We keep your email, what you do in the app, and a payment record. We never ask for your exchange keys, never touch your funds, and never sell your data to anyone.
Each point below is the short version. Open Details for the exact wording that applies.
1Who holds your data
unonitrade. Email unonitrade@gmail.com about anything on this page.
unonitrade, an independently operated service, is the Personal Data Controller for the data described here. Our providers act as Personal Data Processors on our instructions.
We process personal data in line with Law No. 27 of 2022 on Personal Data Protection (UU PDP) and, where it applies to you, other data protection law such as the EU and UK GDPR.
Contact for privacy matters: unonitrade@gmail.com. No Data Protection Officer is currently appointed; processing is not large-scale and does not involve regular systematic monitoring.
2What we keep
Your email and password (scrambled so nobody can read it), your plan and payment reference, what you track and save in the app, and basic technical logs.
Account data. Email address, a hashed password (or a Google account identifier if you sign in that way), join date, verification status.
Subscription data. Your plan, its start and end dates, and a payment reference. Where you pay directly on Solana, the transaction signature and the wallet address you paid from.
Community data. If you join our Telegram group or Discord server through the site, your Telegram or Discord account id and username, so access follows your plan.
Feedback. If you answer our short question after a plan ends, the option you picked and anything you write.
Usage data. Coins you track, headlines you save, your settings, your referral code and its results.
Technical data. IP address, browser and device type, the page that referred you, and request timestamps, held in server logs. We look up which country an IP address belongs to, using a database kept on our own server, only to count visitors by country.
Support data. Anything you email us.
Personal financial data is treated as a sensitive category under most data protection regimes. We keep our handling of payment information to the minimum above and rely on our payment provider for the rest.
3What we never ask for
Your exchange API keys, your wallet access, your card number, or your actual password. The app reads public market data and cannot trade for you even if it wanted to.
Exchange API keys. Never requested, never needed — the service reads public market data only.
Access to your funds or wallets. We cannot place trades, move assets, or see balances.
Card numbers. Handled by our payment provider; we see only a reference and the outcome.
Your plaintext password. Hashed before storage and unreadable, by us or anyone.
Biometric, genetic, health or criminal-record data, or any other sensitive category beyond the limited financial data above.
4Why we keep it
To run your account, take payment, stop fraud, keep the service working, and email you about your account. Marketing only if you opt in.
We rely on a lawful basis for each purpose. Ours are:
Providing the service — basis: performance of a contract with you.
Taking payment and preventing fraud, including detecting self-referral and duplicate trials — basis: contract and legitimate interests.
Keeping the service secure and working — logs, rate limiting, debugging — basis: legitimate interests.
Contacting you about your account, including reminders before your plan ends and one short question after it ends — basis: contract and legitimate interests.
Understanding how the site is used — visitor totals, where visitors come from, device type, and why members leave — basis: legitimate interests.
Optional product updates — basis: your consent, withdrawable at any time without affecting earlier processing.
5The signup code
We email a 6-digit code to check the address is really yours. It expires in minutes, is stored scrambled, and is never used for marketing.
When you sign up we email a one-time code to the address you gave, to confirm it is yours. The code is short-lived, single-use, and stored only in hashed form until it expires or is used. An email delivery provider processes your address and the message on our behalf. We do not use verification emails for marketing.
6Signing in with Google
Google tells us your email, name and an account ID. That is all. No access to Gmail, Drive, contacts or anything else.
If you sign in with Google, Google provides your email address, your name, and a unique account identifier so we can create or find your account. We do not receive your Google password, and receive no access to Gmail, Contacts, Drive or any other Google service. You can revoke the connection at any time in your Google account settings, then set a password and carry on.
7Cookies
Only what the site needs: staying signed in, remembering light or dark mode, and recording that you accepted these documents. No ad trackers.
A session cookie so you stay signed in.
Local storage for interface preferences such as light or dark mode.
A record that you accepted our Terms and this Policy, and the version accepted.
We do not use advertising cookies, cross-site trackers, or third-party analytics that profile you.
8Who else sees it
The companies that host the site, store our backups, send our emails, process payments, and run Telegram and Discord. Each is named below. We do not sell data, ever.
We share personal data only with providers who help us run the service, under contracts requiring them to process it on our instructions and protect it:
Vultr (hosting) — the server holding your account record, session and trade history. Located in Tokyo, Japan.
