Effective:

Privacy Policy

This Privacy Policy describes how we collect and use personal data when you use Caliente Signals (the “Service”). We aim to keep it short, specific, and honest.

1. Data controller

The data controller for personal data processed via the Service is Roman Duda, a sole trader (OSVČ) registered in the Czech Republic, IČO 29808154, with a place of business at Zelenečská 519/44, 198 00 Praha 9 – Hloubětín, Czech Republic. You can reach us at hello@calientesignals.com.

2. What we collect and why

We only collect data that is necessary to run the Service:

  • Account data: your email address, used for sign-in via magic link and for notifications you opt into.
  • Service data: the technical-analysis strategies you create, the signals fired for those strategies, your notification preferences, and backtest history.
  • Telegram link: if you connect a Telegram chat, we store your chat identifier so we can send you alerts.
  • Billing data: if you subscribe to the paid tier, Stripe processes your payment and provides us with a customer identifier and subscription status. We do not receive or store your card details.
  • Operational logs: standard server and application logs (request metadata, error context) used to keep the Service running and to detect abuse.
  • Analytics (only with consent): if you accept analytics cookies, we use PostHog (EU Cloud) to understand how the marketing pages and the app are used. See the Cookie Policy for details. You can decline analytics at any time.

3. Legal bases

We process personal data on the following legal bases under the GDPR:

  • Performance of a contract (Art. 6(1)(b)) — to provide the Service you signed up for: account creation, strategies, signals, notifications, and billing.
  • Legal obligation (Art. 6(1)(c)) — for tax, accounting, and other statutory requirements applicable to a Czech sole trader.
  • Legitimate interests (Art. 6(1)(f)) — to keep the Service secure and to prevent abuse, where this does not override your rights.
  • Consent (Art. 6(1)(a)) — for analytics cookies and any optional communications. You can withdraw consent at any time.

4. Who we share data with

We share personal data with the following service providers to deliver the Service. Each acts under a data processing agreement where applicable:

  • Supabase — authentication, database, and backend hosting (EU region, Frankfurt). DPA.
  • Vercel — hosting of the web application. DPA.
  • Stripe — payment processing for paid subscriptions; collects and stores payment-method data on its own infrastructure. DPA.
  • Resend — email delivery (transactional notifications and account emails). DPA.
  • Telegram — when you have connected Telegram, we send your alerts to the chat you linked. Telegram operates as an independent service and is subject to its own privacy policy.
  • PostHog (EU Cloud) — product analytics, only if you accept analytics cookies. DPA.
  • Sentry (EU region) — error monitoring, so we find out when something breaks. Receives technical diagnostics only: the error, where in our code it happened, and which page you were on. It is configured not to collect your IP address, cookies, request contents or form data. DPA.

5. International data transfers

Some of the service providers above operate or store data outside the European Economic Area (EEA). Where this is the case, we rely on lawful transfer mechanisms such as the European Commission’s Standard Contractual Clauses (SCCs), and, where applicable, on adequacy decisions. The relevant safeguards are described in each processor’s DPA linked above.

6. How long we keep data

We retain personal data for as long as your account is active or as needed to provide the Service. When you delete your account from Settings, your personal data is removed from our active systems. Encrypted operational backups may retain copies for a limited period before they are overwritten. We may retain anonymized or aggregated data that does not identify you.

Where we are required by law to keep certain records (for example, invoicing and tax records relating to paid subscriptions), we retain them for the statutory period.

7. Your rights

Under the GDPR, you have the right to: access the personal data we hold about you; have it corrected; have it deleted (right to erasure); receive a copy in a portable format; object to or restrict certain processing; and withdraw consent for processing based on consent (such as analytics).

You can delete your account at any time from Settings. For other requests, write to hello@calientesignals.com. We will respond within the time limits required by applicable law.

If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with the Czech data-protection authority, Úřad pro ochranu osobních údajů (uoou.gov.cz), or with the supervisory authority of your country of residence.

8. Cookies and analytics

The Service uses a small number of cookies. Authentication cookies are strictly necessary to keep you signed in and are set without consent. Analytics cookies are set only after you accept them on the cookie banner. Full details are in the Cookie Policy.

9. Children

The Service is not directed to anyone under 18. We do not knowingly process personal data of children. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or by in-app notice. The effective date at the top of this page indicates when the current version took effect.

11. Contact

Questions about this Privacy Policy can be sent to hello@calientesignals.com.