Privacy Policy
Last updated: June 2026
OptionsLab ("we", "us", or "our") operates a production trading desk platform. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.
1. Information We Collect
We collect information you provide directly, including:
- Account credentials (username, hashed password)
- Contact details (email address, Telegram handle, WhatsApp number)
- Brokerage account identifiers you configure (e.g. IBKR account numbers)
- Webhook configurations and trading alert payloads
- Notification preferences and profile settings
We also collect operational data automatically, including:
- Server-side audit logs of significant actions (logins, order events, kill-switch activations)
- Session tokens stored in HttpOnly cookies
- Error and diagnostic telemetry sent to Sentry
2. How We Use Your Information
We use collected information to:
- Authenticate you and maintain secure sessions
- Route TradingView alerts and execute trading commands on your behalf
- Send trade notifications via Telegram or WhatsApp when configured
- Detect and diagnose system errors and performance issues
- Maintain audit trails required for compliance and debugging
We do not sell, rent, or share your personal information with third-party advertisers or data brokers.
3. Data Storage and Retention
Your data is stored on servers you control as part of a self-hosted deployment. If you use our managed hosting, data is stored within the hosting region you select. Audit logs are retained indefinitely by default; you may configure retention policies in your deployment settings. We retain error telemetry in Sentry for 90 days.
4. Third-Party Services
OptionsLab integrates with the following third-party services:
- Interactive Brokers (IBKR) — brokerage order routing
- TradingView — alert webhooks
- Telegram — optional trade notifications
- WhatsApp (via Meta) — optional trade notifications
- Sentry — error monitoring and diagnostics
Each service is governed by its own privacy policy. We only transmit the minimum data required for each integration to function.
5. Cookies
We use a single signed HttpOnly session cookie for authentication. No third-party tracking cookies are set by OptionsLab. The session cookie expires after 12 hours by default, or 7 days if you select "remember me" at login.
6. Your Rights
Depending on your jurisdiction you may have rights to access, correct, export, or delete your personal data. To exercise these rights, contact your instance administrator or reach us at the address below.
7. Security
Passwords are stored using bcrypt. Session tokens are signed and stored only in HttpOnly cookies. All communications between your browser and the server should be served over HTTPS in a production deployment. We follow industry-standard practices for secrets management and access control.
8. Changes to This Policy
We may update this policy from time to time. Material changes will be noted with an updated date at the top of this page. Continued use of OptionsLab after changes are posted constitutes acceptance of the revised policy.
9. Contact
Questions about this policy? Reach us at hello@optionslab.io.