Privacy Policy
Last updated: June 24, 2026
1. Information We Collect
- Account data — name, email address, and password (stored hashed, never in plain text).
- Billing data — payment details are handled directly by our payment processor (Stripe); we do not store full card numbers.
- Usage data — log-in activity, dashboard interactions, and risk-monitoring alert history needed to operate the Service.
- Communications — messages you send to support, and waitlist sign-up emails.
2. How We Use Information
We use this information to provide and secure the Service, process payments, send service-related communications (such as account or billing notices), and respond to support requests. We do not sell your personal information.
3. Sharing With Third Parties
We share information only with service providers who help us operate the platform — for example, our payment processor (Stripe) for billing, and our cloud infrastructure providers for hosting — and only to the extent necessary for them to perform that function. We do not share your data with Prop Firms unless you direct us to as part of using the Service.
4. Cookies
We use essential cookies (such as a session/authentication cookie) required for the dashboard and login to function. If analytics tracking is enabled, it is used in aggregate to understand product usage and is not used to sell your data.
5. Data Retention
We retain account and billing data for as long as your account is active and as needed to comply with legal, tax, and accounting obligations. You may request deletion of your account data as described below.
6. Data Security
We apply reasonable technical and organizational measures — including password hashing, encrypted transport (HTTPS/TLS), and access controls — to protect your information. No system is completely secure, and we cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, or request deletion of your personal data, or to object to certain processing. To exercise these rights, contact us at privacy@xpfirm.com.
8. Children's Privacy
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from minors.
9. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by updating the date above.
10. Contact
Questions about this Policy can be sent to privacy@xpfirm.com.