Quberas Privacy & Cookie Policy
Global baseline privacy notice for the Quberas beta, including account, exchange/API, billing, marketplace, referral/affiliate, analytics, and cookie processing.
PRIVACY SUMMARY
Quberas processes account, device, usage, strategy, exchange-connection, trading, billing, marketplace, referral, and support data to provide and secure the Service. Exchange API credentials are sensitive service credentials; do not provide withdrawal-enabled keys. Non-essential cookies or similar technologies are used only where legally permitted and, where required, after consent. This Policy does not reduce rights that mandatory privacy law gives you.
Contents
- Who We Are and Scope
- Personal Data We Collect
- How We Obtain Data
- Purposes and Legal Bases
- Exchange API Credentials and Security-Sensitive Data
- Social Sign-In and Google User Data
- Cookies and Similar Technologies
- When We Share Personal Data
- International Data Transfers
- Retention
- Security
- Your Choices and Rights
- U.S. State Privacy Disclosures
- Automated Processing and Trading Logic
- Children
- Changes to this Policy
- Contact and Representatives
1. Who We Are and Scope
This Privacy & Cookie Policy explains how the Operator identified above processes personal data when you use Quberas websites, applications, APIs, trading automation, backtesting, marketplace functions, billing, referral/affiliate functions, support channels, and related services (the “Service”).
For data-protection law purposes, the Operator is the controller of personal data unless a specific notice states otherwise. Quberas is currently an unincorporated beta project; that status does not remove the need to identify the actual individual or entity that controls the processing. The Operator details above must therefore be completed before publication.
This Policy is designed as a global baseline. Local law may provide additional rights or require an EU, UK, or other local representative. If a local notice or mandatory law conflicts with this Policy, the mandatory rule controls.
2. Personal Data We Collect
Account and identity data. Username, email address, authentication identifiers, account status, language, time zone, profile information, two-factor authentication status, linked login methods, recovery information, and account-security events.
Security and device data. IP address, approximate location derived from IP, browser and device information, session identifiers, login history, security logs, anti-fraud signals, diagnostic events, and related technical metadata.
Exchange and API connection data. Exchange name, API public-key identifiers or snippets, API secret material needed to authenticate the connection, permission-validation results, IP allowlist information where provided, balances, positions, open orders, order/trade history, account-market settings, and other exchange data needed to provide the Service. Quberas is designed not to require withdrawal permission.
Trading, strategy, and backtest data. Strategies, conditions, parameters, bot configuration, symbols, risk settings, backtest inputs and outputs, simulated results, live bot events, orders transmitted through the Service, execution responses, alerts, errors, strategy versions, and related logs.
Marketplace and Program data. Creator listings, strategy descriptions, access settings, subscribers, program attribution, referral codes, traffic-source information, reward calculations, hold/release status, payout details, tax or verification information where required, and anti-fraud records.
Billing data. Plan, add-ons, billing period, invoice and transaction identifiers, payment status, credits, discounts, refunds, chargebacks, and limited payment-method metadata supplied by the payment processor. We generally do not need to store full payment-card numbers.
Communications and support data. Messages, support requests, bug reports, surveys, feedback, complaint records, and correspondence.
Cookie and analytics data. Cookie identifiers, consent choices, page or feature interactions, referrer information, campaign attribution, and analytics or advertising identifiers where enabled.
We may also create aggregated or de-identified information that is not reasonably linked to an identifiable person. We may use that information for analytics, security, product improvement, benchmarking, and business planning.
3. How We Obtain Data
We collect data directly from you; automatically from your browser, device, and use of the Service; from connected exchanges and other integrations that you authorize; from payment and identity providers; from referral, Creator, Affiliate, or Agent relationships; and from security, fraud-prevention, sanctions, analytics, or public sources where legally permitted.
If you provide personal data about another person, you represent that you have the right to do so and have provided any notice or obtained any consent required by law.
4. Purposes and Legal Bases
| Purpose | Typical data | Legal basis where GDPR/UK GDPR applies |
|---|---|---|
| Create and administer accounts; authenticate users | Account, authentication, device, security | Performance of contract; legitimate interests in account security |
| Connect exchanges; transmit orders; display balances and positions | API credentials, exchange account, trading data | Performance of contract |
| Run backtests, bots, notifications, and diagnostics | Strategy, market/exchange, bot and log data | Performance of contract; legitimate interests in reliability and debugging |
| Billing, subscriptions, refunds, credits, creator/program payouts | Billing, transaction, payout, verification | Performance of contract; legal obligations; legitimate interests in fraud prevention |
| Marketplace and referral/affiliate programs | Listings, attribution, rewards, subscriber/access data | Performance of contract; legitimate interests in operating and protecting programs |
| Security, abuse, market-integrity and sanctions controls | Security logs, IP, account, transaction and verification data | Legitimate interests; legal obligations |
| Analytics and product improvement | Usage, diagnostics, aggregated statistics | Legitimate interests; consent where required for device storage/access technologies |
| Marketing communications and advertising technologies | Email, campaign and cookie identifiers | Consent where required; legitimate interests where permitted |
| Legal claims, compliance, audits and requests | Relevant account, transaction, support and log data | Legal obligations; legitimate interests in establishing and defending claims |
Where we rely on legitimate interests, we consider the interests and rights of affected individuals. Where consent is the legal basis, you may withdraw consent prospectively at any time through the available controls or by contacting us. Withdrawal does not make earlier lawful processing unlawful.
