At CaymanBot, we take your privacy seriously. This Privacy Policy describes how we collect, use, store, and protect your information when you use our trading analytics platform.
1. Information We Collect
1.1 Information You Provide
When you create an account and use CaymanBot, we collect:
- Account Information: Username, user ID, email address, and avatar from your chosen OAuth provider (Discord, X, or TikTok)
- Account Preferences: Watchlists, alert settings, and notification preferences
- Payment Information: Processed securely through Stripe (we do not store credit card details)
- Communications: Support tickets, feedback, and messages to our support channels
1.2 Information Collected Automatically
When you use our Service, we automatically collect:
- Usage Data: Features accessed, queries made, alerts triggered
- Technical Data: IP address, browser type, device information
- Performance Data: Response times, error rates, service availability
- Session Information: Login times, session duration, activity patterns
1.3 OAuth Provider Data
When you sign in using one of our supported OAuth providers (Discord, X, or TikTok), we access:
- Basic profile information (username, avatar, user ID)
- Email address (if verified with your provider)
- Provider-specific data where applicable (e.g., Discord server membership for verification purposes)
1.4 Brokerage Account Information (Alpaca Integration)
If you choose to open a brokerage account through our Alpaca Securities integration, we collect the following information as required by federal KYC/AML regulations. This data is transmitted directly to Alpaca Securities LLC and is not stored on CaymanBot servers:
- Full legal name, date of birth, phone number
- Residential address
- Social Security Number (SSN) or Individual Taxpayer Identification Number (ITIN)
- Citizenship and tax residence
- Employment status, employer name and address
- Annual income, liquid net worth, total net worth ranges
- Investment experience
- Funding sources
- Regulatory disclosures (FINRA affiliation, control person, politically exposed person status)
- Trusted contact information (optional)
- IP address (collected at time of agreement signing via ipify.org)
What we DO store locally:
- Your Alpaca account ID and status (encrypted)
- API credentials for trade execution (AES-256-GCM encrypted)
- Order execution history (symbol, side, quantity, price, timestamps)
1.5 Discord Bot Data
If you interact with the CaymanBot Discord bot, we collect:
- Discord User ID: Used for alert delivery and notification routing
- Command Inputs: Commands you send to the bot for processing
- Server and Channel IDs: Used for routing notifications to the correct destination
Command inputs are not persisted beyond the lifetime of the command execution. Your Discord user ID is stored only for alert preference delivery.
1.6 Polymarket Wallet Information (Prediction Market Integration)
If you connect a cryptocurrency wallet for prediction market copy-trading, we collect and store:
- Wallet Address: Your public Ethereum/Polygon wallet address. Note that wallet addresses are publicly visible on the blockchain; we store the association between your CaymanBot account and your wallet address.
- CLOB API Session Key: A derived session key that allows CaymanBot to submit prediction market orders on your behalf. This key is encrypted at rest using AES-256-GCM. It can only trade within the USDC spending cap you approved in MetaMask.
- Copy-Trading Preferences: Which whale traders you follow, position size limits, and auto-trade settings.
- Trade History: Records of copy trades submitted through our platform, including market, side, size, and outcome.
We NEVER collect, transmit, or store your private key, seed phrase, or MetaMask password. The CLOB session key is derived from a one-time EIP-712 signature and provides limited trading authority only within Polymarket's CLOB system.
When you disconnect your wallet, the encrypted session key is permanently deleted from our systems. Your on-chain USDC approval must be revoked separately through MetaMask.
Data We DO NOT Collect
Unless you opt in to the Alpaca brokerage or Polymarket wallet integrations, we do not collect personal financial information.
