1. Who we are
Controller: Mechagora LLC. Privacy contact: privacy.officer@mechagora.com. Legal: legal@mechagora.com.
2. Data we collect
- Account data — email, name, organization membership, role, and authentication identifiers.
- Credentials you submit — passwords are processed only to authenticate (hashed/verified via our identity stack); we do not store plaintext passwords.
- Session and security data — httpOnly cookies, CSRF tokens, MFA status, device/browser signals, IP address, and audit logs for security and compliance.
- Usage and product data — feature usage, preferences, error and performance telemetry related to the Service.
- Broker / BYOK data — keys and connection metadata you supply for broker integrations. Where designed as BYOK, keys remain under your control according to product documentation; we process them only to provide requested integrations.
- Support communications — messages you send to support or legal contacts.
3. How we use data
- Provide, secure, and improve the Service.
- Authenticate users, enforce MFA and access policies, and prevent abuse.
- Display dashboards, analytics, and connected market/broker information.
- Bill and administer subscriptions where applicable.
- Comply with law, respond to lawful requests, and enforce our Terms.
- Communicate service-related notices (security, material policy changes).
4. Legal bases (where GDPR/UK GDPR applies)
We process personal data under one or more of: performance of a contract; legitimate interests (security, product improvement, fraud prevention) balanced against your rights; consent where required; and legal obligation.
5. Cookies and similar technologies
Essential cookies include session and CSRF cookies required for sign-in and authenticated API access. We may use additional cookies or local storage for theme preference and similar UX settings. You can control non-essential cookies via browser settings; disabling essential cookies will break sign-in.
6. Sharing
We may share data with:
- Infrastructure and identity subprocessors that host or secure the Service.
- Payment processors for paid plans (as needed to charge and invoice).
- Brokers and market-data providers you choose to connect (only as needed for that integration).
- Professional advisors and authorities when required by law or legal process.
- Successors in a merger or acquisition, under appropriate safeguards.
We do not sell personal information for money.
7. International transfers
Data may be processed in the United States and other countries where we or our processors operate. Where required, we use appropriate transfer mechanisms (such as Standard Contractual Clauses).
8. Retention
We retain account and audit data for as long as your account is active and as needed for security, legal, and accounting purposes. Session cookies expire according to their configured lifetime. You may request deletion subject to legal retention requirements.
9. Security
We use industry-standard controls including encryption in transit (TLS), httpOnly cookies for sessions, access controls, and monitoring. No method of transmission or storage is 100% secure.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing or withdraw consent. To exercise rights, contact privacy.officer@mechagora.com. You may also lodge a complaint with your local supervisory authority.
11. Children
The Service is not directed to children under 16 (or the minimum age in your jurisdiction). We do not knowingly collect data from children.
12. Changes
We may update this Policy by posting a revised version with a new effective date. Material changes affecting sign-in or data use will be highlighted on this page and, where appropriate, notified in-product.
13. Contact
Privacy Officer — Mechagora LLC
privacy.officer@mechagora.com
Related: Terms of Service · Legal hub · Sign in