Resend (email delivery) — your email address and the contents of the messages we send you: sign-in codes, receipts, and account notices.
NOWPayments (payments) — your order reference and the amount, so an invoice can be created and a payment matched to it. We never see or store your wallet details.
Google (sign-in, only if you choose it) — see section 6.
Telegram (members and free groups) — if you join a group, we store the numeric Telegram account id that accepted the invite, so access can be tied to your subscription and removed when it ends. Telegram itself is governed by its own privacy policy.
Discord (members server) — if you link Discord, we store your Discord account id and username so we can add you to the members server and remove you when your plan ends. Discord is governed by its own privacy policy.
Cloudflare (backup storage) — nightly backup copies of our account database, kept for up to 90 days.
Solana network (only if you pay this way) — payments on a public blockchain are visible to anyone, permanently. That is how the blockchain works, not something we control.
We do not sell personal data and do not share it for anyone else's marketing. We may disclose data where required by law or by a lawful order from a competent authority.
9International data transfers
Some providers store data abroad. We rely on their contractual safeguards, and you can ask us who they are.
Some providers store and process data in other countries. We rely on the contractual safeguards our providers offer, including standard contractual clauses where applicable. You may ask which providers are involved and where they are located.
10How long we keep it, and deletion
We keep your data while your account is open. Delete your account or ask us to, and we erase your personal data within 30 days, except records the law makes us keep.
Account, usage, community and feedback data — kept while your account exists. Erased within 30 days of account deletion or of a valid deletion request.
Payment records — kept as long as tax and accounting law requires, which can be up to ten years, even after your account is deleted. We keep only what that law needs.
Server logs — up to 90 days, then deleted.
Backups — backup copies roll off automatically within 90 days. Until then, deleted data held in a backup is not used, and is only restored to recover from a system failure, after which we delete it again.
Verification codes — minutes.
Totals that no longer identify anyone, such as visitors by country, may be kept longer.
11Security, and what happens if it goes wrong
Encrypted connections, hashed passwords, restricted access. If there is a breach we will tell you promptly.
Connections are encrypted in transit. Passwords are hashed with a modern algorithm. Access to production data is restricted to those who need it. No system is perfectly secure, but because we never hold your funds or exchange keys, a breach of our systems cannot be used to trade on your behalf.
If a personal data protection failure occurs, we will notify affected users, and any supervisory authority we are required to inform, without undue delay and in any case within 72 hours of becoming aware of it. We will tell you what data was affected, when and how it happened, and what we are doing about it.
12Your rights
See your data, correct it, delete it, take it elsewhere, or object to how we use it. Delete your account from the account menu or ask by email, and we erase your data within 30 days.
Subject to the data protection law that applies to you, you have the right to:
be informed about processing, and access your data;
have inaccurate or incomplete data corrected;
have your data erased or destroyed;
withdraw consent where processing is based on consent;
object to processing, including automated decisions that significantly affect you;
restrict or postpone processing;
receive your data in a portable format and have it transmitted elsewhere where technically possible;
claim compensation for a breach of your rights.
Deleting your data. You can delete your account yourself from the account menu, or email unonitrade@gmail.com from the address on your account and ask us to erase your personal data. We may ask you to confirm the request comes from you. Once a request is valid, we erase your personal data within 30 days, except where the law requires us to keep it, such as payment records under tax law. In that case we keep only what is required and tell you what and why.
For anything else, email unonitrade@gmail.com; we respond within 30 days.
13Children
Not for under-18s, and we do not knowingly collect their data.
The service is not for anyone under 18 and we do not knowingly collect data from children. Children's data is treated as a sensitive category requiring parental consent under most data protection regimes; we avoid the issue by not offering the service to minors. If you believe a minor has an account, contact us and we will remove it.
14Changes
If we change something that matters, we tell you before it takes effect.
If we change this policy in a way that materially affects you, we will notify you before it takes effect and ask you to accept the new version.
15Contact and complaints
Email unonitrade@gmail.com. If we do not sort it out, you can complain to your local data protection authority.
If you are not satisfied with our response, you may complain to the data protection supervisory authority in your jurisdiction.
This policy is part of our Terms of Service, and the governing law and courts set out there (section 17) apply to it, without limiting your right to complain to a data protection authority.