MeridianMarketFlow
Sign in
Draft — pending owner review. Not yet in force. This text is a working draft written for review. It has not been checked by a lawyer, the bracketed placeholders are not yet filled in, and nothing here is binding on you or on us until the final version is published.

Privacy Policy

MeridianMarketFlow, operated by [Company legal name] (“we”, “us”). Draft of September 2026 — no version is in force yet.

1. Who is responsible for your data

[Company legal name], [Registered address] is the controller of the personal data described here. For questions or to exercise any right below, message the Telegram bot — that is the channel we monitor. [Placeholder: data protection contact email, and whether an EU representative under GDPR Art. 27 is appointed.]

2. What we hold, and why

We do not hold your broker credentials, your account numbers, or your money. We place no trades: every order is entered by you, at your own broker, so we have no connection to it and nothing to store about it. We do not ask for identity documents. We do not knowingly collect data from anyone under 18.

3. Where your data goes

We do not sell your data, we do not share it with advertisers, and we do not use it to train models about you.

4. International transfers

Some of these providers are outside the EEA. Where that is the case, transfers are made under the European Commission's Standard Contractual Clauses (2021/914), together with the technical measures described below (encryption in transit, access limited to the operator). You can ask us for a copy of the safeguards in place for a specific provider.

5. If you are in the EU or the UK

You have the right to: access a copy of your data; rectify anything wrong; erase your data ("be forgotten"); restrict or object to our processing, including processing based on legitimate interests; portability of the data you gave us, in a machine-readable form; and to withdraw consent where we rely on it, without affecting what came before.

Your closed-trade history is already exportable yourself, at any time, from Settings → Export your records. For anything else, message the bot; we will answer within one month. You may also complain to your national supervisory authority — in the UK, the Information Commissioner's Office.

We make no automated decisions that produce legal effects for you. Position sizing is arithmetic applied to the budget you declared, not a profile built about you.

6. How long we keep it

An erasure request removes the account data; we may keep the minimum needed for legal or accounting obligations, and we will tell you what that is.

7. How we protect it

Passwords are stored as bcrypt hashes, never in readable form — we cannot see yours, which is why a reset sends a code rather than your old password. Reset codes are hashed too, expire in 15 minutes, are single-use, and stop working after five wrong guesses. Sessions are signed cookies, HttpOnly, and carried over TLS once the portal is public. Access to the database is limited to the operator.

[Placeholder: breach-notification commitment — GDPR requires notifying the supervisory authority within 72 hours and affected people without undue delay where the risk is high.]

8. Cookies

One cookie: your sign-in session. It is strictly necessary for the portal to work, sets no identifier for advertising, and is not shared. We run no analytics, no tracking pixels and no third-party advertising.

9. Governing law

This notice is governed by the data protection law of [Jurisdiction], alongside the GDPR where it applies to you. Nothing here removes a right you have under the law of the country you live in.

10. Changes

If we change how we use your data in a way that matters, we will tell you through the bot before it takes effect.

Questions about this document? Message the bot in Telegram — it reaches the operator directly. We do not run a separate support inbox.

Terms of Service · Privacy Policy · Risk Disclosure · Back to the app