Skip to content
YinYang

Legal

Privacy Policy

Version
1.0
Effective date
Last updated

1. Who we are and what this Policy covers

YinYang Algorithms Inc., identified by the Service as an Ontario, Canada corporation (“YinYang,” “we,” “us,” or “our”), operates yinyangalgorithms.com and the related web application, account, subscription, support, referral, and TradingView-benefit workflows.

This Privacy Policy applies to personal information handled through those services. It does not govern a third-party service that you visit or use under that provider’s own terms and privacy policy.

2. Information you provide

  • Account data: email address, username, password, and acceptance of the Terms and Privacy Policy. We store a password hash rather than the password in readable form.
  • Profile and benefit data: TradingView username, Discord username where supplied, account role, plan and entitlement details, and marketing preference.
  • Referral data: referral code, the referring-account relationship, and related registration and aggregate conversion records.
  • Support data: ticket category, subject, message, replies, status, and any information you choose to include. Do not include passwords, private keys, exchange credentials, full card data, or unnecessary identity documents.
  • Creator-application data: name, contact email, primary platform, profile or channel URL, approximate audience, niche, optional country or region, proposal, and consent to be contacted. The application is stored through the authenticated support-ticket workflow.
  • Preferences and content: alert definitions, alert history, feature interests, chart or indicator settings, drawings, and other settings you create or save.

3. Account authentication and browser-held credentials

The Service uses signed access and refresh tokens for authentication. The current frontend stores those tokens in browser local storage and sends the access token with authenticated API requests. Access tokens default to a shorter validity period than refresh tokens, and the frontend attempts refresh before expiry.

Signing out removes the locally stored tokens from that browser. The current system does not maintain a user-facing list of authenticated devices or server-side sessions and does not provide remote token revocation. Protect your device and sign out on shared devices.

4. Billing and subscription information

When you initiate billing, Stripe may receive your email address, YinYang user and customer identifiers, selected plan and interval, TradingView username where required, and referral, trial, or promotion metadata. Stripe collects and processes payment methods. YinYang does not request or store full card numbers or card security codes.

We store limited Stripe and billing records needed to create a customer, reconcile Checkout, apply entitlements, prevent repeated trial or offer use, handle invoices and payment failures, record cancellation state, support disputes, and audit legal acceptance. These records can include Stripe customer, Checkout, Price, Coupon, subscription, invoice, trial, payment-status, and event identifiers.

5. Information collected through use of the Service

For authenticated users, first-party analytics can record the account identifier, page or route, event type and name, event properties, conversion details, a browser-generated session identifier, and time of activity. These records are used to understand and operate the Service; the audited application does not include a third-party advertising or behavioural-analytics SDK.

Our frontend, backend, hosting providers, and security controls also process ordinary request and diagnostic information such as URL, request time, response status, IP address, browser or user-agent headers, authentication result, error context, and service logs. IP addresses are used by rate limiting and may be available to Vercel, Railway, and network providers.

Alert definitions and alert history are stored through authenticated backend services. Notification-display preferences and some chart, indicator, strategy, and alert settings remain in browser storage. Chart drawings may use IndexedDB with a local-storage fallback.

6. Help chat, support tickets, and email copies

Questions typed into the Help chat are matched in your browser against YinYang’s current FAQ, tutorial, and support content. That question-and-answer history is held in the page’s memory and is not sent to an external AI provider or saved to the backend by the chat-answer function.

If you choose to create or reply to a support ticket, the confirmed subject and message are sent to the backend and stored with your account. Authorized employees or administrators may review support content to respond and operate the Service. Support notifications and some administrative copies may be sent through the configured email service.

7. Cookies and browser storage

The current Service uses local storage, session storage, and IndexedDB for authentication tokens, referral attribution, an analytics session identifier, guest-preview state, interface preferences, chart layouts, drawings, indicators, strategies, and alerts. A first-party yy_preview_expired cookie may remember for up to 30 days that a guest preview expired. It uses SameSite=Lax and is used for preview continuity and abuse prevention.

