Privacy Policy

Last updated

This policy explains what personal data [COMPANY_LEGAL_NAME] collects when you use CandleSniff, why we collect it, and what rights you have over it. It is our notice under Articles 13 and 14 of the General Data Protection Regulation (GDPR).

1. Who is responsible for your data

The data controller is [COMPANY_LEGAL_NAME], [REGISTERED_ADDRESS], Italy (VAT [VAT_NUMBER]). For any privacy question or to exercise your rights, contact [email protected].

2. What we collect and why

We collect only what we need to run the service. Each purpose below has its own legal basis under GDPR Article 6.

DataWhy we process itLegal basisKept for
Account data — email, username, display name, password hash, languageCreating and running your account, authenticating youPerformance of a contract (Art. 6(1)(b))Life of the account, then 30 days
Two-factor authentication secrets and recovery codesSecuring your account at your requestPerformance of a contract (Art. 6(1)(b))Until you disable 2FA
Login sessions — IP address, user agent, timestampsKeeping you signed in, showing you your active sessions, detecting account takeoverLegitimate interest in platform security (Art. 6(1)(f))12 months
Content you create — notebooks, datasets, strategies, posts, commentsProviding the features you use and sharing content as you directPerformance of a contract (Art. 6(1)(b))Until you delete it or close your account
Cloud compute usage — run duration, hardware type, costEnforcing plan limits, billing, and showing you your usagePerformance of a contract (Art. 6(1)(b))24 months (billing records: 10 years, see below)
Billing data — plan, subscription status, invoices, partial card details held by StripeTaking payment, issuing invoices, meeting tax obligationsContract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))10 years, as Italian tax law requires
Audit logs — who changed what and whenSecurity, fraud prevention, and demonstrating complianceLegal obligation and legitimate interest (Art. 6(1)(c), (f))24 months
Error diagnostics — stack traces, browser and OS version, the URL where an error happenedFinding and fixing faultsLegitimate interest in a working product (Art. 6(1)(f))90 days
Product analytics — pages viewed, features used, coarse countryUnderstanding which features are worth building onYour consent (Art. 6(1)(a)) — collected only if you accept analytics cookies14 months
Support correspondenceAnswering your question and keeping a record of itLegitimate interest in supporting users (Art. 6(1)(f))24 months after the ticket closes

3. What we do not do

We do not sell your personal data. We do not share it with advertising networks or data brokers. We do not use it to build profiles for third-party marketing, and we do not make decisions with legal or similarly significant effects about you by automated means alone.

4. Content you choose to publish

CandleSniff has social features. Anything you post publicly — a published notebook, a strategy, a post, a comment, your profile — is visible to others and may be indexed by search engines. Think of that material as public. You control the visibility of each item, and you can change it or delete it at any time, though copies may persist in caches or in other users’ screenshots beyond our control.

5. Notebooks and cloud execution

When you run a notebook on Cloud CPU or Cloud GPU, your code and any data it loads are sent to Modal Labs, who run it in an isolated container on our behalf. The container is destroyed when the run ends. We do not read the contents of your notebooks except where you ask us to in support, or where we must investigate a specific abuse report.

Do not put credentials, personal data about other people, or anything you are contractually forbidden to export into a cloud notebook.

6. Who we share data with

We use the processors below. Each is bound by a data processing agreement that limits them to acting on our instructions.

ProcessorWhat they doWhereDPA
StripePayment processing, subscription billing, invoicingUSA / IrelandTerms
Modal LabsCloud CPU/GPU execution of user notebooksUSATerms
ResendTransactional email deliveryUSATerms
SentryError monitoring and diagnosticsUSATerms
Google Cloud PlatformApplication and database hostingEUTerms
CoinGateCryptocurrency payment processing (optional at checkout)Lithuania (EU)Terms

We may also disclose data where the law requires it, to establish or defend legal claims, or to a buyer if the business is sold — in which case we will tell you before your data is transferred.

7. International transfers

Some processors are in the United States. Where data leaves the EEA we rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision such as the EU–US Data Privacy Framework where the processor is certified under it. You can ask us for a copy of the safeguards in place by emailing [email protected].

8. How we protect your data

  • Passwords are hashed; we never store them in a readable form.
  • Sensitive fields such as broker API credentials are encrypted at rest with keys we rotate.
  • Traffic is encrypted in transit with TLS.
  • Access to production data is limited to staff who need it, and every administrative action is written to an audit log.
  • Two-factor authentication is available on all accounts, and we recommend you turn it on.

If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and tell you directly where the risk is high.

9. Your rights

Under GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you. There is a self-service export in your account settings.
  • Rectify — correct data that is wrong or incomplete.
  • Erase — have your data deleted. Closing your account triggers this; we keep only what tax law obliges us to keep.
  • Restrict — ask us to pause processing while a dispute about accuracy or legitimate interest is resolved.
  • Port — receive your data in a structured, machine-readable format, or have it sent to another provider.
  • Object — object to processing based on legitimate interest, including profiling.
  • Withdraw consent — where processing rests on consent, withdraw it at any time. Analytics consent can be changed from the cookie settings link in the footer. Withdrawal does not affect processing already carried out.

Email [email protected] to exercise any of these. We respond within one month, and will tell you if we need longer because the request is complex.

If you think we have handled your data badly, you can complain to the Garante per la protezione dei dati personali, or to the supervisory authority where you live.

10. Cookies

We set only what is needed to sign you in and keep the session secure unless you consent to more. Full detail is in the Cookie Policy.

11. Children

CandleSniff is not for people under 18 and we do not knowingly collect their data. If you believe a minor has an account, tell us and we will remove it.

12. Changes to this policy

If we change how we use your data in a way that affects you, we will email you or show an in-app notice before the change takes effect. The date at the top of this page always reflects the latest revision.

CandleSniff

Trade smarter, not harder.

© 2025 CandleSniff. All rights reserved.

CandleSniff provides research and analytics tools. Nothing on this site is investment advice or a recommendation to trade. Trading carries risk, including the loss of your capital.