Legal

Privacy Policy

Effective date: 25 April 2026 · Version 1.0

This policy explains how Alvest collects, uses, stores and shares your personal data. **Alvest is operated from Türkiye by Hazar Sönmez, who is also the data controller for the purposes of this policy.** Payments for paid subscriptions are processed by our online reseller Paddle.com Market Limited (Merchant of Record). This notice is drafted in accordance with the EU GDPR, the UK GDPR, the Turkish KVKK (Law No. 6698), the Data Protection Act 2018 and the ePrivacy Directive.

Section 01

Data Controller and Scope

Data controller: Hazar Sönmez (Türkiye).

Activity: multi-asset portfolio tracking and analytics (SaaS) delivered at alvest.app. Paid subscriptions are sold by Paddle.com Market Limited acting as Merchant of Record.

Infrastructure providers (data processors):

  • Hosting: Vercel Inc. (CDN + serverless functions)
  • Database + Auth: Supabase Inc. (EU region - Frankfurt)
  • Email delivery: Resend.com (transactional + notification email)
  • Payment: Paddle.com Market Limited (PCI DSS Level 1)
  • Push notifications: Web Push standard (browser-based, no third party)

Analytics: A cookieless, anonymous EU analytics provider (Plausible), loaded only if you grant "Statistics" cookie consent. No third-party advertising or tracking pixels are ever loaded.

Contact:

  • General: info@alvest.app
  • Customer support: destek@alvest.app
  • Privacy requests (KVKK/GDPR): privacy@alvest.app
  • Response time: 2-10 business days

This policy applies to alvest.app, app.alvest.app, the mobile web version and any notifications we send by e-mail.

Section 02

Categories of Personal Data We Process

We process only the minimum data required to deliver the service. We do not sell data, we do not serve ads.

Identity and contact data: E-mail address; profile name and avatar if you sign in with Google. Required to identify your account and manage sessions.

Portfolio data: Transactions, positions, asset amounts, trade dates, alerts, goals and tags that you add. This is your own record and is not investment advice. Stored on the server encrypted at rest with AES-256.

API credentials (optional): Read-only API keys for exchanges such as Binance, BTCTurk, Paribu. These keys are stored only in your browser, encrypted and bound to your user ID. They are never transmitted to Alvest servers and are not visible to Alvest.

Payment data: For Pro and Premium subscriptions we hold only plan type, billing period and next-renewal date. Card numbers, CVV, IBAN and similar sensitive payment data are never processed by Alvest. Payments are processed by Paddle.com Market Ltd. (Merchant of Record) to PCI-DSS Level 1 standard.

Technical and usage data: IP address (short-term, security only), browser type, device type, OS, service events. Aggregate analytics are collected via a cookieless, privacy-focused EU analytics provider - no cookies are placed and IPs are hashed and discarded.

Support correspondence: E-mails you send to destek@ or privacy@, processed to resolve your request.

We do not process special category data (health, biometrics, religion, ethnic origin, union membership, political opinion or criminal records).

Section 03

Purposes of Processing

We process your personal data for the following purposes:

  • Providing the service, creating your account, session management
  • Calculating and displaying your portfolio
  • Sending price alerts, weekly summary reports and security notices by e-mail
  • Managing subscriptions and billing (Free, Pro, Premium)
  • Preventing fraud, abuse, bots and automated attacks
  • Measuring quality of service and making product improvements
  • Complying with legal obligations
  • Handling your requests and complaints
Section 04

Legal Bases

Under Article 6 GDPR our legal bases are:

  • Performance of a contract (Art. 6(1)(b)) - account, portfolio, subscription.
  • Legitimate interests (Art. 6(1)(f)) - security, fraud prevention, product improvement. Our assessments are available on request.
  • Legal obligation (Art. 6(1)(c)) - tax, consumer law, anti-money-laundering.
  • Consent (Art. 6(1)(a)) - marketing e-mails, optional features and statistics/analytics cookies.

Where processing relies on consent, you may withdraw it at any time via your settings without affecting the lawfulness of prior processing.

Section 05

Recipients and Sub-processors

We do not sell, rent or advertise with your data. We share personal data only with the following categories of sub-processors to operate the service:

Database and authentication infrastructure (EU region) - hosts account data, portfolio data and sessions. SOC 2 Type 2 and ISO 27001 certified provider.

Paddle.com Market Ltd. (Ireland / UK) - Merchant of Record: payments, invoicing, VAT handling. PCI-DSS Level 1 certified. Your invoice references "Paddle".

Transactional e-mail provider - delivery of alerts, reports and verification e-mails. DPA and EU SCCs in place.

Cloud hosting and CDN provider - serves the application globally. SCCs in place, SOC 2 Type 2 certified.

AI model provider - when you invoke the Alvest AI analysis feature, only an anonymised portfolio summary (no identifiers) is sent. Zero-retention endpoint; data is not used to train the model.

Cookieless analytics provider (EU) - collects aggregated page views anonymously; no personal data is stored.

Current, complete sub-processor list (legal name, location and DPA links): [/subprocessors](/subprocessors)

Disclosures to competent authorities are made only where legally required, and where permitted we notify you in advance.