- Your messages or activity from other platforms
- Your personal trading account information (unless you connect a brokerage account or wallet)
- Your actual trading positions or portfolio (unless you connect a brokerage account or wallet)
- Your financial account credentials (brokerage API keys and wallet session keys are AES-256-GCM encrypted if stored)
- Your private key, seed phrase, or MetaMask password — never, under any circumstances
2. How We Use Your Information
We use the collected information for the following purposes:
| Purpose | Description |
|---|---|
| Service Delivery | Provide access to options flow data, alerts, and analytics features |
| Account Management | Authenticate users, manage subscriptions, and maintain account security |
| Personalization | Customize alerts, save watchlists, and remember user preferences |
| Communication | Send service updates, alerts, and respond to support requests |
| Improvement | Analyze usage patterns to enhance features and fix issues |
| Security | Detect and prevent fraud, abuse, and unauthorized access |
| Legal Compliance | Meet legal obligations and respond to lawful requests |
3. Data Storage and Security
3.1 Where We Store Data
- Primary Database: Secure cloud infrastructure with encryption at rest
- Session Data: Temporary storage in secure Redis cache
- Analytics Data: Aggregated and anonymized in our secure database infrastructure
- Backups: Encrypted backups stored in geographically distributed locations
3.2 Security Measures
We implement industry-standard security measures including:
- End-to-end encryption for sensitive data transmission
- Secure OAuth 2.0 authentication through trusted providers (Discord, X, TikTok)
- Regular security audits and vulnerability assessments
- Access controls and authentication for internal systems
- Monitoring for suspicious activities and unauthorized access
- Regular updates and patches to maintain security
3.3 Breach Notification
In the event of a data breach that poses a high risk to your rights and freedoms, we commit to:
- Investigating the incident and notifying affected users without undue delay
- Sending notifications via email to your registered email address
- Notifying relevant regulatory authorities as required by applicable law (e.g., within 72 hours under GDPR, as required by state breach notification laws)
- Providing details about the nature of the breach, the data affected, and steps you can take to protect yourself
🔒 Your Security Matters
We recommend enabling two-factor authentication (2FA) on your OAuth provider account to enhance security. We also use secure session management and automatic session expiration to protect your account.
4. Information Sharing and Disclosure
We do not sell, trade, or rent your personal information. We may share your information only in these circumstances:
4.1 Service Providers (Sub-Processors)
| Provider | Purpose | Data Shared |
|---|---|---|
| Alpaca Securities LLC | Brokerage account creation, order execution | KYC data, trade orders, account info |
| Plaid Inc. | Bank account linking, ACH verification | Bank credentials (transmitted directly to Plaid, not stored by CaymanBot) |
| Stripe Inc. | Subscription payment processing | Name, email, billing address |
| Hetzner Cloud | Infrastructure hosting | All data (encrypted at rest and in transit) |
| Discord, X, TikTok | OAuth authentication | Profile info (username, email, avatar) |
| Discord | Bot notifications, alert delivery | User ID, server ID, command inputs |
| SendGrid (Twilio) | Email delivery | Email address, notification content |
| PostHog Inc. | Product analytics, feature flags | Account records (sign-up, trial, subscription); page measurement, with or without a device identifier depending on your region and your choice — see section 7.2 |
| Polymarket / CTF Exchange | Prediction market order submission and settlement | Wallet address, trade orders (submitted via CLOB API, settled on Polygon blockchain) |
Plaid bank connections require periodic reauthorization per CFPB Section 1033 open banking rules.
4.2 Legal Requirements
We may disclose information if required by law or in response to:
- Court orders or subpoenas
- Government agency requests
- Legal proceedings
- Protection of our rights and safety
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, user information may be transferred. We will notify you of any such change.
5. Data Retention
We retain your information for different periods based on its type:
| Data Type | Retention Period |
|---|---|
| Account Information | Duration of account + 90 days after deletion |
| Transaction Records | 7 years (legal requirement) |
| Usage Analytics | 2 years (anonymized) |
| Session Data | 30 days or until logout |
| Support Communications | 2 years after resolution |
6. Your Rights and Choices
6.1 Your Rights
You have the right to:
- Access: Request a copy of your personal information
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and associated data
- Portability: Receive your data in a machine-readable format
- Objection: Object to certain uses of your information
- Restriction: Request limited processing of your data
6.2 How to Exercise Your Rights
To exercise any of these rights, contact us through:
- Email: [email protected]
- Discord: Support channel in our server
6.3 Account & Data Deletion
To request deletion of your account and all associated personal data, email [email protected] from the email address associated with your account. You can also submit a request through our Discord support channel.
Upon receiving your request:
- We will verify your identity
- Your account will be deactivated immediately
- All personal data will be permanently deleted within 90 days
- You will receive confirmation once deletion is complete
7. Cookies, Local Storage, and Tracking
7.1 Essential Cookies
We use essential cookies for:
- Session management and authentication
- Security features and fraud prevention
- Remembering your preferences
7.2 Analytics
We use PostHog as our product analytics platform to understand usage patterns.
Account records. When something happens to your account — you create it, a trial starts, a subscription changes — we record that on our own servers so we can run the business and support you. These are records of events, not tracking of your device, and they are kept whatever you choose below.
Measurement in your browser. How this works depends on where you are and what you choose. There are two modes.
