Privacy Policy
Last updated: August 24, 2026
This Privacy Policy describes how Private Parachute, Inc. ("Parachute," "we," "us," or "our") collects, uses, and protects your information when you use the Parachute Bot Trader platform ("Service"), including the public website, the interest form, checkout, and the authenticated dashboard.
1. Information We Collect
Account Information
When you create an account, we collect your email address, name, and avatar preference, along with records of your subscription and any strategies you license through the marketplace. Account authentication is handled through Supabase.
Kalshi API Credentials
To operate the trading bot on your behalf, we store your Kalshi API key ID and private key. Your private key is encrypted at rest using AES-256-GCM encryption and is decrypted only in memory during bot execution. We never store your private key in plaintext, and we never have access to your Kalshi account password.
Trading Telemetry
The bot generates data about its trading activity, including fills, settlements, positions, heartbeats, market scans, execution orders, and trading signals. This data is stored in our database to power the monitoring dashboard.
We also analyze trading telemetry in aggregated or de-identified formacross accounts — for example, to evaluate how strategies and configurations perform, to improve execution quality, and to decide which strategies to build next. Aggregate analysis never identifies you and never discloses your individual positions or trading activity to other customers.
Usage Data
We collect login events, IP addresses, and anonymous page view analytics (via Vercel Analytics). We use Sentry for error tracking, which may collect stack traces and browser information when errors occur.
Lead Form
If you submit the interest form on our landing page, we collect your name, email address, Kalshi account status, and intended investment basis. We use this information to contact you about the Service.
2. Information We Never Collect
- Your Kalshi account password
- Your bank account or payment card information (handled entirely by Stripe)
- Personal financial data beyond what the trading bot generates and the interest-form figure above
3. How We Use Your Information
- To operate the trading bot on your Kalshi account
- To display your trading performance and bot status on the dashboard
- To send you transactional emails (account invites, password resets, alerts)
- To process your subscription and marketplace payments via Stripe
- To diagnose and fix software errors
- To improve the Service
- To evaluate strategy and configuration performance in aggregated, de-identified form across accounts, informing Service improvements and which strategies we build next
We do not sell your personal information, and we do not share it with third parties for their own advertising or marketing purposes.
4. Third-Party Services
We use the following third-party services to operate the platform:
- Supabase — database, authentication, and realtime subscriptions
- Stripe — subscription billing and payment processing
- Resend — transactional email delivery
- Vercel — web application hosting and anonymous analytics
- Sentry — error monitoring and performance tracking
- DigitalOcean — managed VPS hosting for Cloud-tier trading bots
- Kalshi — event contract trading platform (via your API credentials)
Each of these services has its own privacy policy governing the data they process on our behalf.
5. Data Retention
Trading telemetry is subject to automated retention policies: market scans are retained for approximately 30 days in the operational database (days pending archival may persist longer), bot heartbeats for 14 days, and execution data for 90 days. Account data (credentials, profile, trading configuration) is retained until you request deletion.
6. Data Security
We take the security of your data seriously. API credentials are encrypted with AES-256-GCM. All data is transmitted over HTTPS. Database access is controlled by row-level security policies. However, no system is perfectly secure, and we cannot guarantee the absolute security of your data.
7. Cookies
We use a functional session cookie for authentication (managed by Supabase). Vercel Analytics collects anonymous usage data without using cookies that track personal information. We do not use advertising or third-party tracking cookies.
8. Your Rights
You may ask us, at the contact address below, to: access a copy of the personal information we hold about you; correct information that is inaccurate; delete your account and its associated data; provide your data in a portable format; or object to or restrict a particular use of it. If you are in the European Union, the United Kingdom, or California, these requests correspond to rights you hold under GDPR, UK GDPR, or CCPA/CPRA respectively, and you may also have the right to lodge a complaint with your local supervisory authority.
Account deletion will remove your profile, credentials, trading configuration, and telemetry data. Aggregated or de-identified data that no longer identifies you or your account (for example, cross-account strategy performance statistics) may be retained after deletion. Account deletion will not affect your Kalshi account.
9. International Data Transfers
Our infrastructure providers (listed in Section 4) store and process data primarily in the United States. If you access the Service from outside the United States, your information is transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction.
10. Children's Privacy
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from minors.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service.
12. Contact
Questions about this Privacy Policy, or a privacy request? Contact us at derek@parachute.fund.