SignalForgeAlgorithmic trading
Terms Privacy Sign in
SignalForge legal

Privacy Policy

Effective July 21, 2026

1. Information we collect

When you connect Alpaca, the Service may store your Alpaca account identifier, account environment, a masked account number, authorized scopes, encrypted OAuth access tokens, and connection timestamps. We also process order requests and broker responses, idempotency identifiers, watchlist actions, and security or audit events.

The Service retrieves account, portfolio, order, activity, asset, market-data, and news information when you request it. Standard hosting logs may include IP address, browser type, request path, timestamps, and diagnostic information.

2. How we use information

We use information to authenticate your connection, display broker and market information, carry out actions you request, prevent duplicate or unauthorized transactions, maintain security and audit records, diagnose problems, support users, and comply with legal obligations.

3. How information is shared

Information is exchanged with Alpaca to provide brokerage and market-data features. It may also be processed by hosting, database, security, and other infrastructure providers that operate the Service. We may disclose information when required by law or reasonably necessary to protect users, the Service, or legal rights. We do not sell personal information or use it for third-party behavioral advertising.

4. Cookies and sessions

The Service uses a session cookie and related security data to keep you signed in, preserve OAuth state, and protect requests against forgery. It does not currently use advertising cookies.

5. Storage, security, and retention

OAuth tokens are encrypted in application storage, transmitted over HTTPS in production, and not placed in browser storage or returned in application API responses. No security method is perfect, and absolute security cannot be guaranteed.

Connection credentials are retained while the integration remains connected or as needed for security and recovery. Order, response, and audit records may be retained for operational, compliance, dispute, and legal purposes. Infrastructure logs are retained according to provider and operational settings.

6. Your choices

You can sign out or disconnect Alpaca from the Service. You may also revoke the connection through Alpaca. Revocation stops future access but may not remove records that must be retained by the Service, Alpaca, or other providers. Contact the Service operator to request access, correction, or deletion where applicable.

7. Children

The Service is not directed to children, and we do not knowingly collect personal information from children through the Service.

8. Changes and contact

This policy may be updated by posting a revised version with a new effective date.

© 2026 SignalForge