Privacy Policy
Effective: May 12, 2026 · Version 1.0
1. Who we are
ShaFX (“we”, “us”, “our”) operates the website at shafx.net and the related trader dashboard. We act as the data controller for personal data described in this Policy.
2. Data we collect
Account data: name, email address, password hash, country, preferred currency, communication preferences.
Trading data: linked broker name, broker account number (last digits), aggregated lot volume per instrument, accrued cashback. We do not receive your password, balance, open positions, or P&L.
Payout data: chosen payout method (USDT wallet address, PayPal email, IBAN, broker credit), payout history, transaction references.
Technical data: IP address, browser, device, referring URL, pages visited, session duration. Used for security, fraud prevention, and product improvement.
Communications: support tickets, email correspondence, Telegram messages with our team.
3. How we use your data
- To create and operate your account
- To calculate and pay cashback and loyalty rewards
- To process payouts and meet anti-money-laundering obligations
- To prevent fraud, abuse, and unauthorised access
- To send service notifications, payout confirmations, and (with consent) marketing
- To comply with legal and regulatory requirements
4. Legal bases (GDPR)
We process your data on the following bases: (a) contract — to deliver the Service you signed up for; (b) legitimate interest — to secure the Service and prevent fraud; (c) consent — for marketing communications and optional analytics; (d) legal obligation — for tax, AML, and regulatory record-keeping.
5. Sharing your data
We share data only with: (a) partner brokers, to verify your linked account and confirm volume; (b) payment processors, to deliver your payouts; (c) infrastructure providers (hosting, email, analytics) under strict confidentiality; (d) authorities, when legally required. We never sell your personal data.
6. International transfers
Your data may be processed in countries outside your home jurisdiction. Where required, we use Standard Contractual Clauses or equivalent safeguards.
7. Retention
We keep account and trading data for as long as your account is active and for up to 7 years after closure to meet legal and tax obligations. Marketing-only data is deleted within 30 days of unsubscribe.
8. Your rights
You have the right to: access your data, correct inaccuracies, delete your account, export your data in a portable format, restrict or object to processing, and lodge a complaint with your local supervisory authority. Most rights can be exercised directly from your dashboard or by emailing privacy@shafx.net.
9. Security
We use TLS encryption in transit, hashed and salted password storage, principle-of-least-privilege access controls, and regular security reviews. No system is 100% secure; please use a strong unique password and enable two-factor authentication when available.
10. Cookies
See our Cookie Policy for details on cookies and similar technologies.
11. Children
The Service is not directed to anyone under 18. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact us and we will delete it.
12. Changes
We may update this Policy. Material changes will be notified by email or in-app notice at least 14 days before they take effect.
13. Contact
Privacy questions? Email privacy@shafx.net.