5. Exchange API Credentials and Security-Sensitive Data
Exchange API credentials are sensitive service credentials. Quberas uses them only to authenticate and perform the exchange functions you authorize. The Service is designed to accept read and trade permissions, not withdrawal permissions. You must independently verify the permissions at the exchange.
We may store secret material in encrypted or otherwise protected secrets-management infrastructure and display only a limited snippet in the interface. Security controls reduce risk but cannot guarantee that credentials, accounts, data, or systems will never be compromised.
Where credentials or account-login information are treated as “sensitive personal information” or an equivalent category under applicable law, we use them for providing, securing, authenticating, and protecting the Service and not to infer personal characteristics for advertising.
6. Social Sign-In and Google User Data
Quberas offers optional sign-in and account linking through Google, Apple, and Facebook. Using a social sign-in is optional: you may instead create and use a Quberas account with an email address and a password. This Section describes the data Quberas receives from those providers and how we use, store, share, and delete it.
Data received from Google. When you sign in with Google or link a Google account, Quberas requests only the basic identity scopes userinfo.profile and userinfo.email. From these we receive your Google account identifier, your name, your email address, an indication of whether Google has verified that email address, and the web address of your Google profile picture. Quberas does not request and does not receive access to Gmail, Google Drive, Google Contacts, Google Calendar, Google Photos, or any other Google product data.
How we use Google user data. We use this data only to create your Quberas account, to authenticate you when you sign in, to recognize you as a returning user, to display your name and profile picture inside the Service, and to allow you to link or unlink Google as a sign-in method. We do not use Google user data for advertising, for credit or risk scoring, or for any purpose unrelated to providing and securing the Service.
How we store Google user data. Your Google account identifier, name, email address, and profile-picture web address are stored in your Quberas account record for as long as the Google sign-in method remains linked to your account. The profile picture itself continues to be hosted by Google; Quberas stores only the link to it and does not copy the image. If you begin registration through Google but do not complete it, these fields are held in temporary storage for no more than fifteen minutes and are then discarded automatically.
Google tokens. The authorization code and access token issued by Google are used once, during sign-in, solely to read the fields listed above. Quberas does not store Google access tokens or refresh tokens and does not access your Google account at any other time.
Sharing of Google user data. Quberas does not sell Google user data and does not share it with third parties for their own purposes. It may be processed by the infrastructure and support providers described in Section 8, acting on our instructions, and may be disclosed where required by law.
Your control. You may unlink Google from your Quberas account at any time in your profile settings, and you may revoke Quberas access at any time from your Google Account permissions page at myaccount.google.com/permissions. Unlinking removes the Google account identifier, name, email address, and profile-picture web address associated with that sign-in method. Deleting your Quberas account removes them together with the rest of your account data, subject to Section 10 (Retention).
Apple and Facebook sign-in. Where you sign in with Apple or Facebook, Quberas receives an equivalent minimum set of identity fields from that provider and handles them on the same basis as described in this Section.
Quberas use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Cookies and Similar Technologies
Quberas may use cookies, local storage, pixels, scripts, SDKs, or similar technologies. We group them by purpose:
- Strictly necessary: authentication, session continuity, security, fraud prevention, load balancing, billing flow, and remembering privacy choices. These technologies are used where necessary to provide a requested service.
- Functional: remembering preferences such as language, interface settings, or other optional convenience features.
- Analytics: understanding feature use, performance, errors, and aggregate behavior so we can improve the Service.
- Marketing/attribution: measuring campaigns, referral attribution, or advertising effectiveness where enabled.
Where law requires prior consent for non-essential storage or access technologies, Quberas will not intentionally activate those technologies until you make the required choice. You can change cookie choices through the consent/settings interface where available. Browser controls may also block or delete cookies, but doing so can break parts of the Service.
Because vendors and cookies can change during beta, the current consent interface may provide a more detailed, dynamic list of technologies, vendors, purposes, and durations. That list is part of this Policy for transparency purposes.
