1. Overview, Purpose & Statutory Context
Welcome to Arkenwell. Arkenwell develops high-performance quantitative market intelligence tools, options terminal dashboards, volatility analytics engines, and derivatives software hosted at arkenwell.co and its subdomains (collectively, the "Platform").
This Privacy Policy details our operational data practices, technical security architecture, sub-processor disclosures, and user data principal rights. We operate under core privacy principles of transparency, purpose limitation, data minimization, storage limitation, and robust cryptographic security.
This framework is designed with consideration for international privacy standards and compliance with applicable requirements under the India Digital Personal Data Protection (DPDP) Act, 2023. We do not monetize, sell, or rent your personal data to third-party data brokers or advertising networks.
2. Data Controller & Operator Identity
Arkenwell operates as an independent financial technology workstation and quantitative market intelligence platform governed under Indian legal jurisdiction.
support@arkenwell.coprivacy@arkenwell.co3. Granular Categories of Information We Collect
We process personal data strictly necessary to authenticate your sessions, maintain your custom terminal configuration, persist your workspace state, and secure our API endpoints against malicious traffic.
A. Account Registration & Identity Credentials
When you register for an account or log into the Terminal, we collect your verified primary email address, full name, salt-hashed password credentials, display handle, and optional profile metadata provided during Google OAuth single sign-on authentication.
B. Workspace Preferences & Analytical State
To preserve your workspace across sessions, our servers store user-created watchlists, saved option chain strike layouts, dealer positioning parameters (such as Gamma Exposure and Delta Exposure preferences), custom volatility alert thresholds, saved backtesting inputs, and portfolio tracking parameters.
C. Technical Telemetry & Infrastructure Metadata
When accessing our web applications or API backend, our servers automatically log client IP addresses, HTTP User-Agent strings, browser types, operating system versions, authorization token timestamps, API route latency metrics, and system error tracebacks required for system performance and threat monitoring.
D. Explicit Exclusions
Arkenwell does not collect or store raw payment card numbers, CVVs, expiration dates, bank passwords, or national tax identifiers (such as PAN or Aadhaar) unless mandated by future statutory KYC regulations. Payment card processing is delegated entirely to authorized PCI-DSS compliant payment gateways.
4. Technical Authentication & Token Security
Security and session integrity are built directly into our code architecture:
- RS256 Asymmetric JWT Tokens: User sessions are authorized using JSON Web Tokens (JWT) signed with an RS256 asymmetric cryptographic algorithm using a 4096-bit RSA key pair. Tokens automatically expire to mitigate session hijacking risks.
- One-Time Password (OTP) Verification: Verification codes for login and registration consist of 6-digit cryptographic tokens that automatically expire within 10 minutes. Codes are processed in-memory and dispatched via SendGrid and Resend transactional email gateways.
- OAuth 2.0 Identity Federation: Single Sign-On via Google OAuth retrieves verified email and profile claims directly from Google identity servers without exposing or storing Google account passwords.
- Encrypted Database State: User authentication states, refresh tokens, and session credentials are stored in encrypted database tables managed via Supabase Auth.
5. Purposes of Data Processing
We process your personal information strictly for the following operational purposes:
- To create, verify, and manage your Arkenwell account credentials.
- To execute user-requested quantitative queries, option chain calculations, and backtesting models.
- To persist custom workspace preferences, watchlists, and price/volatility alert triggers.
- To process subscription plan payments and invoices through authorized payment processors.
- To monitor backend API latency, detect intrusion attempts, and prevent brute-force abuse.
- To respond to customer support inquiries and statutory grievance complaints.
6. Market Data, Exchange Compliance & Non-Redistribution
Market data displayed across Arkenwell (including quotes, option chains, and index values from the National Stock Exchange of India (NSE), BSE, and MCX) is provided under vendor licensing agreements strictly for end-user visual analysis.
- Non-Redistribution: You are strictly prohibited from scraping, automated downloading, re-transmitting, or reselling raw exchange data feeds from the Terminal.
- Subscriber Classification: You may be required to declare your status as a Non-Professional (Retail) or Professional subscriber to comply with exchange fee schedules.
- Data Delays: Feeds may be served in real-time or on a 15-minute delayed basis depending on subscription tier. Delay indicators are displayed on terminal views.
7. Infrastructure & Sub-Processors
Running a live market terminal takes a handful of specialist services. We keep the list short and share only the minimum each one needs — every provider below is bound by a data protection agreement, and none of them receive your watchlists, search queries, or strategy inputs for their own use.
| Partner | What it helps us do | Region |
|---|---|---|
| Vercel | Serves the website and terminal interface | USA / Global Edge |
| AWS | Runs the analytics backend | India (AWS Mumbai) |
| Supabase | Stores your account securely (encrypted database) | USA / AWS Cloud |
| SendGrid / Resend | Sends login and verification emails | USA |
| Razorpay | Processes subscription payments | India |
8. Data Retention & Erasure Schedule
We retain personal information only for as long as necessary to satisfy operational purposes or legal duties:
- Active Accounts: Profile data is retained for the active lifecycle of your account.
- Account Erasure Requests: Upon receiving a verified deletion request, account data is permanently purged within 30 calendar days.
- Email OTP Codes: Verification codes expire and are purged from memory within 10 minutes.
- Security Audit Logs: System connection logs are retained for 180 days to support security analysis, then overwritten.
- Billing & Tax Records: Transaction logs are retained for 7 years to comply with statutory tax legislation.
9. Your Rights & Erasure Requests
Under the India DPDP Act 2023 and global privacy standards, you possess rights to access, correct, or delete your personal data.
To request a copy of your personal data, correct inaccurate details, or request full account erasure, email our Privacy Desk at
privacy@arkenwell.co. All requests are acknowledged within 48 hours and completed within 30 days.10. Security Hardening & Technical Controls
We enforce HTTPS TLS 1.3 transit encryption across all API endpoints, AES-256 database storage encryption, restricted database connection pools (10–80 max connections), static code auditing (`oxlint`), and zero public database network access.
11. Children's Privacy & Age Restriction
The Arkenwell Terminal is strictly intended for adult quantitative analysts, traders, and financial professionals. Usage by individuals under 18 years of age is strictly prohibited. Accounts discovered belonging to minors will be closed and data purged immediately.
12. Financial Non-Advisory Status & Legal Disclaimers
Arkenwell is a software technology project. Arkenwell is not registered with SEBI as an Investment Adviser (RIA) or Research Analyst (RA), nor registered with foreign financial regulatory bodies. Terminal outputs do not constitute investment advice or stock recommendations.
13. Contact Information & Statutory Grievance Redressal
In accordance with Section 13 of the India DPDP Act 2023, you may direct statutory grievances or privacy inquiries to our designated Grievance Officer:
support@arkenwell.coprivacy@arkenwell.co