Modern Solutions for Customer Engagement

Highly customizable components for building modern websites and applications that look and feel the way you mean it.

app screen
Last updated: 17 April 2026

Privacy Policy

This policy explains how Alphonce collects, uses, and protects your personal data when you use our platform. We are committed to transparency and compliance with UK data protection law.

1. Who we are

Alphonce is operated by Ochieng & Co, a company registered in the United Kingdom. We are the data controller for the personal data you provide through the Alphonce platform.

  • Trading name: Alphonce
  • Operator:Ochieng & Co
  • Registered in: United Kingdom
  • Contact email: privacy@alphonce.io

If you have questions about how we handle your data, you can contact our Data Protection Officer at the email above.

2. What data we collect

We collect only the data necessary to provide our services. This falls into the following categories:

2.1 Account and identity data

When you register, we collect your name, email address, and password (stored in hashed form). If you join our waitlist, we collect your name, email, and optional company details.

2.2 Financial and portfolio data

When you connect a broker (such as Trading 212, Alpaca, or Interactive Brokers), we receive portfolio holdings, account balances, transaction history, and order execution data through secure API connections. We do not store your broker login credentials — these are handled via OAuth tokens.

2.3 Strategy and bot execution data

If you create, backtest, or deploy trading strategies through ClawBot, we store the strategy parameters, backtest results, live execution logs, and performance metrics. Marketplace sellers must complete identity verification before listing strategies.

2.4 AI research interactions

When you use our AI-powered research engine, we process your natural language queries and the AI-generated responses. We may retain query logs to improve response quality and detect abuse.

2.5 Payment data

Subscription and marketplace purchases are processed by Stripe. We do not store your card details. We retain transaction records, billing addresses, and Compute Unit (CU) usage metrics for accounting and fraud prevention.

2.6 Technical and usage data

We collect IP addresses, browser type, device information, session timestamps, and feature usage patterns. This helps us maintain security, diagnose issues, and improve the platform.

3. How we use your data

We use your personal data for the following purposes:

  • Providing the platform: Authenticating your account, syncing portfolio data, executing strategies, and generating research insights.
  • Processing payments: Billing subscriptions, managing Compute Units, and handling marketplace transactions between buyers and sellers.
  • AI model improvement: Analysing research queries (in anonymised or aggregated form) to improve the accuracy and relevance of our AI-generated outputs.
  • Security and fraud prevention: Detecting unauthorised access, unusual trading patterns, and protecting against financial crime.
  • Legal compliance: Meeting our obligations under financial regulations, tax law, and anti-money laundering requirements.
  • Communication: Sending service updates, security alerts, and (with your consent) marketing about new features.

5. Who we share your data with

We do not sell your personal data. We share it only with trusted service providers who help us operate the platform:

  • Brokerage partners: Trading 212, Alpaca, Interactive Brokers, and others — to execute trades and sync portfolio data via secure APIs.
  • Payment processors: Stripe — to handle billing securely. Stripe operates under its own privacy policy.
  • AI and cloud providers: OpenAI, Anthropic, and similar providers — to power our research engine. Queries are not used to train third-party models where opt-out is available.
  • Infrastructure providers: Supabase (database and auth), Vercel (hosting), Microsoft Azure (compute and verification services).
  • Professional advisers: Accountants, lawyers, and auditors — where required by law or for legitimate business purposes, under strict confidentiality.

All third-party providers are contractually bound to process data only on our instructions and in compliance with UK data protection standards.

6. International data transfers

Some of our service providers are based outside the UK, primarily in the United States and European Economic Area (EEA). When we transfer your data internationally, we ensure appropriate safeguards are in place:

  • UK adequacy decisions: We rely on UK adequacy regulations where the destination country is recognised as providing adequate protection.
  • Standard Contractual Clauses (SCCs): For transfers to the US and other non-adequate countries, we use UK Addendum to the EU Standard Contractual Clauses with our providers.
  • Supplementary measures: We implement additional technical safeguards (encryption at rest and in transit) and contractual controls to protect your data during international transfers.

