Zonelytix legal
Privacy policy
Version 1.1 · Last updated
This policy explains what personal data Zonelytix collects, why, and what you can do about it. If you sign in with Google, Zonelytix receives only your name, email address and profile picture from your Google account and uses them only to create your account and sign you in (see section 2). We do not sell personal data, we do not share Google user data with third parties, and we do not show advertising.
Contents
- 1. Who we are and what this covers
- 2. Google user data (Sign in with Google)
- 3. Data we collect
- 4. Why we use it and on what basis
- 5. AI features and your data
- 6. Who we share it with
- 7. What is public
- 8. International transfers
- 9. How long we keep it
- 10. Your rights: export, deletion and more
- 11. Your choices
- 12. California and other US state rights
- 13. Automated decisions and profiling
- 14. Security and breach notification
- 15. Children
- 16. Cookies
- 17. Changes
- 18. Contact and representatives
1. Who we are and what this covers
Zonelytix (“Zonelytix”, “we”) is the data controller for personal data processed through zonelytix.com, the Zonelytix web app, the Telegram bot and channel, the API and webhooks, and the Zonelytix Bridge Expert Advisor. Zonelytix is the trading name of the company that operates the Service. Its registered details are available on request at legal@zonelytix.com.
This policy applies to all of them. It does not cover your broker, your prop firm, Telegram, Whop or any other service you use alongside Zonelytix; each has its own policy. Where this policy refers to the GDPR it means the EU General Data Protection Regulation and the UK GDPR together.
2. Google user data (Sign in with Google)
Zonelytix offers “Sign in with Google”. When you use it, Zonelytix accesses the following Google user data: your name, your email address, your profile picture and your Google account ID. This section explains how Zonelytix accesses, uses, stores, shares, protects, retains and deletes that data. It applies only if you choose Google sign-in.
Data accessed
When you approve the Google consent screen, Google shares with us: your name, your email address, your profile picture and a Google account identifier. These come from the openid, email and profile scopes. We do not request or receive any other Google data: no Gmail messages, contacts, calendar, Drive files, YouTube, location or payment information.
Data usage
We use this data only to create your Zonelytix account, sign you in, and show your name and picture in your own profile. Your Google email becomes your account email for service messages (sign-in links, billing and account notices). We do not use Google user data for advertising, to build marketing profiles, to train AI or machine-learning models, or for any purpose unrelated to signing you in.
Data sharing
We do not sell, rent or trade Google user data. We do not share it with third parties, except the service providers that host our authentication and database on our behalf (listed in our subprocessors), who process it only to provide sign-in, and where the law requires us to disclose it.
Data storage and protection
Google user data is stored with your account in our database, encrypted in transit (TLS) and at rest, with access limited to the server-side systems that need it and to authorised staff under audit logging. We never receive or store your Google password. Sign-in uses Google’s OAuth 2.0 flow with PKCE.
Data retention and deletion
We keep Google user data for as long as your Zonelytix account exists. You can delete your account at any time in Settings → Data → “Delete my account”; your name, email, profile picture and Google identifier are then deleted within 30 days, except where the law requires us to keep a record (see “How long we keep it”). You can also ask us to delete it by emailing privacy@zonelytix.com. To stop Google sharing data with us, remove Zonelytix at myaccount.google.com → Security → Third-party connections; set a password in Settings first if you want to keep signing in.
Zonelytix’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Data we collect
Most of this you give us directly. Technical data is collected automatically when you use the Service. Billing identifiers come from Whop. Fills, balances and heartbeats come from the Expert Advisor you run.
We do not collect broker credentials, and we cannot: the EA talks to your broker locally and only reports fills, balances and account numbers back to us. We do not ask for identity documents unless a payout, a legal obligation or a fraud investigation requires it. We do not collect special-category data such as health, religion or political opinions, and we ask you not to put it in posts or support messages.
4. Why we use it and on what basis
- To provide the Service you signed up for: computing and delivering signals within your plan, running the EA bridge, the journal, the simulator, the playbook and the community features. Basis: performance of a contract.
- To bill you and keep accounts. Basis: contract and legal obligation.
- To keep the Service secure: detecting abuse, duplicate accounts, vote rings, leaked signals and compromised keys; protecting licence keys and API keys. Basis: legitimate interest in protecting the Service and its members.
- To meet legal obligations: sanctions screening of reward wallets, tax and accounting records, responding to lawful requests from authorities, keeping evidence of your agreement to the terms. Basis: legal obligation.
- To improve the engine: scored community zones and anonymised signal outcomes are used as training and evaluation data. Basis: contract (you agree to this when you submit a zone) and legitimate interest in improving the model.
- To tell you about the Service: operational messages (signals, digests, renewal, security, EA offline, changes to terms) are part of the Service. Product news is sent only if you opt in, and you can opt out at any time. Basis: contract; consent for product news.
- To measure the site with privacy-friendly analytics, if enabled, as described in the Cookie policy. Basis: consent where required, otherwise legitimate interest.
- To answer you when you contact support. Basis: contract and legitimate interest.
Where we rely on legitimate interest we have balanced it against your rights, and you can object as described under Your rights. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it for advertising at all.
