← Back to PineconeX

Privacy Policy

Effective date: 20 June 2026

PineconeX (“we”, “us”, “our”) operates the PineconeX platform at pineconex.com. This policy explains what personal data we collect, why we collect it, and who we share it with. If you have questions, email us at info@pineconex.com.

1. Data we collect

Account informationName, email address, profile pictureGoogle or GitHub OAuth sign-in
GitHub identityGitHub user ID, encrypted OAuth access token, linked repository nameGitHub sign-in and strategy file sync (only if you use GitHub)
Strategy codePine Script source you paste or typeRunning backtests and live bots
Job configurationSymbol, timeframe, parameter ranges, broker choiceExecuting and displaying your results
Job resultsTrade logs, equity curves, performance metricsDisplaying backtest and sweep output
Live bot activityLifecycle events (started, stopped, crashed, restarted) and the bot's own session output file (trade log and metrics)Showing your bots' status and history
Broker credentialsAPI keys / OAuth tokens for Saxo Bank, Lightspeed, Alpaca, or BitstampPlacing live orders on your behalf
Billing informationPayment method, invoice historyProcessed by Stripe; we never see your card number
Usage dataPages visited, features used, error logsImproving the platform and diagnosing bugs
Security & abuse monitoringStrategy-validation outcomes (pass/fail counts) and interpreter crash or timeout events linked to your accountDetecting and preventing attempts to exploit, fuzz, or overload the platform
Auth sessionHTTP-only session cookieKeeping you signed in

We do not continuously track, stream, or store your live trading profit and loss. Your strategy runs in your own connected broker account; we retain only the bot's lifecycle events and its session output file, both deleted when you delete the job or your account. If you want ongoing P&L tracking, your strategy can send it to a destination of your choice (for example a Telegram alert).

2. Legal basis (GDPR)

We process your data under the following bases:

  • Contract: account data, strategy code, job config, and results are necessary to provide the service you signed up for.
  • Consent: broker credentials are stored only when you explicitly connect a broker and can be removed at any time.
  • Legitimate interest: usage data, error logs, and security & abuse monitoring (including strategy-validation crash patterns), to keep the platform secure, stable, and protected against exploitation.
  • Legal obligation: billing records, as required by tax law.

3. Who we share your data with

We do not sell your data. We share it only with the following sub-processors, each bound by their own data processing agreements:

Sub-processorPurposePrivacy info
CombellEU cloud hosting for our application servers and database; stores your account, strategies, and job resultscombell.com
GoogleOAuth sign-in (identity only; we do not access your Drive, Gmail, or Calendar)google.com/privacy
GitHubOAuth sign-in and strategy file sync from a linked repository. We store your GitHub user ID, an encrypted OAuth access token, and the name of any repo you choose to link. We only read repository content and never write to your repos.docs.github.com/site-policy/privacy-policies/github-general-privacy-statement
StripePayment processing and invoicingstripe.com/privacy
MassiveHistorical market data for backtestingmassive.com
Saxo BankLive order execution (only when you connect your Saxo account)home.saxo/privacy
LightspeedLive order execution (only when you connect your Lightspeed account)lightspeed.com/privacy
AlpacaLive order execution (only when you connect your Alpaca account)alpaca.markets/privacy
BitstampLive order execution (only when you connect your Bitstamp account)bitstamp.net/privacy-policy
HetznerHosting for Dedicated VPS instances (only if you purchase a Dedicated VPS), in your chosen EU or US regionhetzner.com/legal/privacy-policy
TelegramDelivering live-bot signal and lifecycle notifications (only when you enable Telegram notifications)telegram.org/privacy

Our application servers and database are hosted by Combell in EU data centres (ISO 27001). On the shared platform, backtest and live-bot execution runs on our own on-premise infrastructure: no third-party cloud provider executes your strategies or holds your broker credentials during trading. On a Dedicated VPS, execution and your broker credentials are isolated to your own single-tenant instance, hosted by Hetzner in your chosen EU or US region.

If you configure a webhook for notifications, your bot's signals and lifecycle events are sent to the URL you choose. That endpoint is under your control, not ours, and is not a PineconeX sub-processor. You are responsible for how the data is handled once it arrives there.

4. Broker credentials

When you connect a broker, we encrypt your credentials at rest using ChaCha20-Poly1305 with a master key that never leaves our servers. They are decrypted only at job launch time and passed directly to the isolated job container; the decrypted copy is never logged and is not retained beyond the lifetime of the job.

We delete your stored broker credentials from our database when you disconnect a broker, log out, or delete your account. A credential in active use by a running bot is held on the execution host only for the lifetime of that bot. You can disconnect a broker at any time from the Live page.

5. Data retention

DataRetention
Account and profileUntil you delete your account
StrategiesUntil you delete them or delete your account
Job resultsUntil you delete them or delete your account
Broker credentialsRemoved when you disconnect the broker, log out, or delete your account
Billing records7 years (legal requirement)
Error and usage logs90 days, then automatically purged
Security & abuse monitoringAnonymised when you delete your account; aggregate counts may be retained for security analysis

6. Your rights (GDPR)

If you are in the EEA or UK, you have the right to:

  • Access: request a copy of all data we hold about you.
  • Portability: receive your data in a machine-readable format.
  • Rectification: correct inaccurate data.
  • Erasure: delete your account and all associated data.
  • Restriction: ask us to stop processing your data while a dispute is resolved.
  • Object: object to processing based on legitimate interest.

To exercise any of these rights, email privacy@pineconex.com or use the account deletion feature in your account settings (once available). We will respond within 30 days.

You also have the right to lodge a complaint with your local supervisory authority (in Belgium: the Gegevensbeschermingsautoriteit).

7. Cookies

We use a single HTTP-only session cookie to keep you signed in. We do not use advertising cookies, tracking pixels, or third-party analytics scripts. No cookie consent banner is shown because the only cookie is strictly necessary for the service to function.

8. Security

Credentials are encrypted at rest. Communication between your browser and our servers uses TLS. Job containers are isolated and have no network access beyond what is required to connect to your broker. We keep dependencies updated and run regular security reviews.

9. Changes to this policy

We may update this policy as the platform evolves. If we make material changes, we will notify you by email or by a notice in the app at least 14 days before the change takes effect. The effective date at the top of this page always reflects the current version.

PineconeX — questions: privacy@pineconex.com

Dalidophe BV · VAT BE 0886.643.940 · info@pineconex.com

© 2026 PineconeX.

This site is maintained by © 2026 Dalidophe BV All rights reserved.