Privacy Policy

Last updated: May 5, 2026 · Compliant with the EU GDPR (2016/679) and Spanish LOPDGDD 3/2018
Contents
  1. Data controller
  2. Data we collect
  3. Legal basis
  4. Purpose
  5. Third parties and subprocessors
  6. International transfers
  7. Data retention
  8. Your GDPR rights
  9. Security
  10. Cookies and local storage
  11. Minors
  12. Changes to this policy
  13. Contact

1. Data controller

The data controller for your personal data is the operator of YudBot (yudbot.com), reachable at support@yudbot.com.

We take privacy seriously. This policy explains what data we collect, why, with whom we share it, and what rights you have.

2. Data we collect

We only collect the data strictly necessary for the Service to work:

CategoryDataWhen
Account Name, email, password (bcrypt hash — never plaintext) On signup
Verification 6-digit OTP codes, reset tokens, expiration timestamps On email verification or password reset
Bots Bot configuration (market, pair, strategy, indicators, risk parameters) On building a bot in the wizard
Payment Lemon Squeezy order identifiers. We do NOT store card numbers or CVVs. On completing a payment
Technical IP address, User-Agent, timestamp of requests (server logs) While using the Service
🔒 We do NOT collect: your broker's data, API keys for your trading account, balance, trades executed by the bot, card numbers, or sensitive data (race, ideology, health, etc.).

3. Legal basis for processing

We process your data on the following legal bases under article 6 of the GDPR:

4. Purpose

We do not use your data for personalized advertising, do not sell it, and do not transfer it to data brokers.

5. Third parties and subprocessors

To deliver the Service, we share strictly necessary data with the following providers, who act as data processors under contract:

ProviderFunctionData shared
Lemon Squeezy Payment processing (Merchant of Record), invoicing Email, name, payment data, country
Resend Sending transactional emails Email, name, message content
Supabase PostgreSQL database Full account and bots data
Railway Backend hosting Logs, data in transit
Vercel Frontend hosting IP and User-Agent (access logs)
Hostinger Domain email hosting (@yudbot.com) Messages received at support@yudbot.com

Each of them is GDPR-compliant and applies appropriate technical and organizational security measures. You can review their privacy policies on their respective websites.

6. International transfers

Some of the providers listed above (Lemon Squeezy, Resend, Vercel, Railway) may process data on servers outside the European Economic Area, primarily in the United States. In those cases, transfers rely on one of the mechanisms in Chapter V of the GDPR:

7. Data retention

8. Your GDPR rights

As a user you have the following rights regarding your personal data:

To exercise any right, write to support@yudbot.com from your registered email. We will respond within a maximum of 30 days.

If you believe your request has not been handled correctly, you have the right to lodge a complaint with the Spanish Data Protection Agency (aepd.es) or your country's supervisory authority.

9. Security

We apply reasonable technical and organizational measures to protect your data:

No measure is foolproof. If we detect a security breach that may affect you, we will notify you without undue delay and, where appropriate, also notify the AEPD as required by GDPR articles 33-34.

10. Cookies and local storage

YudBot does not use tracking or advertising cookies. We do not install Facebook pixels, Google Analytics, or cross-site trackers.

We do use the browser's localStorage, a cookie-similar but strictly local technology, for:

You can clear this storage at any time from your browser settings. If you clear it, you will need to sign in again.

11. Minors

The Service is intended for users 18 years or older. We do not knowingly collect data from minors. If you believe a minor has created an account, write to support@yudbot.com and we will delete it without delay.

12. Changes to this policy

We may update this policy. When we do, we will update the "Last updated" date and, if changes are substantial (e.g. new third parties, new purposes), we will notify you by email before they take effect.

13. Contact