5. AI features and your data
Zone explanations, outlooks and Ask AI answers are generated by a third-party large language model provider acting as our processor. We send the model structured zone and signal data and, for Ask AI, the text of your question. We do not send your name, email, account identifiers, balance or trades. Our agreement with the provider prohibits it from using the data to train its models and limits retention to what is needed to produce the answer and detect abuse.
Please do not type personal data about yourself or anyone else into Ask AI. Questions are kept linked to your account for 90 days for rate limiting and abuse detection, then anonymised or deleted. AI output is not used to make decisions about you.
7. What is public
Your auto-generated username, rank, monthly score, zone accuracy, badge and top-10 history on the leaderboard; your username next to shipped ideas and community zones; and the public track record, which contains signals and outcomes but never any member’s trades, balance or identity. Prize amounts, wallet addresses, transaction hashes, email addresses and real names are never public. Share cards you create from the simulator contain only what is shown on the card.
8. International transfers
Our processors may store or process data outside your country, including in the United States. Where data leaves the EEA, the UK or Switzerland we rely on an adequacy decision (including the EU-US Data Privacy Framework and the UK extension where the recipient is certified), or on the European Commission’s standard contractual clauses and the UK International Data Transfer Addendum, together with a transfer risk assessment and supplementary measures where needed. Ask us at privacy@zonelytix.com for a copy of the relevant safeguard.
9. How long we keep it
Backups are rotated within 30 days. Where we keep data after deletion because a legal obligation or a claim requires it, we restrict it to that purpose.
10. Your rights: export, deletion and more
Depending on where you live, including under the GDPR, you have the right to access your personal data, to correct it, to receive a copy in a portable format, to restrict or object to processing, to withdraw consent at any time without affecting earlier processing, and to have your data deleted. Two of these are built into the app:
- Export: Settings → Data → “Export my data” produces a machine-readable file with your account, settings, trades, journal, community activity and payouts.
- Delete: Settings → Data → “Delete my account” closes the account, revokes EA licence keys and API keys, disconnects Telegram and deletes personal data within 30 days, keeping only what the retention section requires. Your username is removed from community zones and leaderboard history is anonymised.
For anything else, email privacy@zonelytix.com from your account address. We may ask you to confirm your identity through the account. We answer within one month, extendable by two months for complex requests, and we do not charge unless a request is manifestly unfounded or excessive. You may also complain to your data protection authority; in the EEA that is the authority of your country of residence, and in the UK it is the Information Commissioner’s Office.
11. Your choices
- Notifications: each channel and each type of message is controlled in Settings → Notifications. Operational security messages cannot be turned off while the account is open.
- Product news: opt in or out in Settings or with the unsubscribe link in any marketing email.
- Telegram: disconnect at any time in Settings; the bot stops immediately.
- Public profile: you can leave the leaderboard by closing your account; usernames are never your real name.
- Analytics: if enabled, our provider is cookieless and honours the Global Privacy Control and Do Not Track signals.
- Google sign-in: you can revoke Zonelytix in your Google account; set a password first so you can still sign in.
12. California and other US state rights
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon or another US state with a comprehensive privacy law, you may have the right to know what personal information we collect, use and disclose, to access and delete it, to correct it, to obtain a portable copy, to opt out of its sale, sharing or use for targeted advertising or certain profiling, and not to be discriminated against for exercising these rights. We do not sell personal information, do not share it for cross-context behavioural advertising and do not use it for targeted advertising, so there is nothing to opt out of; we honour Global Privacy Control signals regardless. The categories of personal information we collect and the purposes are listed in Data we collect; the categories of third parties are in Who we share it with. To exercise a right, use the in-app export and deletion tools or email privacy@zonelytix.com; an authorised agent may act for you with written permission. If we deny a request you may appeal by replying to our decision.
13. Automated decisions and profiling
Signals are generated from market data, not from your personal data, and are the same for every member on the same plan. Automated systems do score community zones, detect duplicate accounts and vote rings, and apply plan limits; the top 10 and every fraud finding are reviewed by a person before a reward is paid or withheld, and you can contest a decision through support. We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.
14. Security and breach notification
Data is encrypted in transit (TLS) and at rest. Passwords are hashed with a modern algorithm. Two-factor authentication is available and is required to change a reward wallet. EA licence keys are signed and tied to specific MT5 account numbers; API keys are shown once and stored hashed. Row-level security limits each member to their own data. Access to production data is limited to staff who need it and is logged. We keep a vulnerability disclosure programme described on the Responsible disclosure page.
No system is perfectly secure. If a personal data breach is likely to put your rights at risk we will notify you without undue delay, and we will notify the competent authority within 72 hours of becoming aware where the law requires it.
15. Children
The Service is for adults. We do not knowingly collect data from anyone under 18. If you believe a minor has an account, contact us and we will delete it.
17. Changes
We may update this policy. Material changes are announced in the app or by email before they take effect, and we will ask for consent again where a change needs it. The version number and date at the top identify the current version.
18. Contact and representatives
Privacy questions and requests: privacy@zonelytix.com. General support: support@zonelytix.com. Whether a data protection officer and an EU or UK representative under Article 27 GDPR are required depends on where the company is established; their details will be stated here if appointed.