Qorin Systems

Legal

Privacy policy

What we collect, why we collect it, how long it stays, and what you can ask us to do with it. Stated in the same register as the rest of the product.

Effective 26 July 2026

Qorin Systems is pre-launch. Accounts and broker connections do not exist yet, so most of the processing described below is what we will do rather than what we do today, and the text says which is which. This is a provisional draft that has not been reviewed by counsel.

Who we are

Qorin Systems builds software that lets traders configure and run automated strategies against their own brokerage or exchange accounts. It is the controller of the personal data described here. The business is in formation: the legal entity and its registered address will be named here on incorporation, and before any account or broker connection exists.

Qorin is a software provider. We are not a broker-dealer, futures commission merchant, custodian, or investment adviser. We never hold your funds or securities. Your trades execute at your broker or exchange, under your account, using authorisation you grant us.

This policy applies to Qorin and to qorinsystems.com. Questions and requests go to privacy@qorinsystems.com.

What we collect

Accounts and broker connections are not yet available, so today this site collects only the technical data described at the end of this section. Everything above that describes what we will collect once the product is live, and is published now so it can be read before it applies.

Account information. Your name, email address, and a hashed representation of your authentication credentials. We do not store your password in readable form — we cannot see it, and neither can anyone who gains access to our systems.

Trading configuration and activity. The strategies you build or select, your risk limits and sizing rules, and the orders, positions, and performance history that result from running them. This is the data the product exists to produce and show back to you.

Broker and exchange credentials. When you connect an account, we store the credentials or access tokens needed to place orders and read account data on your behalf. This is the most sensitive category of data we hold, and it has its own section below.

Technical data. Your IP address, browser and device information, and the pages and features you request. Used to operate the service, keep it secure, and diagnose faults.

We do not collect health, biometric, precise location, or government-ID data, and we do not want it. If a feature ever changed that, we would update this policy and tell you before it took effect.

Broker and exchange connections

This section covers the credentials and tokens you will give us to connect a broker or exchange, because it is the part of our system where a mistake would hurt you most. No broker integration has been built yet and we hold no customer credentials today. What follows is the standard we are building to, written down in advance so it can be held against us — not a description of controls already running.

  • What we will store. Where a broker or exchange supports OAuth or similar token-based authorisation, we will store the token it issues rather than your broker password. Where a broker offers only an API key and secret, we will store those. Which applies to any given broker depends on that broker, and we will say which on each integration's connection screen.
  • How it will be protected. Credentials will be encrypted at rest using AES-256, held in a dedicated secrets store rather than in the application database, and decrypted only in memory, at the moment of use, by the systems that place orders. Access by staff will require a documented reason, will be logged, and will alert independently of the person requesting it.
  • What scope we will request. We will request the narrowest permissions a broker or exchange allows for placing trades and reading account data. We will never request permission to withdraw or transfer funds. Where a broker's API offers no way to exclude withdrawal permission from a trading credential, we will say so on that integration's connection screen rather than let the narrower promise here imply otherwise.
  • Revocation. You will be able to disconnect an account at any time, from Qorin or directly at the broker. We will then stop placing new orders under that connection, revoke the credential immediately, and purge it from our systems and backups within 30 days. Orders already pending at your broker are unaffected — cancel those with your broker.
  • What we will never do. We will not use your broker credentials for any purpose other than the trading functions you configured, and we will not sell or share the contents of your brokerage account.

How we use information

We use the information above to provide the account and trading functionality you signed up for, execute the strategies and limits you configure, show you your own positions and performance, detect fraud and unauthorised access, keep the systems secure and reliable, provide support, meet legal obligations that apply to us, and improve the product using aggregated or de-identified data wherever the purpose allows it.

We do not use your trading activity, positions, or performance to build advertising profiles.

How we share information

We do not sell personal data. We do not share your trading activity, positions, or performance with advertisers, data brokers, or other customers.

We share information only with:

  • Service providers who host our infrastructure, process payments, or provide support tooling, under contracts limiting them to that service. Today that is Vercel, which hosts this site. We will name each additional subprocessor here before it begins handling customer data, including whichever payment processor we adopt.
  • Your broker or exchange, to the extent necessary to place the orders you configured. This is inherent to how the product works.
  • Law enforcement or regulators, where required by valid legal process, or to protect the rights, property, or safety of Qorin, our customers, or the public.
  • A buyer or successor, if Qorin is involved in a merger, acquisition, or asset sale. We will tell you if your information changes hands this way.

How long we keep it

We keep information as long as we need it to provide the service, meet legal obligations, resolve disputes, and investigate security incidents:

  • Account information — for the life of your account, plus 90 days after closure.
  • Trading configuration and activity — four years after closure, to support dispute resolution and security investigations. This is set to the outside edge of the period in which a contract claim between us could realistically be brought, and no longer.
  • Broker and exchange credentials — revoked immediately on disconnection or account closure, and purged from our systems and backups within 30 days. We do not keep a live credential once it is no longer in use.
  • Technical and log data — 12 months.

We are not ourselves subject to broker recordkeeping rules, so these periods are our choice rather than an obligation we inherited. Where you have a right to request deletion sooner we will honour it, except where we have a legitimate need to retain specific records, such as an open fraud investigation or a legal hold.

Security

We maintain administrative, technical, and physical safeguards designed to protect your information, including encryption in transit using TLS 1.2 or better, encryption at rest using AES-256, access controls and multi-factor authentication for internal systems, automated scanning of our dependencies for known vulnerabilities, and logging of administrative access to production systems.

Before the product handles customer funds data we will add independent security testing and repeat it periodically. We would rather tell you that is still ahead of us than imply it has already happened.

No system is perfectly secure. If we learn of an incident that puts your information at risk we will tell you promptly, consistent with applicable law.

Your rights

If you are a California resident, you have the right to know what personal information and sensitive personal information we have collected, to correct it, to delete it, to limit our use of sensitive personal information, and to know whether we sell or share it. We do not sell personal information, and we honour Global Privacy Control signals as a valid opt-out. “Sharing” has a broad meaning under California law that can catch ordinary advertising and analytics tools; we are auditing our own marketing stack against that definition and will state the result here plainly, including if it turns out we need to offer an opt-out.

If you are a resident of Colorado, Connecticut, Virginia, or another state whose comprehensive consumer privacy law is in effect, you have the right to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of its sale, use for targeted advertising, or certain profiling. If we deny a request you may appeal at privacy@qorinsystems.com, and we will respond within the period your state's law allows.

If you are in the EU or UK, you have the right to access, correct, delete, and port your data, to restrict or object to certain processing, and to withdraw consent where we rely on it. You may lodge a complaint with your local data protection authority.

We process EU and UK data on these bases: performance of our contract with you, our legitimate interests in fraud prevention and service reliability, legal obligation, and consent for marketing and non-essential cookies. Transfers outside the EU or UK rely on the European Commission's standard contractual clauses, together with the UK international data transfer addendum where UK data is involved.

Contact privacy@qorinsystems.com to exercise any right described here. We will verify your identity before acting on a request involving your account, and we will not discriminate against you for asking.

Children's privacy

Qorin is not directed to, and is not available to, anyone under 18. We do not knowingly collect information from children. If we learn we hold information from someone under 18, we delete it.

Changes

If we make a material change to this policy we will notify account holders by email before it takes effect. The effective date above always reflects the current version.