Privacy Policy
Last updated: September 2026
This Privacy Policy explains how NexaTrade (“we”, “us”) collects, uses, stores and protects your personal information when you use our website and trading platform.
1. Information we collect
- Account data: full name, email, hashed password, phone and country.
- Identity verification (KYC): country-specific identity documents and a live face/liveness capture used to confirm you are a real person.
- Financial data: deposit and withdrawal records, transaction IDs, payment method and account balances.
- Technical data: IP address, device fingerprint, browser/operating-system details and sign-in activity for security and fraud prevention.
2. How we use your information
- To create and secure your account and provide the trading terminal.
- To verify your identity and prevent fraud, multi-accounting and money laundering.
- To process deposits, withdrawals and payments.
- To keep security logs, investigate suspicious activity and comply with legal obligations.
- To provide support and important account notifications.
3. Data storage & security
Passwords are hashed with bcrypt and are never stored in plain text. Sessions use encrypted HTTP-only JWT cookies. Data is held in a managed database with access restricted to authorised administrators. Identity documents are access-controlled and used solely for verification.
4. Data sharing
We do not sell your personal data. Information may be shared only with payment providers required to process transactions, or where required by law or to protect the platform and its users from fraud and abuse.
5. Your rights
- You may request access to, correction of, or deletion of your personal data.
- You may revoke sessions and change your password at any time from the Security page.
- You can contact us for any privacy request using the details on our Contact page.
6. Cookies
We use essential first-party cookies to keep you signed in and to remember basic preferences. Authentication cookies are HTTP-only and SameSite-protected.
7. Retention
We retain account, transaction and security records for as long as required to provide the service and meet legal and anti-fraud obligations, after which they are deleted or anonymised.