1. Without storing anything on your device. Nothing is written to your browser: no cookie, no local storage, no identifier. So that a single visit still holds together as one session, PostHog derives a pseudonymous identifier on its own servers instead. It is a hash of your IP address, browser user-agent and the website address you are on, combined with a random salt that is rotated and deleted every day. Because the salt is discarded, the identifier cannot be reversed. Because the website address is part of it, your visit to caymanbot.com cannot be connected to your visit to app.caymanbot.com. And because the salt changes daily, returning tomorrow makes you a new person to us.
2. With a cookie that recognises your browser. A PostHog cookie is set on .caymanbot.com and is shared between our marketing site and the app, so a visit that begins on caymanbot.com and continues in the app is understood as one person rather than two strangers. If you later sign in, that activity is linked to your account.
Which one applies to you:
- If you are in the EEA, the UK or Switzerland, mode 1 applies and nothing is stored on your device unless and until you accept.
- Elsewhere, including the United States, mode 2 applies by default and you can turn it off at any time. Turning it off clears the identifier, it does not merely stop sending.
- If we cannot tell where you are, we use mode 1.
- If your browser sends Global Privacy Control or Do Not Track, mode 1 always applies, everywhere, and overrides any earlier acceptance.
In either mode we record which pages were viewed and any campaign parameters in the link you followed, so we can tell which adverts and pages actually work. In either mode this data is used solely for service improvement and feature prioritisation, is never sold, and is subject to PostHog's privacy policy at posthog.com/privacy.
How to opt out: Use the choice shown in the banner on any page, or, once signed in, your Profile → Privacy settings by toggling off "Analytics". We also honor Global Privacy Control (GPC) browser signals, which automatically decline all non-essential storage.
7.3 Complete Storage Reference
The following table lists all cookies and local storage keys used by CaymanBot:
| Name | Type | Category | Purpose | Duration |
|---|---|---|---|---|
| cayman_session | Cookie (HttpOnly, encrypted) | Essential | User session authentication | Session |
| oauth_state | Cookie (HttpOnly, Secure) | Essential | OAuth CSRF protection | Single request |
| tradeFilters | Cookie | Essential | Remember trade filter settings | 30 days |
| caymanbot-cookie-consent | localStorage | Essential | Remember cookie consent preferences | Persistent |
| caymanbot-theme-pref | localStorage | Essential | Theme preference (light, dark, or system) | Persistent |
| caymanbot-tour | localStorage | Analytics | Track guided tour completion | Persistent |
| referral_code | localStorage | Marketing | Campaign referral attribution | Until checkout |
| ph_* | localStorage + Cookie | Analytics | PostHog user identification and session tracking. Scoped to .caymanbot.com, so it is shared between the marketing site and the app. Not set in mode 1 (section 7.2). |
1 year (cleared on opt-out) |
7.4 Email Communications
We send the following types of email communications:
- Transactional Emails: Account alerts, trade confirmations, security notices, and bank linking confirmations. These are required for service operation and cannot be opted out of.
- Marketing Emails: Newsletters, product updates, and promotional content. These are opt-in only, and every marketing email includes an unsubscribe link.
Unsubscribe requests are honored within 10 business days as required by the CAN-SPAM Act. All emails include our physical mailing address. Email delivery is handled by SendGrid (Twilio) — see our sub-processor table in Section 4.1.
8. Children's Privacy
CaymanBot is not intended for users under 18 years of age. We do not knowingly collect information from children. If we discover that a child under 18 has provided us with personal information, we will delete it immediately.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your own. These countries may have different data protection laws. We ensure appropriate safeguards are in place for such transfers.
10. California Privacy Rights (CCPA)
California residents have additional rights under the California Consumer Privacy Act (CCPA). This section provides the required disclosures.
10.1 Categories of Personal Information Collected (Last 12 Months)
- Identifiers: Username/ID and email address from your OAuth provider, IP address; for brokerage users: legal name, SSN/ITIN, date of birth, phone number, residential address
- Financial Information: Subscription payment records (via Stripe); for brokerage users: income ranges, net worth ranges, funding sources, investment experience, order execution history
- Internet/Network Activity: Usage data, browser type, session information, features accessed
- Professional/Employment Information: For brokerage users only: employment status, employer name and address, job title
- Sensitive Personal Information: For brokerage users only: SSN/ITIN (transmitted to Alpaca Securities, not stored by CaymanBot)
10.2 Sources of Personal Information
- Directly from you (account creation, form submissions, KYC onboarding)
- OAuth providers (profile information from Discord, X, or TikTok)
- Automatically via cookies, local storage, and server logs
- Third-party services (ipify.org for IP detection during brokerage onboarding)
10.3 Business Purpose for Collection
We collect personal information to provide our trading analytics service, process subscriptions, facilitate brokerage account creation (via Alpaca Securities), improve our platform, and comply with legal obligations.
