Privacy policy
Effective 22 August 2026 · Spot Markets, Inc.
This policy covers aispotmarket.com, the trading dashboard, and the Spot API. It does not cover websites we link to, or how a seller venue handles a payload once it has left our gateway.
What we collect
Account data. Name, email, organization, billing address, and the bank or card you use to fund. For institutional accounts we also collect KYC documents you send the desk.
Authentication data. API keys we issue, hashed; session cookies on the dashboard; SSO identifiers if you turn on SSO.
Usage data. Request metadata required to match, settle, and operate the book: instrument, token counts, fill price, timestamps, error codes, IP used to call the API, and user-agent on the dashboard. We keep this so we can invoice you, prove a fill, and debug the engine.
Market data you already made public. Fills you cause print to the public tape without your identity. That print is not personal data.
What we do not keep
Prompts and completions. Spot operates under Zero Data Retention (ZDR): payloads pass through the gateway encrypted and are not written to disk. We do not train models on your traffic. Seller venues countersign the same ZDR and no-training terms.
Payment card numbers. Card data is handled by the payment processor. We store a token, not the PAN.
Why we use it
To operate the marketplace (matching, settlement, payouts), to secure accounts, to invoice and collect fees, to publish the public tape and the Spot Index, and to meet law-enforcement or tax requests we are legally required to answer.
Who we share it with
Venues, so they can serve the request you just bought. They see the payload, not your billing profile.
Processors we use to run the product: hosting, email, payments, and (if you enable it) SSO. They are under contract and are not allowed to use the data for their own purposes.
The public tape, which contains price, size, instrument, and region, never your name or your prompt.
We do not sell personal information.
Retention
Account and ledger records are kept for the life of the account plus the period we need for tax and dispute handling (typically seven years for journals). Session cookies expire. Prompt payloads are not retained. If you close an account we delete or irreversibly anonymize what the law lets us delete.
Your rights
If you are in the EEA, UK, or a US state with a privacy statute you can ask for a copy of the account data we hold, a correction, or a deletion of what is not required to keep the ledger honest. Email legal@aispotmarket.com. We will need to verify you own the account.
A DPA is available on request for customers who need one. GDPR residency pinning is an account setting: US, EU, or APAC.
Cookies
The marketing site is a static Worker and does not need an account cookie. The dashboard uses a session cookie to keep you signed in. We do not run third-party advertising pixels on this site.
Changes
We will update the effective date on this page when the policy changes. Material changes will also appear on the changelog.