Privacy Policy

Effective Date: 25 April 2026
Last Updated: 25 April 2026
Version: 1.0

This Privacy Policy explains how GoldStrait Technologies, LLC collects, uses, and protects your personal data. It complies with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and applicable national data protection laws.

1. Data Controller

GoldStrait Technologies, LLC ("we", "us", "Provider")
1021 E Lincolnway, 10245, Cheyenne, WY 82001, Laramie County, USA
Email (privacy): privacy@goldstrait.com
EU Service Address: (EU service address pending — will be designated)
Manager: Patrick Windolph
EIN: (EIN pending — will be added once issued by the IRS)

For all questions regarding the processing of your personal data, please contact us at privacy@goldstrait.com.

2. What Personal Data We Collect

We collect only the data needed to provide and improve the Service.

2.1 Account Data (provided by you)

2.2 Service Configuration Data

2.3 Usage Data (collected automatically)

2.4 Cookies

See our Cookie Policy below (Section 9). Essential cookies are always set; analytics and marketing cookies are set only with your consent.

2.5 Data We Do NOT Collect

3. How We Use Your Data — Purposes and Legal Basis

We process your data on the following legal bases under Article 6 GDPR:

PurposeLegal BasisRetention
Provide and operate the Service (account, dashboard, bot execution)Contract performance (Art. 6(1)(b) GDPR)Duration of subscription + 3 years after last activity
Process payments and prevent fraudContract + Legitimate Interest (Art. 6(1)(b) and (f))10 years (tax law requirements)
Send transactional emails (login alerts, payment confirmations, security notifications)Contract performance (Art. 6(1)(b) GDPR)Duration of subscription
Send marketing emails (newsletters, product updates)Consent (Art. 6(1)(a) GDPR), revocable any timeUntil consent revoked
Provide customer supportContract + Legitimate Interest3 years after ticket closure
Adaptive login security (risk scoring, suspicious-login detection, trusted device management)Legitimate Interest (Art. 6(1)(f)) — protecting user accountsLogin events: 12 months. Trusted devices: 30 days from last use.
Comply with legal obligations (tax records, AML/sanctions screening)Legal obligation (Art. 6(1)(c) GDPR)Per applicable law (typically 10 years for financial records)
Improve the Service (anonymized usage analytics)Consent for analytics cookies / Legitimate Interest for aggregated metrics25 months (Google Analytics default)

4. Third-Party Service Providers (Sub-processors)

We engage carefully selected service providers to deliver the Service. Each is bound by data processing agreements ensuring GDPR-equivalent protection.

ProviderPurposeLocationTransfer Mechanism
Vultr Holdings, LLCCloud hosting (server infrastructure)Frankfurt, Germany (EU)EU Data Center
Sendinblue (Brevo) SASTransactional and marketing email deliveryFrance (EU)EU-based
MetaApi Cloud (MetaApi LLC)Broker API gateway for trade executionVarious (London, NY, Singapore)EU Standard Contractual Clauses (SCCs) for non-EU regions
Telegram FZ-LLCOptional notification delivery (only if you enable Telegram alerts)United Arab Emirates / DistributedSCCs / your consent
Mercury Technologies, Inc.Business banking (no end-user PII transmitted)USASCCs
Stripe, Inc. (if applicable)Card payment processingUSA / IrelandSCCs + Stripe DPA
Google LLC (Tag Manager / Analytics)Anonymized usage analytics — only with consentUSASCCs + IP-Anonymization

4.1 Cross-Border Transfers. Some of our sub-processors are located outside the EU. We rely on European Commission-approved Standard Contractual Clauses (Decision (EU) 2021/914) and additional safeguards such as encryption in transit and at rest. You may request a copy of the SCCs for any transfer by emailing privacy@goldstrait.com.

4.2 No Sale of Data. We do not sell, rent, or trade your personal data to third parties.

5. Your Rights Under GDPR

If you are in the EU, EEA, UK, or Switzerland, you have the following rights regarding your personal data:

To exercise any right, email privacy@goldstrait.com. We respond within 30 days (extendable by 60 days for complex requests, with notification).

6. CCPA Rights (California Residents)

California residents have the additional rights under the California Consumer Privacy Act:

Note: The Service is not offered to U.S. Persons (see ToS Section 3.2). California residents who nevertheless interact with our website are still afforded these rights for any data we hold.

7. Data Security

We implement industry-standard technical and organizational measures to protect your data:

In the unlikely event of a personal data breach involving high risk to your rights and freedoms, we will notify you and the competent supervisory authority within 72 hours of awareness, in accordance with Articles 33-34 GDPR.

8. Data Retention

We retain personal data only as long as necessary for the purposes set out above:

9. Cookie Policy

We use cookies and similar technologies to operate the Service.

9.1 Essential Cookies (always set, no consent required)

9.2 Analytics Cookies (only with your consent)

You may withdraw or change your cookie consent at any time using the cookie banner (re-displayed yearly) or by clearing your browser's localStorage for goldstrait.com.

10. Minors

The Service is not directed at persons under 18 years of age. We do not knowingly collect personal data from minors. If you become aware that a minor has provided us data, please contact us at privacy@goldstrait.com so we can delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email and posted on this page with an updated "Last Updated" date. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

12. Contact and Complaints

For privacy questions: privacy@goldstrait.com
For general inquiries: support@goldstrait.com
Postal mail: 1021 E Lincolnway, 10245, Cheyenne, WY 82001, Laramie County, USA
EU service address: (EU service address pending — will be designated)

EU/EEA residents may lodge a complaint with their local supervisory authority. A list is available at edpb.europa.eu.

© GoldStrait Technologies, LLC. All rights reserved. Document version 1.0 — 25 April 2026.