Power Bots
LEGAL/PRIVACY NOTICE
Back to catalog
PRIVACY & SECURITY

Privacy Notice

Effective date: August 21, 2026 · Version 1.0
Credential boundary: Power Bots is designed to use Alpaca OAuth. Do not send Power Bots your Alpaca password, one-time code, raw API key, withdrawal credential, or wallet seed phrase.

1. Scope

This Notice explains how Power Bots collects, uses, discloses, retains, and protects personal information when you use its website, account workspace, software, strategy materials, payment links, broker connection, and related services (the “Service”). Alpaca, Google, payment processors, hosting providers, and other third parties publish their own notices for information they process independently.

2. Information collected

  • Account information: name, email address, profile image, authentication identifier, and sign-in timestamps provided through Google and Firebase Authentication.
  • Service information: selected product, access state, configuration, support correspondence, consent records, and activity or security logs.
  • Technical information: browser and device details, IP address, approximate region inferred from IP, requested pages, timestamps, diagnostics, and security events.
  • Payment information: product, subscription status, transaction reference, billing status, and limited customer information returned by the payment provider. Power Bots does not intend to receive or store full payment-card numbers.
  • Broker connection information: Alpaca account identifier, last four account-number characters, environment, account status, authorized scope, encrypted OAuth access token, connection time, and instructions or responses needed to provide an enabled feature.
  • Trading-service information: account state, orders, positions, fills, strategy events, limits, and audit records required to operate, secure, support, and reconcile an activated runtime.

3. How information is used

Power Bots uses information to authenticate users; present evidence and purchased access; establish and maintain requested broker connections; provision and operate authorized paper or approved live features; enforce risk and access controls; provide support; reconcile service activity; detect misuse; investigate incidents; improve reliability; process billing; maintain required records; and comply with law.

Broker information is not used to initiate withdrawals, cash transfers, or changes in beneficial ownership.

4. OAuth and broker credentials

When you choose to connect Alpaca, Power Bots redirects you to Alpaca. You authenticate and authorize the connection on Alpaca’s site. Alpaca then returns a temporary authorization code that Power Bots exchanges server-side for an OAuth token. The client secret and token exchange are never exposed in the browser.

OAuth tokens are encrypted before storage, separated by authenticated user identifier, excluded from browser storage and application logs, and returned only to systems that need them to provide the authorized service. The account workspace displays connection status but never displays the token.

5. Disclosure and service providers

Information may be disclosed to providers that support authentication, hosting, databases, payments, customer support, monitoring, security, and broker connectivity; to Alpaca when you direct Power Bots to connect or transmit an authorized instruction; to professional advisers; when required by valid legal process; or as part of a business transaction subject to appropriate safeguards.

Service providers may process information only for contracted or otherwise disclosed purposes. Power Bots does not sell broker credentials and does not permit advertising networks to use broker-account information or authorization tokens.

6. Current core providers

  • Google Firebase: account authentication and authenticated user identifiers.
  • Vercel: website and server-side application hosting.
  • Alpaca: brokerage authentication, authorization, account information, and order connectivity.
  • Configured payment provider: hosted checkout and payment status. The provider’s identity and terms appear before payment.

7. Retention and deletion

Personal information is retained only as long as reasonably necessary to provide the Service, maintain security and audit history, comply with legal or accounting duties, resolve disputes, and enforce agreements. Broker authorization records are deleted or rendered unusable after disconnect, subject to limited security, legal, or audit retention. Disconnecting Power Bots does not erase records Alpaca maintains independently.

8. Your choices and rights

You may sign out, disconnect a broker connection, revoke the Power Bots application through Alpaca, cancel paid access as described at checkout, and request access, correction, or deletion of applicable personal information. Depending on your location, you may have additional rights to know, correct, delete, restrict, object, or receive a portable copy. Identity verification may be required before a request is completed.

9. Security

Power Bots uses controls designed for the sensitivity of the information, including encrypted transport, encrypted OAuth token storage, anti-forgery and replay protection, server-side identity verification, access controls, scoped credentials, audit logging, and separation of customer connections. Security safeguards are reviewed as the Service changes. No system can guarantee absolute security.

10. Security incidents

Power Bots investigates suspected unauthorized access and will provide notices to affected users, regulators, or others when required. If you suspect unauthorized brokerage activity, immediately contact Alpaca, revoke the Power Bots authorization through Alpaca, disconnect the Service, and secure your Power Bots and Google accounts.

11. International use and children

The Service is operated from the United States and information may be processed in the United States and other locations used by service providers. The Service is not directed to anyone under 18, and Power Bots does not knowingly collect children’s personal information.

12. Changes

This Notice may change when the Service, providers, or legal obligations change. The updated version will display a new effective date. Additional notice or consent will be provided when required.

13. Contact and operator information

Production operator name, mailing address, support address, and privacy-request channel must be inserted here and matched to the Alpaca application record before paid public access opens.

Power Bots
Pre-launch software service
Privacy and security contact: production details pending final operator configuration
POWER BOTS
Broker authorization is revocable
CatalogTerms