Skip to main content

Privacy Policy

Last updated: March 4, 2026

1. Overview

Red Sted (“we,” “us,” or “our”) respects your privacy. This Privacy Policy explains what information we collect when you use red-sted.com (the “Service”), how we use it, and how we protect it.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your email address and a hashed version of your password. We never store passwords in plaintext.

2.2 Exchange API Keys

When you connect a Kraken Futures API key, we encrypt it with AES-256-GCM before storage. The raw key and secret are never stored in plaintext, logged, or transmitted after initial encryption. We use your API keys solely to execute trading operations you initiate and to validate your exchange connection.

2.3 Trading Data

We store records of trades executed through the Service, including: trade direction, entry/exit prices, edge scores, P&L, and timestamps. This data is used to display your trading history and generate analytics within your dashboard.

2.4 Usage Data

We may collect basic usage information such as pages visited, IP address (for activity log purposes), and browser type. We do not use third-party trackers or sell your data to advertisers.

2.5 Payment Information

Payments are processed by Stripe. We do not store your credit card number, CVC, or billing address. Stripe handles all payment data under their own Privacy Policy.

3. How We Use Your Information

  • To provide and maintain the Service
  • To execute trades through your connected exchange account
  • To generate trade analytics and edge scores
  • To process subscription payments via Stripe
  • To send essential account communications (password resets, security alerts)
  • To improve the Service and fix bugs

We do not sell, rent, or share your personal information with third parties for marketing purposes.

4. Data Security

We implement the following security measures:

  • API Key Encryption: AES-256-GCM encryption with keys stored in environment variables, not in the database
  • Password Hashing: Passwords are hashed with bcrypt before storage
  • Session Security: JWT-based sessions with secure, HTTP-only cookies
  • HTTPS: All data transmitted between your browser and our servers is encrypted with TLS
  • Content Security Policy: Strict CSP headers prevent cross-site scripting attacks

While we take security seriously, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

5. Data Retention

We retain your account data for as long as your account is active. Trade history is retained for 90 days after account deletion. Encrypted API keys are permanently deleted immediately upon account deletion. You may delete your account at any time from Security Settings.

6. Third-Party Services

The Service integrates with the following third parties:

  • Kraken: To execute trades and retrieve market data via their API
  • Stripe: To process subscription payments
  • Vercel: To host and serve the application

Each third-party service operates under its own privacy policy. We encourage you to review their policies.

7. Cookies

We use only essential cookies required for the Service to function — specifically, a session cookie that maintains your login state. We do not use advertising cookies, analytics cookies, or third-party tracking cookies.

8. Your Rights

Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your account and personal data
  • Withdraw consent for data processing

To exercise any of these rights, contact us at support@red-sted.com.

9. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us and we will take steps to delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the email associated with your account. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.

11. Contact

For privacy-related inquiries, contact us at support@red-sted.com.