Appearance

Personalize your experience

Mode
Accent Color
Layout
Direction

Privacy Policy

Last updated

This policy explains what data QuaTick collects when you use the platform, why we collect it, how it is stored and who it is shared with. It covers the sensitive case specifically: the broker API credentials you connect so the platform can place orders on your instruction.

Who we are

QuaTick provides trading software. We are not a broker, we do not hold client funds or securities, and we do not provide investment advice. Your capital remains with the broker you connect. For any privacy question, contact support@quatick.com.

Data we collect

We collect only what the platform needs to work, in four categories:

  • Account data — your name, email address, password hash, and any profile details you choose to add.
  • Broker connection data — the API keys, secrets, session tokens or OAuth tokens you supply for each broker you link, plus the broker account identifier.
  • Trading and platform data — the strategies, bots, watchlists, screener filters, chart layouts and settings you create, and the orders and positions QuaTick reads back from your brokers to display them.
  • Technical and usage data — IP address, browser and device information, pages visited and features used, collected through Google Tag Manager and Google Analytics.

How we use your data

  • To authenticate you and keep your account secure.
  • To connect to your brokers and place, modify or cancel orders on your explicit instruction, whether manual or through a strategy you have created and started.
  • To display your consolidated positions, holdings, funds and profit and loss.
  • To run backtests, screens and automation you configure.
  • To provide support when you contact us.
  • To understand aggregate product usage so we know which features to improve.
  • To send service messages about your account, and — only if you opt in — product updates.

How broker credentials are handled

This is the most sensitive data on the platform, so it is treated differently from everything else.

  • Credentials are encrypted at rest and are never returned to the browser or embedded in client-side code.
  • Order placement happens server-side, so key material stays out of any code running on your device.
  • Where a broker offers OAuth — for example Fyers, Flattrade or Upstox — authorisation happens on the broker's own domain and QuaTick receives a scoped token rather than your password.
  • We request trading and read scopes only. We never request funds-transfer or withdrawal permission, and for crypto exchange API keys we recommend you explicitly disable withdrawal and restrict the key by IP.
  • You can revoke any broker connection from your account at any time, which deletes the stored credentials for that broker.

Who we share data with

We do not sell your personal data. We share it only where it is necessary to run the service:

  • Your brokers and exchanges — we transmit order instructions and read account state through their APIs, on your instruction.
  • Infrastructure and hosting providers that operate the servers and databases the platform runs on.
  • Analytics providers — Google Analytics and Google Tag Manager — for aggregate usage measurement.
  • Payment processors, which handle subscription billing. Card details are processed by them and are not stored by QuaTick.
  • Law enforcement or regulators, where we are legally required to disclose.

Cookies and tracking

We use cookies and similar storage for session management, to remember your theme and layout preferences, and for analytics. You can block or clear cookies in your browser, though doing so will sign you out and reset preferences. Analytics can additionally be blocked with any standard browser extension.

Data retention

Account and trading configuration data is retained for as long as your account is active. Broker credentials are deleted when you disconnect the broker or delete your account. Aggregate, non-identifying usage statistics may be retained after account deletion. Where we are required to keep records for legal, tax or accounting purposes, we retain the minimum necessary for the required period.

Your rights

  • Access — request a copy of the personal data we hold about you.
  • Correction — update inaccurate account details from your profile settings or by contacting support.
  • Deletion — request deletion of your account and associated data. Broker credentials are revoked and removed as part of this.
  • Withdraw consent — opt out of non-essential communications at any time.
  • Portability — export your strategies, watchlists and trade history.
  • To exercise any of these, email support@quatick.com.

Security

The platform is served over HTTPS with HSTS, a strict Content Security Policy and standard hardening headers. Credentials are encrypted at rest, passwords are hashed, and access to production systems is restricted. No system is perfectly secure, so we also recommend you enable two-factor authentication with your broker, use a unique password for QuaTick, and IP-restrict API keys where your broker supports it.

Children's data

QuaTick is not intended for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us and we will remove it.

Changes to this policy

We may update this policy as the platform changes or as legal requirements evolve. The "last updated" date above always reflects the current version. Material changes will be communicated by email or an in-product notice before they take effect.