Section 06

International Transfers

Some sub-processors are located outside the EEA/UK. Transfers rely on one of the following safeguards under GDPR Chapter V:

  • Adequacy decisions by the European Commission or the UK Government
  • EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum
  • Additional technical and organisational safeguards (encryption, access control, audit logging)
  • Where necessary, your explicit consent

A list of current sub-processors and transfer mechanisms is available on request.

Section 07

API Keys and Zero-Trust Model

Exchange API keys are the most sensitive surface we touch, so our model is deliberately zero-trust:

  • Keys are stored only in your browser; they are never sent to our servers
  • Storage uses symmetric encryption with a key derived from your user identity
  • Only read-only permissions are supported; trade and withdrawal permissions are rejected by the client
  • Exchange API calls originate from your browser and data is not persisted server-side
  • When you remove a key, the encrypted copy in your browser is wiped immediately
  • We recommend IP restrictions, 2FA and read-only scope on the exchange side at all times

Alvest cannot be held liable for unauthorised use of API keys obtained outside of our control; if an exchange reports a leak we will notify you promptly.

Section 08

Cookies and Local Storage

We do not use advertising or third-party marketing cookies.

Strictly necessary cookies: Session ID, CSRF token, theme and language preference. Required for the service to function; exempt from consent under the ePrivacy Directive.

localStorage: UI preferences and transient drafts, stored only on your device.

Analytics: our cookieless analytics provider (Plausible) loads only if you enable the "Statistics" cookie category, and collects only aggregated data.

See our Cookie Policy for the full register.

Section 09

Retention Periods

Data is retained only as long as necessary for the purposes of processing:

  • Account data: While the account is active, plus a 30-day grace window after deletion.
  • Portfolio data: Lifetime of the account; permanently deleted within 30 days of account deletion.
  • API keys: Only in your browser; removed as soon as you delete them.
  • Payment records: Held by Paddle for up to 10 years under applicable tax law.
  • Support correspondence: 24 months after the ticket is closed.
  • Security logs: 90 days, extended to 12 months in the event of a material incident.
  • Backups: Encrypted and rotated on a rolling basis within 35 days.
Section 10

Your Rights

Under GDPR Articles 15 to 22 and the UK GDPR you have the following rights:

  • Access: confirmation of whether we process your data and a copy of it
  • Rectification of inaccurate or incomplete data
  • Erasure (right to be forgotten)
  • Restriction of processing
  • Data portability in a machine-readable format (JSON)
  • Objection, including to processing based on legitimate interests
  • Not to be subject to solely automated decisions with legal or similarly significant effects
  • Withdraw consent at any time where processing is based on consent

Requests should be sent to privacy@alvest.app. We respond within 30 days free of charge after verifying your identity. We may charge a reasonable fee or refuse requests that are manifestly unfounded or excessive.

Section 11

Automated Decisions and Profiling

Alvest does not carry out automated decision-making that produces legal effects or similarly significant effects on users. The Alvest AI analysis feature is informational only; it is not investment advice and does not place trades.

Section 12

Children's Privacy

The service is not directed to individuals under 18. We close accounts we learn to be under the applicable age and delete associated data. Parents or guardians can contact privacy@alvest.app.

Section 13

Personal Data Breach Notification

In the event of a personal data breach we notify the competent supervisory authority without undue delay and within 72 hours, and we will notify affected users directly where the breach is likely to result in a high risk to their rights and freedoms, as required by Articles 33 and 34 GDPR.

Section 14

Security Measures

Our technical and organisational measures include:

  • TLS 1.2+ encryption for all connections
  • AES-256 full-disk encryption at the database layer
  • Row-Level Security (RLS) policies for tenant isolation
  • Least-privilege access with multi-factor authentication for administrators
  • API keys never reach our servers
  • Automated dependency vulnerability scanning
  • Regular penetration testing and independent audits
  • Confidentiality obligations for all personnel

Responsible disclosure: privacy@alvest.app, subject line "Security Disclosure". We aim to acknowledge within 24 hours.

Section 15

Changes to This Policy

We may update this policy for legal, technical or operational reasons. Material changes are announced at least 15 days before they take effect, by e-mail and in-app notice. The current version is always published on this page.

Section 16

Contact, Complaints and Supervisory Authorities

Contact:

  • Privacy requests (KVKK/GDPR): privacy@alvest.app
  • General: info@alvest.app
  • Customer support: destek@alvest.app
  • Response time: 2-10 business days (up to 30 days statutory limit for formal GDPR / UK GDPR requests)

Supervisory authorities:

  • EU/EEA: the Data Protection Authority of your member state
  • United Kingdom: Information Commissioner's Office (ICO)
  • Türkiye: Kişisel Verileri Koruma Kurumu (KVKK)

For matters specific to payment data, the Merchant of Record Paddle.com Market Limited is responsible - paddle.net/contact

---

Legal information: Data controller is Hazar Sönmez (Türkiye). Alvest is operated from Türkiye.

Contact Us
Response2 business days (up to 30 days for formal requests)