Privacy Policy
ONEVAR Privacy Policy
ONEVAR (onevar.io)
Last updated: September 13, 2026
Developer Contact: support@onevar.io
ONEVAR Quantitative Risk Management operates the ONEVAR Desk (the "Service"). This Privacy Policy explains what personal data ONEVAR collects when you sign in with Google, how that data is used and protected, and the rights you have over it.
1. Overview and Data Controller
The data controller for the Service is ONEVAR (onevar.io). The Service is quantitative risk-management and algorithmic execution software: it is not a broker, not a custodian, and not a source of financial advice. This policy applies to the website onevar.io and to the authenticated ONEVAR Desk application.
- Data controller and developer contact: support@onevar.io.
- This policy covers personal data processed through Google Sign-In, the desk application, and the billing flow.
- By creating an account you acknowledge the practices described here.
2. Data collected via Google OAuth
ONEVAR uses Google Sign-In for authentication. When you sign in, ONEVAR receives only the basic profile data that Google returns through the standard OpenID Connect scopes (openid, profile, email).
- Email address
- Full name (display name)
- Profile picture
- Unique Google user identifier
ONEVAR does not request, receive, or process any sensitive data, Google Drive files, Google Contacts, or Gmail messages.
3. Other data we collect
Beyond the Google profile, the Service processes only the data required to operate the desk:
- Account and session data: sign-in timestamps, session tokens, and audit events required for security.
- Configuration data: the risk parameters, watchlists, and portfolio metrics you set in the desk.
- Trading records: orders and executions performed through your own broker account, retained for your history and the audit trail.
- Billing data: subscription status and identifiers handled by Stripe. ONEVAR never sees or stores payment card numbers.
4. Purpose of processing
Your Google profile data is used solely to enable sign-in, maintain a secure working session, and associate the analytical and portfolio risk metrics you configure with your authenticated account.
- Account identity: recognise you across sessions and protect the desk against unauthorised access.
- Secure session: maintain an authenticated, encrypted session while you use the Service.
- Portfolio association: link the analytical and risk metrics you configure to your authenticated account.
- Service operation and abuse prevention: keep the desk reliable and detect unauthorised or fraudulent use.
5. Compliance with Google Limited Use requirements
The use and transfer to other apps of information received from Google APIs by ONEVAR will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- ONEVAR does not sell personal data obtained through Google to third parties.
- ONEVAR does not use Google-obtained personal data for advertising or marketing purposes.
- ONEVAR does not transfer Google-obtained personal data to external brokers.
6. Data sharing and sub-processors
ONEVAR does not sell, rent, or trade personal data. Data is processed only by the providers required to run the Service:
- Hosting and backend infrastructure (Lovable Cloud) — stores account, configuration, and audit data.
- Stripe — processes billing and subscription status; card details never reach ONEVAR servers.
- Alpaca — order execution happens only on your own Alpaca account, using credentials you provide; ONEVAR receives no personal data from Google that is transferred to Alpaca.
7. Cookies and tracking
The Service uses only functional storage: your authenticated session and your language preference. No advertising trackers, analytics beacons, or third-party marketing cookies are installed.
- Session token — keeps you signed in securely.
- Language preference — remembers EN or IT between visits.
8. Data retention and deletion
You may revoke ONEVAR's access to your Google data at any time from the permissions panel of your Google account.
- To revoke access, open your Google Account permissions page and remove ONEVAR.
- To request the definitive deletion of your profile and any associated data from ONEVAR's databases, email support@onevar.io: your request will be fulfilled within 30 days.
- Audit logs of trading activity may be retained longer to comply with legal obligations.
9. Security
Access to your data is restricted to authenticated administrators and protected by Row-Level Security on the backend. All traffic is encrypted in transit. If you connect an Alpaca account, your API credentials are stored server-side and encrypted; ONEVAR is non-custodial and never holds, moves, or withdraws your funds. We do not store payment card numbers on ONEVAR servers; card data is handled by our payment provider.
10. Children's privacy
The Service is not directed at individuals under the age of 18, and ONEVAR does not knowingly collect personal data from minors. If you believe a minor has created an account, contact us and the data will be deleted.
11. Changes to this policy
If this policy changes, the updated version will be published on this page with a new revision date. Material changes will be announced to authenticated users before they take effect.
12. Contact
For any question about your data, this policy, or a deletion request, contact the developer responsible for data handling.
Developer Contact: support@onevar.io