, we notify you and the relevant authority within the time the law requires.
8. Children
The Service is for adults. We do not knowingly process the data of anyone under 18. If you believe a minor has an account, tell us at support@f8ware.com and we will close it.
9. Changes
We publish changes here with a new version number and date, and we notify material changes in the app and by email before they take effect.
Simulated trading only. No real funds are traded, held, or invested. Fees purchase an evaluation service; rewards are performance fees paid by the company.