Privacy & Data Processing Notice
Wallet addresses and public trading records can be linked to individuals and are not inherently anonymous. SmartLiquid processes data using web servers, databases and third-party services. This notice does not promise complete decentralization, zero data collection or absolute security. The final privacy policy still requires the operator details and specific processing arrangements identified as outstanding in this draft.
1. Data processed and its sources
Depending on how you use the service, processing includes email, user identifiers and wallet addresses supplied by you or a login provider; authorization status, agent addresses and encrypted agent keys; copy settings, orders, fills, positions, performance and deposit, withdrawal or transfer records; and IP addresses, browser information and timestamps in access and security logs. The system can also infer country or region from IP addresses and obtain wallet activity from public interfaces such as Hyperliquid to generate statistics and labels. Combining public data with account information may identify a person.
2. Purposes and lawful grounds
Data is used for login and account management, authorization and copy execution, fee calculation, record displays, risk checks, troubleshooting and security audits. Each activity must have a lawful basis required by applicable law, such as contractual necessity, a legal obligation, assessed legitimate interests or valid consent; these grounds are not interchangeable. The final policy must map activities to their grounds and any relevant interests. Visiting the website alone must not be treated as consent to all processing.
3. Third-party recipients and international processing
Login authentication involves Clerk; some wallet, authentication and signing functions involve Turnkey; trading, queries and settlement involve Hyperliquid. Hosting, database and operational providers may also process data needed for the service. The final policy must specify the parties’ roles, data received, processing locations and international-transfer arrangements. Third-party policies do not replace the platform’s own transparency and protection duties. Legally required disclosures should remain within the applicable authority and procedures.
4. Device credentials and key-security boundaries
In supported device-authentication flows, fingerprints or facial features are normally verified by the device or authenticator, while the application processes verification results and related credential information. This does not establish that every wallet private key is stored in a local secure chip. Agent keys can be encrypted at rest on the platform and used for server-side signing, and third-party signing paths also exist. Encryption, access controls and third-party hardware protection do not eliminate key compromise, permission misuse, account-recovery or software risks, or mean that the entire copy system runs in a trusted execution environment.
5. Cookies and browser storage
The website and login services use cookies or similar technologies to maintain sessions. Local storage also records wallet preferences, onboarding status, risk acknowledgements and referral attribution. You can manage or clear this data through your browser, which may require signing in or configuring settings again. Clearing browser data does not revoke trading permissions or erase server records. Non-essential tracking requires the information and choices mandated by applicable law; risk acknowledgement or login is not consent to marketing tracking.
6. Retention and public-ledger limitations
Retention periods or clear criteria should be set for each data category according to service needs, legal duties, security and dispute handling; indefinite blanket retention is not appropriate. Actual periods for data and backups, deletion procedures and international arrangements have not yet been confirmed in this draft and must be completed in the final policy. Stopping copying or signing out does not erase all records. Public blockchain records generally cannot be changed or deleted by the platform, but this does not remove its obligations to handle lawful deletion requests for database records it controls.
7. Individual rights and contact channels
Depending on applicable law, you may have rights to information, access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaints to a competent authority. Wallet analysis and labels may involve profiling; where applicable, you may request information and human review of relevant automated decisions. Withdrawal does not affect earlier processing based on valid consent or automatically end processing supported by another lawful ground. The operator, usable privacy-request channel and relevant complaint authority remain to be confirmed; these details must be provided before the final policy takes effect.