You can clear these items through browser controls, but doing so can sign you out, reset preferences or drawings, remove referral attribution before signup, or restart local state. The current site does not provide a cookie-consent manager. If optional advertising or third-party analytics technology is introduced, this Policy and any required consent controls must be updated before use.

8. External content and market-data requests

Binance supplies market data used by the Service. Some frontend market-data requests can connect directly to Binance, which means Binance may receive ordinary network and request information such as your IP address and browser headers.

Tutorial videos use YouTube’s privacy-enhanced youtube-nocookie.com embed and load lazily. Loading or playing an embedded video still creates a connection to YouTube and may allow YouTube to process device and usage information under its own privacy terms.

TradingView and Discord usernames are stored when you request related benefits. Those services are separate, and no automated TradingView or Discord provisioning API is present in the audited application. Information may be used by authorized personnel to perform the requested manual provisioning or support.

9. Why we use information

  • create accounts, authenticate requests, maintain profiles, and provide guest, Free, beta, paid, and staff access;
  • deliver charts, analytics, indicators, alerts, saved settings, tutorials, support, and requested external benefits;
  • create and reconcile Stripe billing, trials, promotions, renewals, cancellations, payment failures, and entitlements;
  • answer support and privacy requests and administer creator applications;
  • record legal acceptance, marketing choices, referral attribution, and aggregate referral conversions;
  • operate, diagnose, secure, prevent abuse of, and improve implemented Service features;
  • comply with legal obligations and establish, exercise, or defend legal claims.

10. Consent and your choices

Required account and service processing is identified through the registration and checkout disclosures. Optional marketing consent is presented separately and is not preselected. Where consent is the applicable basis, you may withdraw it, subject to reasonable notice and any processing that remains necessary for your account, a transaction, security, or law.

You can choose whether to provide optional profile fields, whether to apply a referral code, whether to load external video content, and whether to receive marketing. Some information is necessary to create an account, authenticate you, deliver a selected feature, or complete billing.

11. Marketing and service communications

Product updates, beta announcements, market insights, launch offers, and promotion campaigns are marketing messages. The current campaign selector sends those messages only to accounts whose stored marketing preference is enabled.

You can opt in during signup or change the setting at any time under Profile → Email preferences. Turning it off updates your account preference and is used to exclude the account from later campaign-recipient selection. A promotional message already queued for retry may not be stopped by the current implementation. The presently implemented control is the authenticated Profile setting; the application does not currently provide a one-click email unsubscribe endpoint.

Messages sent for account operation, security, support, trials, billing, receipts, cancellation, and payment status are treated as service or transactional communications. Turning off marketing does not stop communications reasonably needed to provide the account or transaction. Some billing communications may be sent by Stripe according to Stripe configuration.

12. Service providers and other disclosures

Confirmed technology and service relationships used by the current implementation include:

  • Vercel for frontend hosting and the application API proxy;
  • Railway and PostgreSQL for backend hosting and application data storage;
  • Stripe for customers, Checkout, Customer Portal, subscriptions, invoices, payment methods, billing events, trials, and promotions;
  • Google Gmail API or configured SMTP through Nodemailer for outbound email and notification copies;
  • Binance for market data; and
  • YouTube for privacy-enhanced tutorial-video embeds.

We may disclose information to these providers only as reasonably needed for their role; to professional advisers under appropriate duties; to investigate fraud, abuse, security events, or disputes; when required by law or valid legal process; or in connection with a merger, financing, reorganization, sale of assets, or other business transfer, subject to applicable law.

We do not sell personal information or use it for cross-context behavioural advertising in the current implementation.

13. Cross-border processing

YinYang is identified as operating from Ontario, Canada, but service providers may process information in Canada, the United States, or other locations where they or their subprocessors operate. Information in another jurisdiction may be available to courts, law enforcement, or regulators under that jurisdiction’s laws. Exact hosting regions and provider subprocessors can change and are not controlled solely by application code.