10.4 Third Parties with Whom Data Is Shared
- Stripe: Payment processing
- Alpaca Securities LLC: Brokerage account creation and order execution
- Plaid Inc.: Bank account verification (if applicable)
- Cloud infrastructure providers: Service hosting
- PostHog Inc.: Product analytics (account records, and page measurement as described in section 7.2)
10.5 Your CCPA Rights
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by us
- Right to correct inaccurate personal information
- Right to opt-out of the sale of personal information
- Right to non-discrimination for exercising your privacy rights
- Right to limit use and disclosure of sensitive personal information
10.6 Do Not Sell My Personal Information
CaymanBot does not sell your personal information. We do not sell, rent, or trade any personal data to third parties for monetary or other valuable consideration. If this practice ever changes, we will update this policy and provide a clear opt-out mechanism.
If you have questions about how your data is used, contact us at [email protected].
10.7 Sensitive Personal Information
We may collect the following categories of sensitive personal information (SPI), solely for the purposes disclosed:
- SSN/ITIN: Collected from brokerage users and transmitted directly to Alpaca Securities LLC for KYC/AML compliance. Not stored by CaymanBot.
- Financial Account Information: Bank account details transmitted directly to Plaid Inc. for ACH verification. Not stored by CaymanBot.
- Encrypted API Credentials: Brokerage API keys stored with AES-256-GCM encryption for trade execution.
Use of SPI is limited to what is reasonably necessary for the specific purpose for which it was collected.
10.8 Global Privacy Control
CaymanBot honors Global Privacy Control (GPC) browser signals as valid opt-out requests under the CCPA. When we detect a GPC signal, we automatically decline non-essential cookies and storage (analytics and marketing categories).
11. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following additional provisions apply under the General Data Protection Regulation (GDPR).
11.1 Data Controller
The data controller is CaymanBot, 1111B S Governors Ave #39622, Dover, DE 19904. Contact: [email protected]
11.2 Lawful Basis for Processing
| Processing Activity | Lawful Basis |
|---|---|
| Account creation and service delivery | Contract performance (Art. 6(1)(b)) |
| KYC/AML verification (brokerage users) | Legal obligation (Art. 6(1)(c)) |
| Fraud prevention, security monitoring | Legitimate interests (Art. 6(1)(f)) |
| Marketing emails | Consent (Art. 6(1)(a)) |
| Essential cookies and session management | Contract performance (Art. 6(1)(b)) |
| Non-essential storage (analytics, marketing) | Consent (Art. 6(1)(a)) |
11.3 Cross-Border Transfers
Your data is processed on Hetzner Cloud infrastructure with EU-based servers. For transfers to US-based processors (Alpaca Securities, Plaid, Stripe), we rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs) to ensure adequate protection.
11.4 Your Additional GDPR Rights
In addition to the rights listed in Section 6, you have the right to:
- Lodge a complaint with your local supervisory authority
- Withdraw consent at any time (without affecting the lawfulness of processing based on consent before withdrawal)
- Request data portability in a structured, commonly used, machine-readable format
11.5 Automated Decision-Making
Subscription tier features are gated by plan level. We do not engage in automated profiling that produces legal or similarly significant effects on you.
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of material changes by:
- Posting the new policy on our website
- Updating the "Last Updated" date
- Sending notifications through email or Discord
13. Contact Information
For privacy-related questions or concerns:
- Email: [email protected]
- Mail: CaymanBot, 1111B S Governors Ave #39622, Dover, DE 19904
- Discord: https://discord.gg/srhedBZe7C
- Response Time: We aim to respond within 48 hours
🛡️ Our Commitment
We are committed to protecting your privacy and maintaining the security of your information. We will never sell your data, and we only use it to provide and improve our services.
14. Data Protection Officer
While we are not required to appoint a formal DPO, all privacy concerns are handled by our privacy team and can be directed to [email protected].
15. Consent
By using CaymanBot, you consent to the collection and use of your information as described in this Privacy Policy. If you do not agree with this policy, please do not use our Service.