Skip to content
SignalFlow
Legal documents

SignalFlow Privacy Policy

What data the service processes, why it is needed, and how users can exercise their rights.

Introduction

Welcome to SignalFlow, a trading signals service available at signalflowtrade.com.

This Privacy Policy explains what data we collect, why we use it, who we may share it with, and how users can exercise their rights.

SignalFlow is not a bank, broker, or payment system. It does not accept user funds or process bank card data. Trading account deposits are made directly through Binodex under that service’s terms.

Data we collect

Depending on the features you use, SignalFlow may process the following categories of data.

Account data

  • name or display name;
  • email address;
  • registration and email verification dates;
  • account status and role.

We do not store passwords in plain text. The database stores only a cryptographic hash created using Argon2id.

Authentication and security data

  • IP address;
  • User-Agent, which may contain information about the browser and operating system;
  • session creation, renewal, and termination dates;
  • authentication token hashes;
  • information about sign-in attempts and security events.

SignalFlow does not create separate persistent device identifiers.

Service usage data

  • history of issued signals;
  • selected currency pairs and expiration times;
  • signal direction, issue time, and outcome;
  • information about the use of SignalFlow features;
  • technical interaction timestamps.

Data related to Binodex

  • numeric Binodex account ID;
  • registration status through the partner link;
  • confirmed deposit amount;
  • registration, deposit, and access verification dates;
  • technical events received from the Binodex partner system.

SignalFlow does not receive or store the user’s Binodex password, bank card data, or payment method details.

Telegram data

If a user voluntarily enables notifications, we may store their Telegram Chat ID and the information required to send those notifications.

Support requests

  • name, if provided;
  • email address;
  • message content;
  • date and technical details of the request.

Technical information

We may receive information about application errors, performance, visited pages, and the technical environment.

Goal planner data is stored locally in the user’s browser and is not sent to the SignalFlow database.

How we use data

Personal data is used for the following purposes:

  • creating and maintaining a SignalFlow account;
  • verifying an email address;
  • authenticating users and maintaining user sessions;
  • verifying access requirements through Binodex;
  • providing trading signals and maintaining signal history;
  • calculating outcome statistics;
  • sending service emails and notifications;
  • providing support;
  • maintaining security and preventing abuse;
  • identifying and resolving technical errors;
  • improving the service;
  • complying with applicable legal requirements.

SignalFlow does not use the data it receives to conduct financial transactions and does not manage the user’s funds or trading account.

Signal history may be used in aggregated or anonymized form to evaluate the quality of the service.

Automated algorithms

SignalFlow may use automated algorithms, including machine learning technologies, to analyze market data, test trading strategies, and generate trading signals.

These algorithms analyze market data and are not used to evaluate the user’s personality. They do not make decisions that create legal or similarly significant effects for the user.

Trading signals are provided for informational purposes only. They are not guaranteed forecasts or personalized investment advice.

Data security

We use organizational and technical safeguards, including:

  • data transmission over HTTPS using SSL/TLS;
  • password storage as Argon2id hashes;
  • one-time refresh tokens;
  • limited access token lifetimes;
  • access control and separation of permissions;
  • technical error monitoring;
  • database backups;
  • rate limiting for suspicious requests and sign-in attempts.

Despite these safeguards, no method of storing or transmitting information over the internet can guarantee absolute security.

Sharing data with third parties

We do not sell, rent, or disclose personal data to third parties for their independent marketing use.

We may also disclose information to public authorities where disclosure is required by applicable law or a binding lawful request.

Some service providers may process data in other countries. In such cases, transfers must comply with applicable cross-border data transfer and personal data protection requirements.

Cookies and local storage

SignalFlow uses the essential sf_refresh cookie to authenticate users and securely maintain user sessions. This cookie has a limited lifetime and cannot be accessed by JavaScript running on the page.

The browser’s local storage may contain:

  • a short-lived access token;
  • selected language or interface preferences;
  • goal planner data.

These technologies are required for the website’s features to work.

SignalFlow does not currently use advertising or analytics cookies. If such technologies are added, this Policy will be updated and user consent will be requested where required by law.

Users can delete local data and cookies through their browser settings. This may sign them out of their account and reset saved preferences.

User rights

To the extent provided by applicable law, users may:

  • request information about the personal data being processed;
  • obtain a copy of their data;
  • request correction of inaccurate or outdated information;
  • request deletion of their account and related data;
  • restrict or object to data processing;
  • withdraw previously given consent;
  • request an export of their data in an accessible format.

We may need to verify the user’s identity or account ownership before fulfilling a request.

Requests may be submitted through the support page or by email at supportsignalflow@gmail.com.

Some data may be retained after a deletion request where necessary to comply with legal requirements, maintain security, resolve disputes, or protect the operator’s legitimate interests.

Data retention

Account data and signal history are retained while the account is active and while the information is required to provide the service.

Authentication tokens are retained until they expire or are revoked early. One-time email verification and password reset tokens are retained until they expire or are used.

Once an account deletion request has been confirmed, the account and associated personal data are deleted from the production database unless continued retention is required by law.

Changes to this Policy

We may update this Policy when SignalFlow features, service providers, applicable laws, or data processing practices change.

Users may be notified of material changes through the website or by email.

Continued use of the service after this Policy is updated does not replace separate user consent where such consent is required by law.

Support