Privacy Policy
Last updated: August 14, 2026
1. Introduction
QFI Terminal ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect your personal data when you use our Service, in compliance with the EU General Data Protection Regulation (GDPR) and applicable Portuguese law.
2. Data Controller
QFI Terminal is the data controller. For questions about data processing, contact privacy@qfiterminal.com.
3. Data We Collect
| Data | Purpose | Legal Basis |
|---|---|---|
| Email address | Account creation, communication | Contract performance |
| Name | Account identification | Contract performance |
| Google/X OAuth ID | Social login | Consent |
| IP address | Security, rate limiting, fraud prevention | Legitimate interest |
| Browser user agent | Security, bot detection | Legitimate interest |
| Usage data (tabs visited) | Product analytics, improving the Service | Legitimate interest |
| Watchlist & portfolio data | Service functionality | Contract performance |
| Support chat messages | Answering your question, and finding out what our help pages fail to explain | Legitimate interest |
4. Data We Do NOT Collect
- We do not sell, rent, or share personal data with third parties for marketing.
- We do not use tracking pixels, retargeting cookies, or advertising networks.
5. Payment Data
All payment processing is handled by Stripe, Inc. We do not store credit card numbers, bank details, or payment credentials. Stripe's privacy policy applies to payment data: stripe.com/privacy.
6. Cookies
- Signing in: Required for authentication. Kept for up to 7 days.
- Staying signed in: Optional persistent login (7 days). The token is hashed and replaced on each use.
- Protecting the sign-in: Short-lived values (5 minutes) that protect Google and X sign-in against cross-site request forgery. Deleted the moment you return.
- Knowing you have been here: Records that you have already seen the landing page, so the site opens the terminal instead (1 year).
- Referral credit: Stores a referral code (30 days). First-party, no tracking.
- Campaign measurement: A random first-party identifier (30 days) that ties a signup to the campaign that brought the visit. No name, no email, no profile, never shared. This is the one the Decline button removes.
We use no advertising, retargeting or third-party analytics cookies. The only third-party cookies on the site are set by Google reCAPTCHA, on the contact forms, and by YouTube if you play an embedded stream inside the terminal. Every cookie is listed one by one, with its purpose and duration, in our Cookie Policy.
7. Data Storage & Security
- Data is stored in a PostgreSQL database on our own server in Germany, inside the EU.
- All API communication is encrypted via HTTPS/TLS.
- Passwords are hashed with bcrypt (never stored in plaintext).
- Remember-me tokens are SHA-256 hashed and rotated on each use.
- Row Level Security is enabled on the tables that hold personal data.
- API endpoints are protected by session checks, rate limiting, CORS, and user-agent filtering.
8. Data Retention
- Account data is retained while your account is active.
- Session tracking data is retained for 90 days.
- Performance logs are retained for 30 days.
- Support chat messages, and the IP address they were sent from, are retained for 90 days and then deleted automatically.
- Upon account deletion, all personal data is permanently removed within 30 days.
9. Your Rights (GDPR)
Under the GDPR, you have the right to:
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate data.
- Erasure: Request deletion of your data ("right to be forgotten").
- Portability: Receive your data in a machine-readable format.
- Objection: Object to processing based on legitimate interest.
- Restriction: Request restriction of processing.
To exercise any of these rights, email privacy@qfiterminal.com. We will respond within 30 days.
10. Third-Party Services
- Stripe: Payment processing
- Hetzner Online GmbH: Server and database hosting (Germany, EU)
- Google OAuth: Optional social login
- OpenAI: Powers the support assistant on our home page. What you type into that chat is sent to OpenAI so it can write the reply
11. International Transfers
Your data is primarily stored in the EU. Where data is processed outside the EU, we ensure appropriate safeguards are in place, including Standard Contractual Clauses where applicable. The support chat is the one place where text you write is sent to a provider in the United States: your message goes to OpenAI to be answered, and the copy we keep stays on our server in Germany.
12. Children
QFI Terminal is not intended for individuals under 18. We do not knowingly collect data from minors.
13. Changes
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification. The "Last updated" date reflects the most recent revision.
14. Contact
For any privacy-related inquiries:
Email: privacy@qfiterminal.com