HollowCandle
Privacy Policy
Last updated: October 6, 2026
This policy explains what information HollowCandle ("we", "us") collects when you use hollowcandle.com, how we use it, and the choices you have. It applies to the website, the trading terminal, alerts, and related services (together, the "Service").
1. Information we collect
- Account information — the email address you register or the Google account you sign in with. If you connect a crypto wallet, we store the public wallet address you connect (wallet addresses are public on-chain data by nature).
- Exchange API keys (optional) — if you connect a Binance API key for live trading, we store that key and its secret only in encrypted form (AES-256-GCM envelope encryption) and display back only a masked fingerprint. We refuse keys with withdrawal permissions, and disconnecting the key deletes the stored record.
- Usage data you create — your paper-trading account state (positions, simulated fills, PnL), alert rules you configure, plan/subscription status, and display preferences.
- Technical data — session cookies and a pseudonymous visitor id used to keep you signed in and rate-limit abuse (see §4). We do not run third-party advertising or cross-site tracking trackers.
2. What we do not collect
- We never ask for, store, or process card numbers — payments run inside Whop's embedded, PCI-compliant checkout.
- We never request wallet signatures that move funds, and we cannot access your wallet's private keys. LIVE wallet reads are read-only. Exchange API keys you optionally connect are stored encrypted and limited to trading — withdrawal-enabled keys are refused.
- We do not sell personal data.
3. How we use information
- Authenticate you and keep your session signed in.
- Store and evaluate your alert rules server-side so they keep watching prices while you are away.
- Maintain your paper-trading ledger (simulated balances, positions, and fills on real market prices).
- Manage your subscription through our payment provider.
- Prevent abuse (rate limiting) and diagnose errors.
4. Cookies
We set a small number of strictly necessary cookies and no advertising cookies:
gb_session— your signed-in session (deleted when you log out).gb_uid— pseudonymous visitor id used before you have an account.hc_google_oauth_state— short-lived CSRF protection during Google sign-in (10 minutes).
5. Third-party services
- Google — optional "Continue with Google" sign-in. Google shares your name, email, and profile picture when you choose it. Subject to Google's Privacy Policy.
- Whop — payments and subscription billing (card data is collected and processed by Whop and its payment processors, never by us).
- TradingView — embedded chart widgets. Loading a chart connects you to TradingView's servers.
- Market data providers — public cryptocurrency exchange APIs (e.g. Binance) provide the market prices used for simulated fills. When you place live orders with a connected API key, Binance also executes those orders and processes the associated account data under its own terms.
- Hosting & database — Vercel (application hosting) and Neon (managed PostgreSQL) process data on our behalf.
6. Wallet & exchange connections
Connecting a wallet is optional. We only read public on-chain balances through your wallet's standard interface, display them to you, and never initiate transactions, swaps, or signatures that could move funds.
Connecting an exchange API key is optional and enables real trading on your own account. The key and secret are stored only in encrypted form, are used solely to place orders and read balances at your instruction, are refused if they allow withdrawals, and are deleted when you disconnect them in the terminal.
7. Retention & security
- Account and usage data is retained while your account is active.
- Deleting your account or requesting deletion removes your personal data from production within 30 days (backups may persist briefly and are then destroyed).
- Data is encrypted in transit (TLS) and at rest by our providers. Connected exchange API keys are additionally encrypted with our own AES-256-GCM vault before storage. No system is perfectly secure, but we minimize what we hold.
8. Your rights
You may request access to, correction of, or deletion of your personal data at any time by emailing mallmallcovv@gmail.com. We respond within 30 days. If you are in the EEA/UK, you also have the right to lodge a complaint with your local supervisory authority.
9. Children
The Service is not directed at anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes
If we change this policy we will update the date above and, for material changes, announce them in the app before they take effect.
11. Contact
Questions about privacy: mallmallcovv@gmail.com.