Privacy Policy
Last updated: March 11, 2026
1. Introduction
Panovix ("we," "us," or "our") operates the website at panovix.com and the Panovix web application (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service.
By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Service.
For any privacy-related inquiries, contact us at support@panovix.com.
2. Information We Collect
2.1 Information You Provide Directly
When you register, subscribe, or communicate with us, we may collect:
- Account identifiers (name, email address, username)
- Authentication credentials (hashed passwords)
- Subscription and billing information (plan type, payment dates; we do not store full payment card numbers)
- Broker connection credentials (encrypted API keys, OAuth tokens for services such as NinjaTrader/Tradovate, ProjectX, and Rithmic)
- Trading data you choose to import or sync (trade history, journal entries, notes, screenshots)
- Support correspondence (emails, in-app messages)
- Affiliate application details (if applicable)
2.2 Information Collected Automatically
When you access the Service, we may automatically collect:
- Device and browser information (device type, operating system, browser type and version)
- Network activity (pages visited, features used, clicks, time spent)
- IP address and approximate geolocation derived from it
- Cookies and similar tracking technologies (see Section 6 below)
2.3 Information from Third Parties
We may receive information when you:
- Sign in via third-party providers (e.g., Discord, Google)
- Connect a brokerage account (account identifiers, trade data, balances)
- Are referred through an affiliate link (referral code, referring URL)
3. How We Use Your Information
We process your personal information for the following purposes:
- Account management: Creating, maintaining, and authenticating your account
- Service delivery: Providing trade journaling, analytics, trade copying, practice trading, and related features
- Payment processing: Managing subscriptions, invoicing, and affiliate commissions via Stripe
- Communication: Sending transactional emails (password resets, subscription confirmations), product updates, and—with your consent—marketing communications
- Analytics and improvement: Understanding usage patterns to improve the Service
- Security and fraud prevention: Detecting, preventing, and responding to security incidents
- Legal compliance: Fulfilling legal obligations and responding to lawful requests
We do not engage in fully automated decision-making that produces legal or similarly significant effects on you.
4. Broker Data and Trading Information
When you connect a brokerage account (e.g., NinjaTrader/Tradovate, ProjectX, Rithmic), we access your trading data solely to provide the features you have requested (journal syncing, trade copying, analytics).
- Broker API credentials are encrypted at rest using AES-256 encryption
- OAuth tokens are stored securely and refreshed automatically; we never see your broker password
- Trade data synced from brokers is stored in your private account and is never shared with other users
- You may disconnect a broker and delete synced data at any time through your account settings
5. Payment Information
We use Stripe as our third-party payment processor. When you subscribe or make a purchase:
- Payment card details are sent directly to Stripe and are never stored on our servers
- We retain only the last four digits of your card, card brand, and expiration date for display purposes
- Stripe processes payments in accordance with PCI DSS requirements
- For details on Stripe's data practices, see the Stripe Privacy Policy
6. Cookies and Tracking Technologies
We use cookies and similar technologies for:
- Strictly necessary cookies: Session management, authentication, and security (always active)
- Preference cookies: Remembering your settings (chart layout, theme, timezone)
- Analytics cookies: Understanding how users interact with the Service (e.g., Vercel Analytics)
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect Service functionality.
7. Data Sharing and Disclosure
We may share your information with:
- Service providers: Hosting (Vercel), payments (Stripe), email delivery, analytics, and customer support tools that process data on our behalf
- Broker platforms: When you connect a brokerage, we exchange data necessary for the integration to function (trade data, positions, orders)
- Legal authorities: When required by law, regulation, legal process, or governmental request
- Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity
We do not sell your personal information to third parties. We do not share your data for behavioral advertising purposes.
8. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Specific retention periods include:
- Account data: Duration of active account plus 30 days after deletion request
- Transaction records: Up to 7 years for tax and legal compliance
- Support correspondence: Up to 2 years after resolution
- Analytics data: Aggregated and anonymized data may be retained indefinitely
- Backups: Encrypted backups are purged within 90 days
9. Data Security
We implement industry-standard security measures to protect your personal data from unauthorized access, use, or disclosure, including:
- TLS encryption for all data in transit
- AES-256 encryption for sensitive data at rest (broker credentials, API keys)
- Hashed and salted passwords (bcrypt)
- Regular security assessments and vulnerability testing
- Role-based access controls for internal systems
No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data, subject to legal retention requirements
- Data portability: Request your data in a structured, machine-readable format
- Opt-out: Unsubscribe from marketing communications at any time via the link in any email or through account settings
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us at support@panovix.com. We will respond within 30 days.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose
- Request deletion of your personal information
- Request correction of inaccurate personal information
- Opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising)
- Non-discrimination for exercising your privacy rights
12. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected data from a minor, we will take steps to delete it promptly.
13. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our hosting infrastructure is located. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
14. Third-Party Links
The Service may contain links to third-party websites or services (e.g., broker platforms, TradingView). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
16. Contact Us
If you have questions or concerns about this Privacy Policy, contact us at:
- Email: support@panovix.com
- Website: panovix.com