7. Data retention

We retain your data only for as long as necessary for the purposes outlined above:

  • Account data: Retained for the duration of your account plus 6 years after closure (for tax and regulatory compliance).
  • Financial and portfolio data: Retained for 6 years from the date of the last transaction or sync, in line with UK tax and financial record-keeping requirements.
  • AI research queries: Retained for 12 months, then anonymised or deleted.
  • Bot execution logs: Retained for 3 years for audit and marketplace verification purposes.
  • Marketing data: Retained until you withdraw consent or unsubscribe.
  • Technical logs: Retained for 90 days, then aggregated or deleted.

After the retention period expires, we securely delete or anonymise your data. If you request deletion earlier, we will comply unless a legal obligation requires us to retain the data.

8. Your data protection rights

Under UK data protection law, you have the following rights:

  • Right to access (Article 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Article 16): Request correction of inaccurate or incomplete data.
  • Right to erasure (Article 17): Request deletion of your data in certain circumstances (the "right to be forgotten").
  • Right to restrict processing (Article 18): Request that we limit how we use your data.
  • Right to data portability (Article 20): Receive your data in a structured, machine-readable format, or have it transferred to another controller.
  • Right to object (Article 21): Object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent: Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
  • Right to complain: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have mishandled your data.

To exercise any of these rights, contact us at privacy@alphonce.io. We will respond within one month, or up to three months for complex requests.

9. Cookies and tracking

We use cookies and similar technologies to operate and improve the platform. Under the Privacy and Electronic Communications Regulations (PECR), we require your consent for non-essential cookies.

9.1 Essential cookies

These are necessary for the platform to function — for example, maintaining your session and security tokens. They cannot be disabled.

9.2 Analytics cookies

We use anonymised analytics to understand how users interact with features. These help us improve the platform. We request your consent before enabling these.

9.3 Preference cookies

These remember your settings (such as dark/light mode and dashboard layout preferences) to enhance your experience.

You can manage your cookie preferences at any time through your browser settings or by contacting us. For more details, see our Cookie Policy.

10. Data security

We take the security of your data seriously, particularly given the sensitive financial nature of our platform:

  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
  • Access controls: Role-based access, multi-factor authentication, and regular access audits.
  • API security: Broker connections use OAuth 2.0 with scoped permissions. We never store your broker passwords.
  • Monitoring: Continuous security monitoring, intrusion detection, and automated vulnerability scanning.
  • Incident response: We have a documented breach response plan and will notify you and the ICO within 72 hours if a breach affects your personal data.

Despite our safeguards, no system is completely secure. We encourage you to use strong passwords and enable two-factor authentication on your account.

11. AI and automated decision-making

Alphonce uses artificial intelligence to power research insights and strategy recommendations. We want to be transparent about how this affects you:

  • Research engine: AI-generated insights are for informational purposes only. They do not constitute financial advice. You remain responsible for all investment decisions.
  • Strategy scoring: Automated systems score and rank strategies in our marketplace based on backtest and live performance metrics. These scores are clearly labelled as algorithmic.
  • Bot execution: ClawBot executes trades based on parameters you define. You can pause, modify, or stop any bot at any time. We do not make unsupervised autonomous decisions on your behalf.
  • No profiling: We do not use your personal data to create profiles for purposes that produce legal or similarly significant effects without human oversight.

Under UK GDPR Article 22, you have the right not to be subject to solely automated decisions with significant effects. Our AI features are designed to augment, not replace, your judgment.

12. Children's privacy

Alphonce is not intended for individuals under 18 years of age. We do not knowingly collect data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it.

13. Changes to this policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by email or through the platform at least 30 days before they take effect. The "Last updated" date at the top of this page indicates when the policy was last revised.

14. Contact us

If you have questions, concerns, or requests regarding this privacy policy or our data practices, please contact us:

You also have the right to lodge a complaint with the UK Information Commissioner's Office:

ico.org.uk
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

This privacy policy is governed by the laws of England and Wales. Alphonce is a Tooling Provider under the 2026 EU AI Act (Limited Risk category). Deployment risk remains with the user. This policy does not constitute legal or financial advice.