← Back to PineconeX

Privacy Policy

Effective date: 20 June 2026

PineconeX (“we”, “us”, “our”) operates the PineconeX platform at pineconex.com. This policy explains what personal data we collect, why we collect it, and who we share it with. If you have questions, email us at info@pineconex.com.

1. Data we collect

Account informationName, email address, profile pictureGoogle or GitHub OAuth sign-in
GitHub identityGitHub user ID, encrypted OAuth access token, linked repository nameGitHub sign-in and strategy file sync (only if you use GitHub)
Strategy codePine Script source you paste or typeRunning backtests and live bots
Job configurationSymbol, timeframe, parameter ranges, broker choiceExecuting and displaying your results
Job resultsTrade logs, equity curves, performance metricsDisplaying backtest and sweep output
Live bot activityLifecycle events (started, stopped, crashed, restarted) and the bot's own session output file (trade log and metrics)Showing your bots' status and history
Broker credentialsAPI keys / OAuth tokens for Saxo Bank, Lightspeed, or AlpacaPlacing live orders on your behalf
Billing informationPayment method, invoice historyProcessed by Stripe — we never see your card number
Usage dataPages visited, features used, error logsImproving the platform and diagnosing bugs
Security & abuse monitoringStrategy-validation outcomes (pass/fail counts) and interpreter crash or timeout events linked to your accountDetecting and preventing attempts to exploit, fuzz, or overload the platform
Auth sessionHTTP-only session cookieKeeping you signed in

We do not continuously track, stream, or store your live trading profit and loss. Your strategy runs in your own connected broker account; we retain only the bot's lifecycle events and its session output file, both deleted when you delete the job or your account. If you want ongoing P&L tracking, your strategy can send it to a destination of your choice (for example a Telegram alert).

2. Legal basis (GDPR)

We process your data under the following bases:

  • Contract — account data, strategy code, job config, and results are necessary to provide the service you signed up for.
  • Consent — broker credentials are stored only when you explicitly connect a broker and can be removed at any time.
  • Legitimate interest — usage data, error logs, and security & abuse monitoring (including strategy-validation crash patterns), to keep the platform secure, stable, and protected against exploitation.
  • Legal obligation — billing records, as required by tax law.

3. Who we share your data with

We do not sell your data. We share it only with the following sub-processors, each bound by their own data processing agreements:

Sub-processorPurposePrivacy info
GoogleOAuth sign-in (identity only — we do not access your Drive, Gmail, or Calendar)google.com/privacy
GitHubOAuth sign-in and strategy file sync from a linked repository. We store your GitHub user ID, an encrypted OAuth access token, and the name of any repo you choose to link. We only read repository content — we never write to your repos.docs.github.com/site-policy/privacy-policies/github-general-privacy-statement
StripePayment processing and invoicingstripe.com/privacy
MassiveHistorical market data for backtestingmassive.com
Saxo BankLive order execution (only when you connect your Saxo account)home.saxo/privacy
LightspeedLive order execution (only when you connect your Lightspeed account)lightspeed.com/privacy
AlpacaLive order execution (only when you connect your Alpaca account)alpaca.markets/privacy
TelegramDelivering live-bot signal and lifecycle notifications (only when you enable Telegram notifications)telegram.org/privacy

We run our own infrastructure for backtest and live-bot execution — no third-party cloud provider processes your strategy code or trading results.

If you configure a webhook for notifications, your bot's signals and lifecycle events are sent to the URL you choose. That endpoint is under your control, not ours, and is not a PineconeX sub-processor — you are responsible for how the data is handled once it arrives there.

4. Broker credentials

When you connect a broker, we encrypt your credentials at rest using ChaCha20-Poly1305 with a master key that never leaves our servers. Credentials are decrypted only at job launch time and are passed directly to the isolated job container. No credential is logged or retained beyond the lifetime of the job.

You can disconnect a broker at any time from the Live page, which permanently deletes the stored credentials from our database.

5. Data retention

DataRetention
Account and profileUntil you delete your account
StrategiesUntil you delete them or delete your account
Job resultsUntil you delete them or delete your account
Broker credentialsUntil you disconnect the broker or delete your account
Billing records7 years (legal requirement)
Error and usage logs90 days, then automatically purged
Security & abuse monitoringAnonymised when you delete your account; aggregate counts may be retained for security analysis

6. Your rights (GDPR)

If you are in the EEA or UK, you have the right to:

  • Access — request a copy of all data we hold about you.
  • Portability — receive your data in a machine-readable format.
  • Rectification — correct inaccurate data.
  • Erasure — delete your account and all associated data.
  • Restriction — ask us to stop processing your data while a dispute is resolved.
  • Object — object to processing based on legitimate interest.

To exercise any of these rights, email privacy@pineconex.com or use the account deletion feature in your account settings (once available). We will respond within 30 days.

You also have the right to lodge a complaint with your local supervisory authority (in Belgium: the Gegevensbeschermingsautoriteit).

7. Cookies

We use a single HTTP-only session cookie to keep you signed in. We do not use advertising cookies, tracking pixels, or third-party analytics scripts. No cookie consent banner is shown because the only cookie is strictly necessary for the service to function.

8. Security

Credentials are encrypted at rest. Communication between your browser and our servers uses TLS. Job containers are isolated and have no network access beyond what is required to connect to your broker. We keep dependencies updated and run regular security reviews.

9. Changes to this policy

We may update this policy as the platform evolves. If we make material changes, we will notify you by email or by a notice in the app at least 14 days before the change takes effect. The effective date at the top of this page always reflects the current version.

PineconeX — questions: privacy@pineconex.com

© 2026 PineconeX.

This site is maintained by © 2026 Dalidophe B.V. All rights reserved.