Privacy policy

Data controller

Online Hospitality SARL, Rue Loubnane, Immeuble 10, Appartement 15, Guéliz, Marrakech, Maroc, publisher of PIPSTER PRO, is the controller of the data described below. For any question about your data: privacy@pipster.ch.

Applicable legislation

As the publisher is established in Morocco, processing falls under Law No. 09-08 on the protection of individuals with regard to the processing of personal data, supervised by the National Commission for the Control of Personal Data Protection (CNDP). As the Service is also offered to people residing in the European Economic Area, the General Data Protection Regulation (GDPR) applies to processing concerning them, by virtue of its article 3(2).

Data collected

  • Account: email address, display name where you provide one, password stored as a cryptographic hash, address confirmation status.
  • Subscription: plan, modules, billing period, status, period dates, Stripe identifiers (customer, subscription, invoice).
  • Technical and security: IP address and user agent at sign-in, sign-in dates, authentication attempts, persistent session tokens, audit log of sensitive actions.
  • Usage: instruments and timeframes viewed, modules opened, requests made — for security, load measurement and enforcement of your plan's limits.
  • Audience and journey measurement: the steps you take within the service — opening the pricing page, being shown an offer, clicking an element reserved for a higher plan, reaching a limit, leaving for payment, days of actual use. These events are recorded by our own servers, linked to your account when you are signed in, and are used to understand where the product gets in the way and to decide how it should evolve.
  • Preferences: terminal and display settings, alerts enabled, saved drawings, and the capital and risk percentage you enter for position sizing.
  • Google sign-in, if you use it: your Google account identifier, your email address, your name and the address of your profile picture, passed on by Google at the moment you agree to sign in. No other access to your Google account is requested or obtained.
  • Referral, where applicable: the code of the affiliate who directed you to the service, so that the commission due to them can be attributed.

No banking data is collected by the publisher: payment is entirely delegated to Stripe. The capital you enter to size your positions is used solely for the calculation shown on screen; it is neither passed to a third party nor used for any other purpose.

Purposes and legal bases

  • Providing the Service and managing the account — performance of the contract.
  • Invoicing, accounting and tax obligations — legal obligation.
  • Security, prevention of abuse, account sharing and fraudulent access — legitimate interest.
  • Audience measurement and product improvement — legitimate interest; you may object at any time (see "Your rights").
  • Service information: incidents, changes, subscription expiry — performance of the contract.
  • Marketing communications — consent, revocable at any time and without effect on the service.

Retention periods

  • Account data: for the lifetime of the account, then deleted within thirty days.
  • Sign-in logs and authentication attempts: twelve months.
  • Journey and audience measurement events: twenty-four months, then deleted.
  • Accounting records: ten years, in accordance with legal obligations.

Processors and recipients

  • Stripe (payment, invoicing and subscription portal) — Ireland and United States, covered by standard contractual clauses.
  • OVH SAS, 2 rue Kellermann, 59100 Roubaix, France — hosting of the website and the database.
  • Market data providers (OANDA, Twelve Data, Coinbase, Yahoo Finance): they receive quote requests issued by our servers, with no identifying personal data. The real-time crypto feed is the exception: it connects the visitor's browser directly to Coinbase, which therefore receives their IP address.
  • Google Ireland Ltd., for "Sign in with Google" — Ireland and United States, standard contractual clauses. As the sign-in library is loaded from Google's servers, Google receives your IP address and user agent on pages where the button is displayed, whether or not you use it.
  • Anthropic PBC, for artificial-intelligence assistance and analysis features when you call on them — United States. Only the content of your request and the market context displayed are transmitted; neither your identity, nor your email address, nor your payment data.
  • An email delivery provider, for the service messages you receive.

No personal data is sold or rented to third parties. Transfers outside Morocco and the European Economic Area are covered by standard contractual clauses or an equivalent mechanism.

Cookies and local storage

The Service sets only cookies necessary for it to work: a session cookie, a "stay signed in" cookie if you ask for one, a language cookie, a cookie identifying the account-free trial, and a referral cookie if you arrived through an affiliate link. No advertising cookie is set and no third-party tracker is loaded for advertising purposes.

The journey measurement described above does not rely on third-party cookies: it is recorded by our own servers, from the pages you open and the actions you take within the service.

Your display settings, drawings and terminal preferences are saved in your browser's local storage; they reach our servers only if you are signed in and account synchronisation is active.

Google sign-in is an exception on one point: it relies on a library served by Google, which may read or set cookies on Google's domains in order to recognise an already-open Google session. Those cookies are neither set nor readable by the publisher and are not used to track you on this site.

Your rights

You have a right of access, rectification, erasure, restriction, objection and portability regarding your data, as well as the right to withdraw consent already given. You may exercise these rights from your account area or by writing to privacy@pipster.ch; a reply is given within one month.

If the reply does not satisfy you, you may refer the matter to the National Commission for the Control of Personal Data Protection (CNDP), the competent authority at the publisher's place of establishment.

Where the GDPR applies to your situation, you may in addition lodge a complaint with the supervisory authority of your country of residence in the European Economic Area. Residents of Switzerland may contact the Federal Data Protection and Information Commissioner.

Security

HTTPS-encrypted exchanges, passwords stored as hashes, session tokens renewed at each sign-in, rate limiting on authentication attempts, secrets encrypted at rest, a database located outside the web root, and an audit log of sensitive actions.

Minors

The Service is not intended for minors and no account may be opened by a person who is not of legal age and legal capacity. No data is knowingly collected from a minor.