Privacy Policy

Last updated: February 2026

1. Introduction

ATMA ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our automated trading management service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Username and email address
  • Password (stored as a secure hash)
  • Full name and profile information
  • Account creation timestamp

2.2 Trading Information

To provide trading services, we collect:

  • Trading strategies and preferences
  • Trade history and performance data
  • Account balance and transaction records
  • API credentials (encrypted and stored securely)

2.3 Communication Information

For notifications and support, we collect:

  • Phone number (for SMS notifications, if provided)
  • Email address (for account communications and daily forecasts)
  • Notification preferences (email/SMS settings)
  • Discord webhook URLs (if configured for trade notifications)

2.4 Technical Information

We automatically collect:

  • IP address and device information
  • Browser type and version
  • Usage patterns and service interactions
  • Error logs and diagnostic data
  • Login timestamps and session data

3. How We Use Your Information

We use collected information to:

  • Provide and maintain the trading service
  • Execute trades and manage positions as configured
  • Generate performance analytics and reports
  • Send important service notifications via email and SMS
  • Send daily volatility forecasts (if opted in)
  • Send trade notifications (trades, deposits, withdrawals) via SMS (if opted in)
  • Send account-related emails (welcome, password resets, etc.)
  • Provide customer support via phone, email, and in-app chat
  • Improve service functionality and user experience
  • Detect and prevent fraud or security issues
  • Comply with legal obligations

4. Data Storage and Security

4.1 Encryption

Sensitive information, including API keys and credentials, is encrypted using industry-standard encryption methods before storage. We use Fernet symmetric encryption for API keys and bcrypt for password hashing.

4.2 Data Storage

User data is currently stored in JSON files on secure servers. We are in the process of migrating to a PostgreSQL database for enhanced security and scalability. All data is stored in encrypted form where applicable.

4.3 Security Measures

  • Secure password hashing (bcrypt/pbkdf2)
  • API key encryption at rest
  • Rate limiting to prevent abuse
  • Session management with secure cookies
  • Regular security audits and updates

5. Data Sharing and Disclosure

We do not sell your personal information. We may share data only in the following circumstances:

  • Brokerage APIs: Your API credentials are used solely to execute trades through your brokerage account (e.g., Tradier)
  • Email Service Providers: We use Zoho Mail to send account-related emails. Your email address is shared with Zoho for delivery purposes only.
  • SMS Service Providers: We use Twilio to send SMS notifications. Your phone number is shared with Twilio for message delivery only. Standard message rates may apply.
  • Discord: If you configure Discord webhooks, trade notifications are sent to your Discord server via the webhook URL you provide.
  • Service Providers: With trusted third-party services necessary for operation (e.g., hosting, analytics)
  • Legal Requirements: When required by law, court order, or government regulation
  • Business Transfers: In connection with a merger, acquisition, or sale of assets (with notice to users)

6. Your Rights and Choices

You have the right to:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information through the settings page
  • Deletion: Permanently delete your account and all associated data through the Settings → Security → Delete Account feature. This action is irreversible and will delete all trades, balance history, settings, and personal information.
  • Portability: Export your trading data in a machine-readable format
  • Opt-out: Control notification preferences in Settings:
    • Disable email notifications for daily forecasts
    • Disable SMS notifications for daily forecasts
    • Disable SMS notifications for trades, deposits, and withdrawals
    • Disable general SMS notifications

To exercise these rights, contact us at support@atmatrader.com or call (833) 408-9321, or use the account settings page.

7. Cookies and Tracking

We use session cookies to maintain your login state and preferences. These cookies are essential for service functionality and do not track you across other websites. You can control cookie settings through your browser, though disabling cookies may affect service functionality.

8. Third-Party Services

Our service integrates with:

  • Brokerage APIs: (e.g., Tradier) for trade execution. Your API credentials are encrypted and used solely for trade execution.
  • Discord: For notifications via webhook URLs you provide. Messages are sent to your Discord server.
  • Zoho Mail: For sending account-related emails (welcome emails, password resets, daily forecasts, etc.)
  • Twilio: For sending SMS notifications (daily forecasts, trade notifications, etc.). Standard message rates may apply.
  • Analytics: For service improvement (anonymized data)

These services have their own privacy policies. We encourage you to review them:

9. Data Retention

We retain your data for as long as your account is active or as needed to provide services. Trading history and performance data are retained for analytical purposes.

Account Deletion: When you delete your account through the Settings page, we will permanently delete:

  • Your account information and profile data
  • All trade history and analytics data
  • Account balance and transaction records
  • API keys and configuration settings
  • Notification history
  • All other user-specific data files

Account deletion is immediate and irreversible. Some data may be retained in backups for up to 30 days, after which it will be permanently removed. We may retain certain information as required by law or for legitimate business purposes (e.g., fraud prevention).

10. Children's Privacy

Our service is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a minor, please contact us immediately.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or through the service. The "Last updated" date at the top indicates when changes were made. Continued use of the service after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: