Privacy Policy
Effective 31 August 2026. Latis is operated by Latis Trading, an Australian sole trader.
1. What we collect
- Account info: your email address, used for login and login-link delivery.
- Exchange API keys you connect — encrypted at rest (AES-256-GCM) and never displayed again in full once saved.
- Bot configuration and activity: strategy settings, trade history, equity and P&L history, webhook signals sent to your bots.
- Billing information: handled entirely by Stripe, our payment processor. We never see or store your card details — we hold only subscription status and billing history Stripe reports to us.
- Support requests and messages you send us.
- Standard technical data (IP address, browser/device info, timestamps) generated by using the Service.
2. How we use it
To operate your account and run your bots (including placing orders on your connected exchanges using your keys), process payments, send transactional emails (login links, payment failures, bot pauses), respond to support requests, and maintain and secure the Service. We do not sell your personal information.
3. Who we share it with
- Your connected exchange(s) (e.g. Binance, Kraken, Coinbase, Bybit, OKX) — receives API calls made using your key to check balances and place orders you've configured.
- Stripe — processes payments for your subscription.
- Resend — delivers transactional email (login links, alerts) on our behalf.
Latis is self-hosted on our own infrastructure rather than a third-party database platform, so your account and trading data isn't additionally shared with a hosted-database vendor. We don't share your data with anyone else except where required by law.
4. Data retention and deletion
We keep your account and trading data for as long as your account is active, and afterward only as long as needed for legitimate business or legal purposes (e.g. billing records). You can request deletion of your account and associated data at any time by contacting us — exchange API keys are deleted immediately on request or on account closure.
5. Security
Exchange API secrets are encrypted at rest and only decrypted server-side, at the moment they're needed to call an exchange. No system is perfectly secure, but we design around the assumption that a leaked key should do as little damage as possible — which is also why we recommend connecting keys without withdrawal permission.
6. Cookies
We use a session cookie to keep you signed in. We don't use advertising or cross-site tracking cookies.
7. Your rights
You can access, correct, or request deletion of your personal information by contacting us at the address below. If you're in a jurisdiction with additional statutory privacy rights (such as the EU/UK GDPR), those rights apply to you in full alongside this policy.
8. Children
Latis is not directed at anyone under 18, and we don't knowingly collect information from them.
9. Changes to this policy
We may update this policy from time to time. Material changes will be notified via the Service or by email.
10. Contact
Questions about this policy, or a request to access or delete your data: [email protected].