At CaymanBot, we take your privacy seriously. This Privacy Policy describes how we collect, use, store, and protect your information when you use our trading analytics platform.

1. Information We Collect

1.1 Information You Provide

When you create an account and use CaymanBot, we collect:

1.2 Information Collected Automatically

When you use our Service, we automatically collect:

1.3 OAuth Provider Data

When you sign in using one of our supported OAuth providers (Discord, X, or TikTok), we access:

1.4 Brokerage Account Information (Alpaca Integration)

If you choose to open a brokerage account through our Alpaca Securities integration, we collect the following information as required by federal KYC/AML regulations. This data is transmitted directly to Alpaca Securities LLC and is not stored on CaymanBot servers:

What we DO store locally:

1.5 Discord Bot Data

If you interact with the CaymanBot Discord bot, we collect:

Command inputs are not persisted beyond the lifetime of the command execution. Your Discord user ID is stored only for alert preference delivery.

1.6 Polymarket Wallet Information (Prediction Market Integration)

If you connect a cryptocurrency wallet for prediction market copy-trading, we collect and store:

We NEVER collect, transmit, or store your private key, seed phrase, or MetaMask password. The CLOB session key is derived from a one-time EIP-712 signature and provides limited trading authority only within Polymarket's CLOB system.

When you disconnect your wallet, the encrypted session key is permanently deleted from our systems. Your on-chain USDC approval must be revoked separately through MetaMask.

Data We DO NOT Collect

Unless you opt in to the Alpaca brokerage or Polymarket wallet integrations, we do not collect personal financial information.

  • Your messages or activity from other platforms
  • Your personal trading account information (unless you connect a brokerage account or wallet)
  • Your actual trading positions or portfolio (unless you connect a brokerage account or wallet)
  • Your financial account credentials (brokerage API keys and wallet session keys are AES-256-GCM encrypted if stored)
  • Your private key, seed phrase, or MetaMask password — never, under any circumstances

2. How We Use Your Information

We use the collected information for the following purposes:

Purpose Description
Service Delivery Provide access to options flow data, alerts, and analytics features
Account Management Authenticate users, manage subscriptions, and maintain account security
Personalization Customize alerts, save watchlists, and remember user preferences
Communication Send service updates, alerts, and respond to support requests
Improvement Analyze usage patterns to enhance features and fix issues
Security Detect and prevent fraud, abuse, and unauthorized access
Legal Compliance Meet legal obligations and respond to lawful requests

3. Data Storage and Security

3.1 Where We Store Data

3.2 Security Measures

We implement industry-standard security measures including:

3.3 Breach Notification

In the event of a data breach that poses a high risk to your rights and freedoms, we commit to:

🔒 Your Security Matters

We recommend enabling two-factor authentication (2FA) on your OAuth provider account to enhance security. We also use secure session management and automatic session expiration to protect your account.

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information. We may share your information only in these circumstances:

4.1 Service Providers (Sub-Processors)

Provider Purpose Data Shared
Alpaca Securities LLC Brokerage account creation, order execution KYC data, trade orders, account info
Plaid Inc. Bank account linking, ACH verification Bank credentials (transmitted directly to Plaid, not stored by CaymanBot)
Stripe Inc. Subscription payment processing Name, email, billing address
Hetzner Cloud Infrastructure hosting All data (encrypted at rest and in transit)
Discord, X, TikTok OAuth authentication Profile info (username, email, avatar)
Discord Bot notifications, alert delivery User ID, server ID, command inputs
SendGrid (Twilio) Email delivery Email address, notification content
PostHog Inc. Product analytics, feature flags Account records (sign-up, trial, subscription); page measurement, with or without a device identifier depending on your region and your choice — see section 7.2
Polymarket / CTF Exchange Prediction market order submission and settlement Wallet address, trade orders (submitted via CLOB API, settled on Polygon blockchain)

Plaid bank connections require periodic reauthorization per CFPB Section 1033 open banking rules.

4.2 Legal Requirements

We may disclose information if required by law or in response to:

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, user information may be transferred. We will notify you of any such change.

5. Data Retention

We retain your information for different periods based on its type:

Data Type Retention Period
Account Information Duration of account + 90 days after deletion
Transaction Records 7 years (legal requirement)
Usage Analytics 2 years (anonymized)
Session Data 30 days or until logout
Support Communications 2 years after resolution

6. Your Rights and Choices

6.1 Your Rights

You have the right to:

6.2 How to Exercise Your Rights

To exercise any of these rights, contact us through:

6.3 Account & Data Deletion

To request deletion of your account and all associated personal data, email [email protected] from the email address associated with your account. You can also submit a request through our Discord support channel.

Upon receiving your request:

  1. We will verify your identity
  2. Your account will be deactivated immediately
  3. All personal data will be permanently deleted within 90 days
  4. You will receive confirmation once deletion is complete

7. Cookies, Local Storage, and Tracking

7.1 Essential Cookies

We use essential cookies for:

7.2 Analytics

We use PostHog as our product analytics platform to understand usage patterns.

Account records. When something happens to your account — you create it, a trial starts, a subscription changes — we record that on our own servers so we can run the business and support you. These are records of events, not tracking of your device, and they are kept whatever you choose below.

Measurement in your browser. How this works depends on where you are and what you choose. There are two modes.