14. Security safeguards and access

Current safeguards include bcrypt password hashing, signed authentication tokens, authenticated API routes, role checks for employee routes, CORS and security headers, rate limiting, Stripe webhook-signature verification, webhook-event idempotency, and provider-managed transport encryption. Access to account, billing, and support information is intended to be limited to users, authorized personnel, and providers that need it for their role.

No internet or storage system is perfectly secure. Browser-held bearer tokens and information included in support requests can be sensitive. Protect your credentials and device, do not submit secrets in tickets, and report suspected unauthorized account activity through the Support Centre.

15. Retention

We keep personal information only as long as reasonably needed for the purposes described in this Policy, including maintaining an account or subscription, providing support, preventing fraud and repeated offer use, securing the Service, resolving disputes, maintaining legal-acceptance evidence, and meeting tax, accounting, and legal obligations.

Different records have different purposes, so there is no single fixed retention period stated here. Closing a support ticket does not delete it. Browser data remains until you or the application clears it. Stripe, Google, Vercel, Railway, Binance, and YouTube apply their own retention practices to information under their control.

Deletion may leave limited residual copies in backups or disaster-recovery systems where applicable until those copies are overwritten or no longer needed. Those copies are not ordinarily used for active operations. Backup retention periods depend on provider and deployment configuration and are not fixed in this Policy.

16. Access, correction, deletion, and complaints

Depending on the law that applies, you may have rights to ask about the existence, use, and disclosure of your personal information; request access or correction; request deletion; withdraw consent; object or restrict certain processing; receive portable information; or complain to a privacy regulator. These rights may be subject to identity verification and lawful exceptions.

You can directly change your marketing preference and submitted TradingView or Discord username through Profile. The Service does not currently provide self-service account deletion, a general export tool, or direct editing of account email and username.

To request access, correction, deletion, marketing withdrawal, or review of a privacy concern, submit an authenticated support ticket and identify it as a privacy request. We may need to verify that you control the account. We may retain limited billing, legal-acceptance, security, fraud, tax, accounting, or dispute records where deletion is not required or permitted. The verified request path currently requires account access; a separate public privacy mailbox and postal address are not published.

17. Legal requests, security incidents, and business transfers

We may preserve or disclose information where reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate fraud or abuse, enforce agreements, or establish or defend a claim. We will assess the scope and legal basis of a request before disclosing information where applicable.

If a security incident involving personal information occurs, we will investigate and take reasonable containment and remediation steps. We will notify affected individuals and regulators when applicable law requires notification. This Policy does not promise that every event will meet a legal reporting threshold.

If the Service or business is reorganized, financed, merged, sold, or transferred, personal information may be reviewed or transferred as part of that transaction, subject to confidentiality safeguards and applicable law.

18. Children

The Service is not directed to children and is intended for people who can enter the Terms of Service in their jurisdiction. Registration does not collect a date of birth and the current application has no parental-consent workflow. If you believe a child provided personal information through the Service, use the contact route below so the circumstances can be reviewed.

19. International users

If you use the Service outside Canada, local privacy law may provide additional rights or impose additional limits. Submit a request through the process above and identify your jurisdiction so we can assess the law that applies. The availability of the Service in a location does not mean every feature, payment method, or privacy regime applies there.

20. Changes to this Policy

We may update this Policy prospectively when our Service, providers, processing, or legal obligations change. The live page identifies its version, effective date, and last-updated date. For a material change, we will provide notice or request a new acknowledgement where required. Historical acceptance records retain the policy version recorded at the time.

21. Privacy questions and complaints

Account holders can submit a privacy question or complaint through an authenticated support ticket. Include the account email, the right or concern involved, the information or time period at issue, and the requested outcome, but do not include a password, token, full card number, or unnecessary identity document.

If you are not satisfied with the response, you may have the right to contact the Office of the Privacy Commissioner of Canada, an applicable provincial privacy authority, or the privacy regulator in your jurisdiction.

Related: Terms of Service, Support Centre, and Support Ticket.