Privacy
What PrismEdge collects, and what you control.
How PrismEdge handles the data needed to run the private terminal, billing, support, and the dashboard, which services process it, and the rights you hold over it.
Contents
Key points
Analytics only with consent. Product analytics, Vercel Analytics, Sentry session replay, and referral attribution stay off until you accept them on the cookie banner. Declining erases the identifiers. Sign-in, checkout, and every product feature work without them.
Stripe handles payments. Full card numbers and card security codes are processed by Stripe and never reach PrismEdge. PrismEdge stores the billing references needed to know your subscription status.
You control your data. Download everything PrismEdge holds about your account from the Account page in your dashboard, and request deletion from the same page. You can withdraw analytics consent at any time via Cookie Settings in the footer, and complain to your data protection authority.
01Who is responsible
PrismEdge is operated by Robert Iordache, sole trader, Ireland, who is the data controller for the data described here. For any privacy question or request, contact support through the Support page or write to privacy@prismedge.eu; requests are handled against the account the request comes from.
02Information collected
Account data: email address, name, password hash (held by Supabase Auth), TradingView username, subscription and access status. Billing references: Stripe customer and subscription identifiers, invoice status. Operational data: support messages, onboarding progress, admin review logs, and security logs. Usage events are collected only after analytics consent.
03Why, and on what legal basis
Operating your account and access runs on contract. Billing record keeping runs on legal obligation. Security controls, fraud prevention, and error monitoring run on legitimate interest. Product analytics, session replay, and referral attribution run on consent only, and are off until given.
05Services that process data
Supabase (authentication and database), Stripe (payments), Vercel (hosting, and visit analytics only after consent), Resend (transactional email), Sentry (error monitoring; session replay only after consent, with text masked), PostHog (product analytics, only after consent). Each processes data only to provide its service.
06International transfers
Some of the services above process data in the United States. Transfers rely on the safeguards those providers offer under EU data protection law, including standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.
07Retention
Account data is kept while the account exists. Billing records are kept as long as legal record keeping requires. Support messages and admin logs are kept while they are operationally needed. Analytics identifiers are erased when consent is declined or withdrawn.
08Your rights
Under EU data protection law you can request access, correction, deletion, portability, or restriction of your data, object to processing based on legitimate interest, withdraw consent at any time without affecting past processing, and lodge a complaint with your supervisory authority. Export is self-service from the Account page in your dashboard, where you can also request deletion; deletion is completed within 30 days and confirmed by email. Correction, restriction and objection are handled through support.
09Support messages
Support requests are used to respond to billing, access, setup, login, and TradingView username issues. Do not send exchange passwords or private keys; support will never ask for them.
10Security controls
Protected routes, server side entitlement checks, environment variable secrets, Stripe webhook signature verification, and Supabase row level security policies reduce unauthorised access. Error reports are masked before they leave the browser.
Need a data correction, export, or deletion?
Export and deletion requests start on the Account page in your dashboard. Use support for questions about your account profile, TradingView username, subscription state, or stored access status.