1. Without storing anything on your device. Nothing is written to your browser: no cookie, no local storage, no identifier. So that a single visit still holds together as one session, PostHog derives a pseudonymous identifier on its own servers instead. It is a hash of your IP address, browser user-agent and the website address you are on, combined with a random salt that is rotated and deleted every day. Because the salt is discarded, the identifier cannot be reversed. Because the website address is part of it, your visit to caymanbot.com cannot be connected to your visit to app.caymanbot.com. And because the salt changes daily, returning tomorrow makes you a new person to us.

2. With a cookie that recognises your browser. A PostHog cookie is set on .caymanbot.com and is shared between our marketing site and the app, so a visit that begins on caymanbot.com and continues in the app is understood as one person rather than two strangers. If you later sign in, that activity is linked to your account.

Which one applies to you:

In either mode we record which pages were viewed and any campaign parameters in the link you followed, so we can tell which adverts and pages actually work. In either mode this data is used solely for service improvement and feature prioritisation, is never sold, and is subject to PostHog's privacy policy at posthog.com/privacy.

How to opt out: Use the choice shown in the banner on any page, or, once signed in, your Profile → Privacy settings by toggling off "Analytics". We also honor Global Privacy Control (GPC) browser signals, which automatically decline all non-essential storage.

7.3 Complete Storage Reference

The following table lists all cookies and local storage keys used by CaymanBot:

Name Type Category Purpose Duration
cayman_session Cookie (HttpOnly, encrypted) Essential User session authentication Session
oauth_state Cookie (HttpOnly, Secure) Essential OAuth CSRF protection Single request
tradeFilters Cookie Essential Remember trade filter settings 30 days
caymanbot-cookie-consent localStorage Essential Remember cookie consent preferences Persistent
caymanbot-theme-pref localStorage Essential Theme preference (light, dark, or system) Persistent
caymanbot-tour localStorage Analytics Track guided tour completion Persistent
referral_code localStorage Marketing Campaign referral attribution Until checkout
ph_* localStorage + Cookie Analytics PostHog user identification and session tracking. Scoped to .caymanbot.com, so it is shared between the marketing site and the app. Not set in mode 1 (section 7.2). 1 year (cleared on opt-out)

7.4 Email Communications

We send the following types of email communications:

Unsubscribe requests are honored within 10 business days as required by the CAN-SPAM Act. All emails include our physical mailing address. Email delivery is handled by SendGrid (Twilio) — see our sub-processor table in Section 4.1.

8. Children's Privacy

CaymanBot is not intended for users under 18 years of age. We do not knowingly collect information from children. If we discover that a child under 18 has provided us with personal information, we will delete it immediately.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your own. These countries may have different data protection laws. We ensure appropriate safeguards are in place for such transfers.

10. California Privacy Rights (CCPA)

California residents have additional rights under the California Consumer Privacy Act (CCPA). This section provides the required disclosures.

10.1 Categories of Personal Information Collected (Last 12 Months)

10.2 Sources of Personal Information

10.3 Business Purpose for Collection

We collect personal information to provide our trading analytics service, process subscriptions, facilitate brokerage account creation (via Alpaca Securities), improve our platform, and comply with legal obligations.

10.4 Third Parties with Whom Data Is Shared

10.5 Your CCPA Rights

10.6 Do Not Sell My Personal Information

CaymanBot does not sell your personal information. We do not sell, rent, or trade any personal data to third parties for monetary or other valuable consideration. If this practice ever changes, we will update this policy and provide a clear opt-out mechanism.

If you have questions about how your data is used, contact us at [email protected].

10.7 Sensitive Personal Information

We may collect the following categories of sensitive personal information (SPI), solely for the purposes disclosed:

Use of SPI is limited to what is reasonably necessary for the specific purpose for which it was collected.

10.8 Global Privacy Control

CaymanBot honors Global Privacy Control (GPC) browser signals as valid opt-out requests under the CCPA. When we detect a GPC signal, we automatically decline non-essential cookies and storage (analytics and marketing categories).

11. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following additional provisions apply under the General Data Protection Regulation (GDPR).

11.1 Data Controller

The data controller is CaymanBot, 1111B S Governors Ave #39622, Dover, DE 19904. Contact: [email protected]

11.2 Lawful Basis for Processing

Processing Activity Lawful Basis
Account creation and service delivery Contract performance (Art. 6(1)(b))
KYC/AML verification (brokerage users) Legal obligation (Art. 6(1)(c))
Fraud prevention, security monitoring Legitimate interests (Art. 6(1)(f))
Marketing emails Consent (Art. 6(1)(a))
Essential cookies and session management Contract performance (Art. 6(1)(b))
Non-essential storage (analytics, marketing) Consent (Art. 6(1)(a))

11.3 Cross-Border Transfers

Your data is processed on Hetzner Cloud infrastructure with EU-based servers. For transfers to US-based processors (Alpaca Securities, Plaid, Stripe), we rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs) to ensure adequate protection.

11.4 Your Additional GDPR Rights

In addition to the rights listed in Section 6, you have the right to:

11.5 Automated Decision-Making

Subscription tier features are gated by plan level. We do not engage in automated profiling that produces legal or similarly significant effects on you.

12. Changes to This Privacy Policy

We may update this Privacy Policy periodically. We will notify you of material changes by:

13. Contact Information

For privacy-related questions or concerns:

🛡️ Our Commitment

We are committed to protecting your privacy and maintaining the security of your information. We will never sell your data, and we only use it to provide and improve our services.

14. Data Protection Officer

While we are not required to appoint a formal DPO, all privacy concerns are handled by our privacy team and can be directed to [email protected].

15. Consent

By using CaymanBot, you consent to the collection and use of your information as described in this Privacy Policy. If you do not agree with this policy, please do not use our Service.