Privacy Policy

Last updated: August 2026

This Privacy Policy explains how DAlgo Technologies Pvt. Ltd. ("DAlgo", "we", "us") collects, uses, stores, and shares your information when you use our automated trading platform. It is written to comply with the Information Technology Act, 2000, the Information Technology (Amendment) Act, 2008, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and applicable GDPR principles.

1. Information We Collect

  • Name, email, and mobile number — collected when you create an account.
  • Aadhar card number and images — collected for KYC verification, encrypted at rest in Supabase Storage.
  • Broker API credentials — AES-256 encrypted, never stored in plaintext.
  • Trading data — your positions, orders, and journal entries.
  • Session cookie — dalgo_access_token (HttpOnly).

2. Why We Collect It

  • KYC verification as required by the Prevention of Money Laundering Act (PMLA), 2002.
  • Operating the automated trading platform on your behalf.
  • Sending trade notifications and alerts.
  • Improving platform performance.

3. How We Store It

  • Database: Supabase PostgreSQL, hosted in the ap-south-1 (Mumbai) region.
  • KYC documents: Supabase Storage, in a private bucket accessible only via signed URLs.
  • Broker credentials: AES-256-GCM encrypted before storage, decrypted only at trade execution time.
  • No data is stored outside India.

4. Who We Share It With

  • Zerodha Kite Connect API — to execute your trades.
  • Resend — email delivery only (name and email).
  • Supabase — database and storage provider.

We never sell your data to any third party, ever.

5. Data Retention

  • KYC documents: retained 5 years after account closure, per PMLA 2002.
  • Trading journal: retained 7 years, per the IT Act.
  • Account data: deleted within 30 days of a written deletion request, subject to legal retention requirements.

6. Your Rights

  • Access: request a copy of your data at any time.
  • Correction: update incorrect information.
  • Deletion: request account deletion.
  • Contact: support@dalgo.online for all requests.

7. Cookies

  • One cookie only: dalgo_access_token.
  • HttpOnly, Secure, SameSite=Lax.
  • Expires at midnight IST daily.
  • Required for login — cannot be disabled while logged in.
  • No tracking, advertising, or third-party cookies.

8. Security

  • All connections are encrypted via TLS.
  • Broker credentials are encrypted with AES-256-GCM.
  • Access tokens are never logged or exposed in responses.
  • Regular security reviews.

9. Contact

Privacy Officer: Dinesh Wadhwani

Email: support@dalgo.online

We respond to all privacy requests within 30 days.