Legal
Privacy Policy
1. Who we are
For this instance, the data controller (or equivalent) is the Operator that deploys and runs NavStak. Contact for privacy requests: Mission → Messages → Support, or the Operator email designated for this instance.
2. Scope
This Policy covers the NavStak website and product surfaces for this instance, including Mission, account features, paper and live trading workflows, messaging, Ava support, and authorized Admin tools. Third-party venues, payment processors, and identity providers have their own policies.
3. Data we process
Depending on how you use the Service, we may process:
- Account data — email, display name, authentication secrets (hashed), role flags;
- Profile & preferences — theme, optional social handles, product settings;
- Trading operational data — paper and live orders/positions metadata, risk settings, style/aggression, engagement state, machine-generated theses or exit reasons;
- Connectivity data — exchange key labels, non-secret metadata, host/surface assignment (we ask you not to store unnecessary secrets in free-text fields);
- Support data — messages, Ava chats, support cases, and attachments you send;
- Technical data — IP address, user agent, session identifiers, approximate location derived from IP, logs, performance metrics, and security audit events;
- Commercial data — plan selection, invoices or payment references if billing is enabled.
We do not ask for government ID by default. Market data from third parties is processed to operate rankings and trading features and is not “your” personal data, though it may be linked to your activity history.
4. How we use data
- Provide, secure, and improve the Service;
- Operate paper/live books, autopilots, learning systems, and operator fleet controls;
- Authenticate sessions and prevent abuse, fraud, and security incidents;
- Respond to support requests and improve help knowledge (without using your private keys as training fodder);
- Meet legal obligations and enforce Terms;
- Communicate service notices (security, material product or Terms changes).
We do not sell personal information. We do not use third-party advertising cookies on the Mission product surface today.
5. Legal bases (where applicable)
If GDPR or similar laws apply, we rely on one or more of:
- Contract — to provide the Service you request;
- Legitimate interests — security, product integrity, aggregated improvement (balanced against your rights);
- Consent — where we ask for it (for example, certain optional communications);
- Legal obligation — when the law requires retention or disclosure.
6. Sharing
We may share data with:
- Infrastructure processors — hosting, databases, email delivery, error monitoring under contractual confidentiality;
- Venues you connect — order and account actions you authorize via your keys;
- Professional advisers or authorities when required by law or to protect rights and safety;
- Successors in a merger or asset transfer, subject to continuing privacy protections.
Authorized Operator personnel and automated admin tools may access account and trading operational data to run support, security, and platform operations.
7. Retention
We retain account and trading operational data while your account is active and for a reasonable period afterward for security, dispute, and legal purposes. Support tickets and security logs may be kept longer when needed for investigations. You may request deletion; residual backups may persist for a limited window before expiring. Exact retention schedules should be finalized by the Operator with counsel.
8. Security
We use administrative, technical, and organizational measures appropriate to the risk — including session controls, access restrictions for Admin surfaces, and secret handling practices. No method of transmission or storage is fully secure. You must protect your passwords and API keys and use venue-side permissions conservatively.
9. International transfers
This instance may be hosted in the United States or other regions chosen by the Operator. If you access the Service from another country, your data may be processed where the servers and operators are located. Where required, the Operator should implement appropriate transfer safeguards.
10. Your rights
Depending on your location, you may have rights to:
- Access, correct, or delete personal data;
- Export a copy of certain data;
- Object to or restrict certain processing;
- Withdraw consent where processing is consent-based;
- Appeal a denial (where state law provides) or lodge a complaint with a supervisory authority.
To exercise rights, contact the Operator via Messages → Support or the designated privacy email. We may need to verify your request. Some data (for example security logs) may be retained where the law allows.
11. Children
The Service is not directed to children under 18 (or a higher age required in your region). We do not knowingly collect personal data from children. If you believe a child has provided data, contact the Operator to request deletion.
12. Cookies & local storage
We use essential cookies or similar storage for authentication sessions and local UI preferences (for example theme). These are required for the product to function. We do not currently use third-party advertising cookies on Mission. If analytics cookies are introduced later, this Policy will be updated and consent obtained where required.
13. AI assistants & support tooling
Ava and related help features process the text you submit to generate replies and, when needed, support cases. Prompts may be combined with product knowledge documents. Admin-only knowledge is not intended for non-admin pilots. Do not submit secrets, seed phrases, or full API key material in chat. Local or third-party models may be used to generate replies subject to Operator configuration.
14. Changes
We may update this Policy by posting a new version on this page and changing the “Last updated” date. Material changes may be highlighted in-product when practical. Continued use after the effective date means you accept the updated Policy, except where consent is required by law for a specific change.
15. Contact
Privacy inquiries: Mission → Messages → Support, or the Operator’s designated privacy contact.
Legal entity: [Operator entity — to be designated]
Privacy email: [To be designated]