1. Data We Collect
We collect the following types of personal data when you use our platform:
- Account Information: Name, email address, username, and password hash when you register.
- Profile Information: Avatar images, Telegram handle, and display name (if provided).
- Trade Journal Data: Trade entries, chart screenshots, P&L records, and personal trading notes you upload to the journal.
- Usage Data: IP address, browser type, device information, and interaction logs (e.g., page views, login times) collected automatically.
2. How We Use Your Data
We use your personal data solely for the following purposes:
- To provide, maintain, and improve the XAUCORE platform.
- To process your registration and authenticate your logins.
- To securely store your Trade Journal entries and chart screenshots for your personal use.
- To send you important administrative emails (e.g., password resets, subscription updates).
- To prevent fraud, abuse, and unauthorised access to the platform.
We do not sell, rent, or share your personal data or trading history with third parties for marketing purposes.
3. Data Storage and Security
Your data is stored securely on our servers. We implement industry-standard security measures, including encryption in transit (HTTPS/SSL) and secure password hashing (bcrypt/scrypt), to protect your data from unauthorised access, alteration, or destruction. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
4. Data Breach Notification
In compliance with the PDPA 2024 amendments, in the event of a data breach that is likely to result in significant harm to you, we will notify you and the relevant regulatory authorities as soon as practicable, detailing the nature of the breach and the steps taken to mitigate it.
5. Your Rights
Under the PDPA, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate or incomplete data.
- Deletion: Request the deletion of your account and associated data (including your Trade Journal).
- Withdraw Consent: Withdraw your consent for us to process your data, which may result in the termination of your account.
To exercise any of these rights, please contact our Data Protection Officer at admin@xaucore.com.
6. Third-Party Services
We may use third-party service providers (e.g., payment processors, email delivery services like Mailgun) to facilitate our services. These providers have access to your personal data only to perform specific tasks on our behalf and are obligated not to disclose or use it for any other purpose.
7. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Your continued use of the platform after changes are posted constitutes your acceptance of the revised policy.
8. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at admin@xaucore.com.
Effective Date: 1 May 2026 | XAUCORE | xaucore.com