Legal

Privacy Policy

Your privacy matters to us. This policy explains what data we collect, how we use it, and the controls you have over your information.

Effective: January 1, 2025 Last updated: January 1, 2025

01Information We Collect

We collect information in the following categories:

Account data: Name, email address, and password hash when you register. If you sign in via Google, we receive your name, email, and profile picture from Google's OAuth service.

Financial data: Your USDT TRC-20 deposit address (generated on the platform), withdrawal addresses you provide, transaction amounts, plan activations, and balance history. We do not hold your private keys.

Referral data: Your referral code usage history, referred users (by anonymised UID), and commissions earned.

Usage data: Pages visited, features used, device type, browser, operating system, IP address, and session timestamps. This data is collected automatically via our analytics infrastructure.

Communications: Messages you send via our support form, email, or Telegram.

02How We Use Your Data

We use your data to:

  • Operate, maintain, and improve the PROFISTRA platform;
  • Process deposits, investments, and withdrawals;
  • Calculate and credit profits and referral commissions;
  • Authenticate your identity and secure your account;
  • Detect, investigate, and prevent fraud, abuse, and security incidents;
  • Comply with legal obligations including AML and sanctions screening;
  • Communicate service updates, security alerts, and support responses;
  • Analyse aggregate usage patterns to improve platform performance.

We do not sell, rent, or trade your personal data to third parties for marketing purposes.

03Data Sharing

We share data only in the following limited circumstances:

Service providers: We use Firebase (Google) for authentication and database services, and may use third-party analytics and monitoring tools. These processors act under data processing agreements that restrict them from using your data for any purpose other than providing services to us.

Blockchain: On-chain transactions (deposits and withdrawals) are publicly visible on the Tron blockchain by nature of the technology. We have no control over this.

Legal requirements: We may disclose your information if required to do so by law, court order, or governmental authority, or to protect the rights, property, or safety of PROFISTRA, its users, or the public.

04Cookies & Tracking

PROFISTRA uses browser localStorage to store your session token, user preferences, and referral code information. We do not use third-party advertising cookies. Our analytics may use first-party cookies to track sessions and usage patterns, which helps us improve the platform. You can clear localStorage and cookies at any time through your browser settings, though this will log you out of your session.

05Data Security

We implement industry-standard technical and organisational measures to protect your data:

  • All data is transmitted over TLS/HTTPS;
  • Authentication is handled by Firebase Authentication using JWT tokens;
  • Passwords are hashed using bcrypt and are never stored in plaintext;
  • Database access is role-controlled with principle-of-least-privilege rules;
  • We conduct regular security reviews of our infrastructure.
No system is 100% secure. We cannot guarantee absolute security of information transmitted over the internet.

06Data Retention

We retain your personal data for as long as your account is active and for a period of 5 years following account closure, to comply with legal, tax, and AML obligations. Transaction records may be retained longer as required by applicable regulations. You may request deletion of non-essential data; however, transaction and compliance records cannot be deleted during the mandatory retention period.

07Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the data we hold about you;
  • Rectification: Request correction of inaccurate or incomplete data;
  • Erasure: Request deletion of your data, subject to legal retention requirements;
  • Portability: Request your data in a structured, machine-readable format;
  • Objection: Object to processing based on legitimate interests.

To exercise any of these rights, contact us at support@profistrafunds.com. We will respond within 30 days.

08Children's Privacy

PROFISTRA is not directed at or intended for use by persons under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided us with personal data, we will delete it promptly. If you believe a minor has registered an account, please contact us immediately.

09Contact & Updates

If you have questions or concerns about this Privacy Policy, please contact our Data Protection team at support@profistrafunds.com or via our Contact page.

We may update this policy from time to time. Material changes will be communicated via the platform dashboard with at least 14 days notice before taking effect. Continued use of the Services constitutes acceptance of any revised policy.