Privacy Policy
Your trust and capital safety are our highest priorities. Learn how YesToBuy protects your credentials, encrypts trading data, and maintains zero access to your funds.
AES-256-GCM
All broker API secrets and tokens are encrypted at rest with military-grade ciphers.
Zero Fund Access
Broker APIs forbid withdrawals via trading keys. We can never move or withdraw your money.
No Data Selling
We never monetize, rent, or share your trade history, strategies, or personal details.
Instant Wipe
Disconnecting a broker or closing your account permanently deletes all stored credentials.
1. Overview & Commitment
YesToBuy ("we", "us", "our", or the "Platform") provides algorithmic trade execution and automated risk management software for Indian stock and derivative traders. We are committed to transparency, data minimization, and strict security compliance. This Privacy Policy details how we collect, store, process, and safeguard your personal details, broker credentials, and order telemetry when you use our website, APIs, and trading desk.
2. Information We Collect
We collect only the minimum information necessary to authenticate your identity, execute your automated trading rules, and display live order analytics:
- Account Credentials: Your full name, email address, and encrypted passwords. Passwords are never stored in plaintext and are hashed using modern cryptographic algorithms (e.g. Argon2 / Bcrypt).
- Broker API Data: Your broker client ID, App ID, API Secret Key, and temporary session authorization tokens (for supported brokers including Fyers, Dhan, Angel One, and Upstox).
- Trade & Order Telemetry: Records of webhooks received, signals processed, order parameters (symbol, price, quantity, direction), broker order IDs, fill status, and execution timestamps.
- Session & Audit Logs: IP addresses, browser user-agent, and login timestamps used strictly to prevent unauthorized access and maintain security auditability.
3. Protection of Broker Credentials & Fund Safety Guarantee
SEBI regulations and Indian broker API architectures (Fyers, Dhan, Angel One, Upstox) strictly isolate trading endpoints from banking/withdrawal operations. Algorithmic API keys cannot authorize fund withdrawals, account transfers, or bank account changes. YesToBuy never has, nor will ever request, access to transfer or withdraw funds from your trading account.
All broker secrets, auth codes, and refresh tokens stored in our PostgreSQL database are encrypted at rest using AES-256-GCM authenticated encryption. Encryption keys are managed securely in server environment variables and are never checked into version control. In-memory decryption occurs strictly in ephemeral OTP processes when issuing authorized order requests to your broker.
4. How We Use Your Information
Your data is processed strictly for the following functional purposes:
- Routing trade orders to your connected broker gateway in real time according to your predefined signal and risk configurations.
- Enforcing your safety risk matrix (maximum daily loss limits, per-trade position size caps, stop loss, and max daily trade limits).
- Conducting automated morning session token validations before market open (9:15 AM IST) to ensure trade readiness.
- Rendering live position analytics, P&L reporting, and execution latency metrics in your personal trading dashboard.
- Sending essential operational alerts (e.g., token expiration notices, risk limit alerts, or account security notifications).
5. Third-Party Broker Integrations
When an order is triggered, YesToBuy transmits your trade parameters directly to the authorized API servers of your selected broker (such as
api.fyers.in
or api.dhan.co) over encrypted TLS 1.3 connections. We do not intermediate funds, and we never share your data with unauthorized third parties, advertisers, or third-party analytics trackers.
6. Data Retention & User Rights
You maintain full sovereignty over your data:
- Credential Revocation: You can disconnect or delete any broker integration from your Settings dashboard at any time. Doing so immediately purges the associated API keys and session tokens from our database.
- Account Deletion: You may request full account termination at any time by contacting our support desk. All associated profile data, risk settings, and credentials will be permanently erased.
- Export Rights: You can export and download your trade records and audit logs directly from the platform.
7. Security & Infrastructure Controls
Our application infrastructure adheres to rigorous software engineering best practices:
- End-to-end encryption in transit (HTTPS with TLS 1.3 and HSTS headers enforced).
- Cross-Site Request Forgery (CSRF) protection and Content Security Policies on all forms and WebSocket channels.
- Strict rate limiting on login and registration endpoints to protect against brute-force attacks.
- Automated server-side error monitoring without recording sensitive credential payloads in log files.
8. Grievance Officer & Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data security, please contact our designated privacy and security team:
Privacy & Security Officer: YesToBuy Financial Technologies
Email: privacy@yestobuy.com
Support Portal: support@yestobuy.com
Response Window: All security and privacy inquiries are acknowledged within 24 business hours.