1. Who we are
Sky Ridge Capital LLC operates SignalAudit and is responsible for the personal information described in this policy. This policy applies to our website, authenticated workspace, subscriptions, support, and webhook receiver.
2. Information we collect
Account and profile information
When you use Sign in with ChatGPT, we receive your authenticated account identifier, email address, and an optional display name from OpenAI. When you use email sign-in, Supabase verifies the one-time code sent to your email address. SignalAudit stores an internal account identifier, linked sign-in method, email address, display name, and secure session record. We also collect profile choices such as trading experience, account-size range, primary instrument, preferred session, risk settings, and workspace preferences.
Trading-process information
We store information you enter into SignalAudit, including session and pre-market plans, risk limits, key levels, event windows, playbooks, checklist criteria, setup names, prop-firm rule settings, trade outcomes, R-multiples, profit or loss figures, process scores, behavior goals, and review notes. If you import a CSV trade export, we also store the trade fields you choose to import, such as instrument, date and time, direction, quantity, entry and exit prices, profit or loss, setup, and notes. Evaluation protection checks store the proposed contract, quantity, entry, stop, estimated risk, rule-check result, and the decision you record after reviewing it. Closed-loop journal records may include links between protection checks and trades, execution scores, plan adherence, emotional states, behavior tags, trade lessons, and daily debrief responses.
Webhook and technical information
If you use the signal receiver, we process webhook payloads and related details such as ticker, action, strategy, status, timestamp, payload hash, source, and delivery latency. We also process security and diagnostic information such as authentication or session cookies, request timing, error details, and rate-limit events.
Billing information
Stripe processes your payment-card details. We receive limited billing information such as Stripe customer and subscription identifiers, subscription status, renewal date, and payment event status. We do not store your full payment-card number.
3. How we use information
- provide, personalize, and maintain your private workspace;
- calculate position-size and risk guardrails, process scores, history, setup analytics, and prop-rule progress;
- receive and display authorized webhook events;
- authenticate users, manage invitations, subscriptions, and access;
- secure, troubleshoot, and improve SignalAudit;
- respond to support, privacy, and billing requests; and
- comply with law, enforce our terms, and protect users and the service.
4. How we disclose information
We disclose information only as reasonably needed to:
- service providers that host, authenticate, bill, secure, or support SignalAudit, including Stripe, OpenAI, and Supabase;
- professional advisers, regulators, law enforcement, or other parties when required by law or necessary to protect rights and safety;
- a successor in a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate safeguards; or
- another party when you direct us or give consent.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and SignalAudit does not currently use third-party advertising trackers.
5. Authentication and payments
Authentication is available through OpenAI’s Sign in with ChatGPT or a passwordless email code provided by Supabase, and payments are processed by Stripe. Information those providers collect directly is governed by their privacy notices. Review the OpenAI Privacy Policy, Supabase Privacy Policy, and Stripe Privacy Policy for more information.
6. Retention
Signal webhook receipts are generally retained for 30 days. We retain account, journal, session, profile, playbook, imported-trade, pre-market, prop-rule, protection-check, trade-review, and daily-debrief information while your account is active and for a reasonable period afterward to provide the service, maintain security, resolve disputes, and meet legal obligations. Billing and transaction records may be kept longer where required for accounting, tax, fraud-prevention, or legal purposes. Retention may also be extended for backups, disputes, or legal holds.
7. Security
We use reasonable technical and organizational safeguards designed to protect information, including account-scoped access, protected webhook endpoints, request validation, and rate-limiting. No online service can guarantee absolute security. Do not place payment-card details, passwords, brokerage credentials, API keys, account numbers, or other unnecessary secrets in journal entries, webhook payloads, or CSV imports. Import only the trade fields needed to use the service.
8. Your choices and requests
You may update many profile and session details in the product. The Account & Billing page lets you download a copy of your SignalAudit data and, after any subscription has ended, permanently delete your account data. You may also request access, correction, or deletion of personal information, or ask a privacy question, by emailing hometownbuyerclub@outlook.com. We may need to verify your identity and may retain information where the law permits or requires it. Canceling a subscription stops future renewals but does not by itself delete your account.
9. Children and location
SignalAudit is not intended for anyone under 18, and we do not knowingly collect personal information from children. SignalAudit is operated in the United States, and information may be processed and stored in the United States.
10. Changes and contact
We may update this policy as the service changes. We will post the current version here, update the effective date, and provide additional notice when required. Contact Sky Ridge Capital LLC through the beta support inbox at hometownbuyerclub@outlook.com.