8. When We Share Personal Data
We may disclose personal data only as reasonably necessary for the following categories of recipients:
- cloud hosting, databases, logging, secrets management, content delivery, cybersecurity, email/messaging, support, analytics, and other technology providers;
- connected exchanges, market-data providers, OAuth/identity providers, and other integrations you choose to use;
- payment processors, banks, payout providers, tax or identity-verification providers involved in billing or Program payments;
- professional advisers, auditors, insurers, financing parties, and counterparties to a bona fide financing, restructuring, incorporation, asset transfer, merger, or sale;
- authorities, courts, exchanges, payment providers, rights holders, or other parties where we reasonably believe disclosure is required by law or necessary to protect rights, security, users, market integrity, or the Service.
Marketplace creators and subscribers may receive limited information needed to operate access or support a transaction. We do not disclose exchange API secrets to strategy creators or other marketplace users merely because you subscribe to a strategy.
9. International Data Transfers
Quberas is a global online service and our users, providers, exchanges, infrastructure, and support resources may be located in different countries. Personal data may therefore be processed outside your country.
Where a law requires a transfer mechanism for cross-border transfers, we will use a legally recognized mechanism or other permitted basis, which may include contractual safeguards such as standard contractual clauses, adequacy decisions, or another lawful transfer tool, as applicable. No transfer mechanism eliminates all foreign-jurisdiction or cybersecurity risk.
10. Retention
We retain personal data for no longer than reasonably necessary for the purposes described in this Policy, taking account of account status, active subscriptions, strategy and bot history, security and fraud risks, dispute limitation periods, backup cycles, payment and tax record requirements, Program holds and clawbacks, legal obligations, and the need to establish or defend claims.
Some data may be deleted or anonymized shortly after account closure, while transaction, security, legal, tax, marketplace, or payout records may need to be retained longer. Backups may persist until overwritten by the applicable backup cycle. We may retain de-identified or aggregated data that no longer identifies you.
11. Security
We use technical and organizational measures intended to protect personal data and service credentials, which may include access controls, encryption, secrets management, logging, environment separation, two-factor authentication, monitoring, and least-privilege controls. Security practices evolve during beta.
No internet, cloud, exchange, authentication, or storage system is completely secure. You are responsible for account security practices described in the Terms, including strong unique credentials, 2FA, restricted exchange API permissions, and prompt revocation of compromised keys.
If we become aware of a personal-data breach, we will assess and make legally required notifications to affected individuals or authorities where applicable.
12. Your Choices and Rights
Depending on where you live and whether a particular law applies to Quberas, you may have rights to request access, correction, deletion, portability, restriction, objection, or information about processing; withdraw consent; opt out of certain targeted advertising, sale, or sharing; limit certain uses of sensitive personal information; or appeal a privacy-request decision.
To exercise a privacy right, contact [email protected] or use an in-product privacy control if available. We may need to verify your identity and authority before acting. We may deny or limit a request where permitted by law, including where data must be retained for security, fraud prevention, legal obligations, transactions, or legal claims.
If GDPR or UK GDPR applies, you may also complain to the competent supervisory authority. If you are in California or another U.S. state with applicable privacy rights, we will provide the rights and opt-out mechanisms required by the law that applies to Quberas. We will not unlawfully discriminate against you for exercising a privacy right.
13. U.S. State Privacy Disclosures
Quberas does not sell personal data for monetary consideration. If the use of analytics, advertising, or attribution technologies is legally treated as a “sale”, “sharing”, or targeted advertising under an applicable U.S. state law, Quberas will provide any required opt-out mechanism and honor legally recognized opt-out preference signals where the law requires it.
Categories collected may include identifiers; internet/network activity; commercial or transaction information; account and authentication information; approximate geolocation; professional/business information for marketplace or Program participants; and sensitive account-access credentials used to provide and secure the Service. The purposes and recipient categories are described elsewhere in this Policy.
This section applies only to the extent Quberas is subject to the relevant state law; it does not create rights that a law does not otherwise provide.
14. Automated Processing and Trading Logic
Quberas bots can automatically transmit trading instructions based on strategy logic and market/exchange data. That automation is a product function chosen by the user; it is not designed to profile an individual using personal data in order to make employment, credit, housing, insurance, or similar decisions about that person.
If Quberas later introduces personal-data profiling or solely automated decisions that produce legal or similarly significant effects and applicable law requires additional notice or rights, we will provide the required information and controls.
15. Children
The Service is not directed to children and is intended only for users who are at least 18 years old. We do not knowingly solicit personal data from children for use of the trading Service. If you believe a child has provided personal data in violation of this rule, contact [email protected].
16. Changes to this Policy
We may update this Policy as the beta, technology stack, vendors, legal obligations, marketplace, Programs, or data practices change. We will update the effective date and provide additional notice of material changes where required by law. Where consent is required for a new processing activity, an updated policy alone does not replace that consent.
17. Contact and Representatives
Privacy email: [email protected].
Legal email: [email protected].