The short version#
- We store an email, your orders, your simulated trading records, and a payout wallet address.
- We do not collect identity documents for KYC.
- We don't sell personal data. Processors get only what they need to work.
What we store#
| Data | Why |
|---|---|
| Email + password hash (or Google OAuth id) | your login |
| Display name (optional) | your profile |
| Orders + payment references | what you bought; Helio tx / PayPal capture ids |
| Simulated trading records | orders, fills, positions, equity history, breach evidence |
| Payout wallet address + payout records | paying you; on-chain tx signatures |
| Affiliate data (if you join) | clicks, conversions, commissions |
| Technical logs (IP, user agent) | rate limiting, abuse and fraud prevention |
| Device and network signals | enforcing one person per account, and stopping banned traders returning under a new email |
Trading records are also the product's honesty mechanism — every fill keeps the market snapshot it was quoted against (see the fill policy).
On device and network signals specifically. Because there is no KYC here, the account limit and the ban list in the rules would otherwise mean nothing — an account is an email address, and email addresses are free. So when you sign up, sign in, buy an evaluation or request a payout we record the IP address the request came from, its rough location (country, region, city — from the address, never from GPS), your browser's user-agent string, and a fingerprint your browser computes from its own hardware and locale: platform, graphics adapter, screen size, timezone, language, processor cores and memory. Those values are hashed; the hash is what we store and compare.
What that is used for, and nothing else: matching accounts to each other. It is never used to track you across other websites, never sold or shared with advertisers, and never fed into analytics. We do not enumerate your fonts, read your clipboard, or touch your browsing history. A match is a prompt for a human to look — a shared IP address is treated as weak on its own, because households, offices and mobile networks produce them constantly — and no account is closed by an automated decision alone. These records are kept for as long as the account exists and up to 24 months afterwards as fraud evidence.
What we never collect#
- No identity documents, selfies, or address proofs — no KYC exists here.
- No card numbers or bank details: card/PayPal data stays with PayPal; crypto payments settle on-chain via Helio. We see references, not credentials.
- No retargeting or advertising pixels. Analytics are listed in full under Cookies and analytics.
Fullport Tap (browser extension)#
Fullport Tap overlays a trade panel on supported trading terminals. It runs only on those sites, and it handles exactly this data:
| Data | What happens to it |
|---|---|
| Your Fullport session token + account email | stored locally in the extension after you click Connect; used to authenticate to our engine |
| The token / pool address of the coin page you have open | read from the page URL (or the page when the URL hides it) and sent to our engine to quote and fill your simulated orders |
| Your panel settings (presets, slippage, unit) | stored locally in the extension |
| Anonymous diagnostics (which terminal, order result code, latency) | sent to our engine to keep fills reliable; contains no page content, no wallet data; switch it off in the panel settings |
- It never requests wallet access, seed phrases or private keys, and never places on-chain transactions.
- It never reads or changes the terminal's own controls, and does not record your browsing, clicks or keystrokes.
- It talks only to fullportcapital.co and our engine host — no third-party analytics or ad networks.
- Uninstalling the extension deletes everything it stored locally; your account data stays with your Fullport account as described above.
How it's used#
To operate your accounts, compute and enforce the published rules, process payments and payouts, prevent fraud and simulation abuse (conduct-rule screening such as deployer-wallet checks and markout monitoring), send transactional email (account issued, breach, payout status), and comply with law. We do not sell or rent personal data, and we don't send marketing email without your consent.
Retention#
- Account and trading records: kept while your account exists, then up to 24 months for dispute and fraud defense.
- Order/payout records: kept as required for accounting and tax law.
- High-resolution price ticks: about 7 days; equity snapshots: about 30 days at full resolution.
- Technical logs: about 90 days.
Security#
Transport encryption everywhere, row-level access controls on user data, trading state writable only by the engine's service credentials, admin actions audit-logged, and payout signing keys kept off our servers entirely (payouts are signed from an offline operator machine). No system is perfect; we design so that a web-tier compromise cannot move treasury funds.
Your rights#
Email fullportcapitalco@gmail.com from your account email to access, correct, export, or delete your data. Deletion removes personal identifiers; records we must keep (paid orders, payout ledgers, fraud evidence) are retained in de-identified or legally-required form.
Privacy contact#
For questions about how Fullport Capital handles your data, email fullportcapitalco@gmail.com. See Your rights for account-data requests.
Changes#
Material changes to this policy will be posted here with an updated date, and announced in-product for logged-in users.