GRIDer

Privacy Policy

Version 2026-10-03 · Change history

This policy explains how we process your personal data when you visit grider.xyz and its subdomains, buy a GRIDer Pack license, use the installed software or contact us. We apply Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

1. Data controller

  • Controller: Juan Jesús Cobo Gómez (self-employed)
  • Tax ID (NIF): 77343450Q
  • Address: c/ Henry Dunant 2, 1º B, 23009 Jaén (España)
  • Email for any privacy matter: info@grider.xyz
  • Phone: +34 666 379 783

We have not appointed a data protection officer, as we are not required to. For any question about your data, write to the email above.

2. Scope

This policy covers the seller's websites and servers: grider.xyz (including the store, the calculators and the range study), docs.grider.xyz (documentation), get.grider.xyz (installer, license check, orders, withdrawals and complaints), registry.grider.xyz (software images) and scanner.grider.xyz (public data for the range study). It does not cover the third-party services we link to (exchanges, Discord, Telegram, X…), which have their own policies.

  • When: only if you accept the "Tracking cookies" category in the grider.xyz cookie notice. If you do not accept it, the Umami script is not loaded. The documentation website has no analytics.
  • What data: the address of the page you visit, without the part after "?" or "#" (in the calculators that is where amounts and ranges go, so they never reach the analytics); the referring page; the page title; the browser, operating system and device type; the screen size; the browser language; and your approximate location (country and, at most, region and city). Umami does not store your IP address: it uses it on the spot, together with your browser's technical data, to work out that approximate location and a pseudonymous session identifier. It uses no cookies.
  • Do Not Track: if your browser sends the "Do Not Track" signal, your visit is not recorded even if you have accepted.
  • Purpose: to know how many visits the website gets and which pages are used, so we can improve it. We only look at aggregate reports. We do not build profiles, we do not use this data for advertising and we do not measure what you type into forms.
  • Legal basis: your consent (Art. 6(1)(a) GDPR and Art. 22(2) of Spanish Law 34/2002, LSSI). You can withdraw it at any time with the "Cookie preferences" button in the footer of every page, without affecting the lawfulness of the processing before the withdrawal.
  • Controller and processor: the seller is the controller. Umami Software, Inc. (United States), which provides the Umami Cloud service, processes the data on our behalf as processor, on its servers in the United States and the European Union.
  • International transfer: to the United States, based on the standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR) included in Umami's data processing agreement (umami.is/dpa).
  • Retention: up to 6 months, the data retention period of the Umami Cloud plan we use; then the data is deleted.
  • What: the choice you make in the cookie notice (which categories you accept or decline, that you have already chosen and a random identifier of that choice) is stored in three cookies in your browser for 365 days. The notice script does not send it to any server. The details are in the Cookie Policy.
  • Purpose and legal basis: to respect your choice and be able to show whether or not you gave us your consent, as the law requires (Arts. 6(1)(c) and 7(1) GDPR; Art. 22(2) LSSI).
  • Script provider: the notice is the free script from cookieconsent.com, by TermsFeed. Your browser downloads it from the cookieconsent.com servers, which, as with any download, receive your IP address and technical browser data and process them under their own privacy policy.

c) Orders, licenses and invoicing

  • What: the order form data (plan, customer type, name, email and country; if you buy as a business, company name, VAT number and address; and the paying wallet, if you give it); the boxes you tick and the version of the terms you accept, with their date and time; the order code; the blockchain payment details (sending address, network, amount, date and transaction identifier) and the exchange rate applied; the invoices; and communications about the order, including withdrawals and complaints.
  • Purpose: to handle your order and your license, collect payment, issue invoices, deal with withdrawals, guarantee claims and complaints, and meet our legal obligations: tax, accounting, consumer law and, where applicable, international sanctions.
  • Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR).
  • Mandatory data: the required fields of the form are necessary to sell you the license; without them we cannot process the order.
  • Retention: 6 years from the last transaction related to the order, because of commercial and tax obligations; then the data is deleted.
  • Recipients: Oracle (hosting) and Zoho (email), as processors (section 4); and the tax authorities, courts and other authorities where the law requires it.
  • Public blockchain: USDC payments are recorded on a public blockchain, visible to anyone, which nobody can modify or delete. We link your payment to your order; that link is not published.

d) License check

  • What: the installed software periodically sends the license server your license token and a random identifier of your installation. Linked to your license we store its status, its expiry and, for each installation, that identifier, the dates of the first and the last check and the number of checks. We do not store IP addresses or wallets in the database, and the software sends no keys, balances, positions, orders or data about your trading.
  • Why and on what legal basis:
    • to check that your license is in force, count the installations that use it and deliver, in the signed response, the latest version and security notices: this is necessary to perform your contract (Art. 6(1)(b) GDPR);
    • to keep the list of installations of each license in order to detect whether it is used on more machines than purchased (shared licenses): our legitimate interest in preventing unauthorized use of the software (Art. 6(1)(f) GDPR).
  • We do not use this data for product statistics or for any other purpose.
  • You have the right to object to the shared-license check: see section 7.
  • Retention: each installation leaves the list 180 days after its last check. License data is kept while the license is in force and for up to 12 months after it expires, so that we can reactivate it if you renew and deal with claims; then it is deleted. If there is an open dispute, we block it until it is resolved.
  • Recipient: Oracle (hosting), as processor.
  • Technical logs: like any web server, the one that answers these checks records the IP address and time of each request. Those logs are used only for security (section 3.f) and are deleted after 14 days at most.

e) Downloads of the installer, the image and updates

  • What: when your server or your Mac downloads the installer, the configuration or the software image (get.grider.xyz and registry.grider.xyz), we count how many times your install URL has been used (it allows 5 downloads in 72 hours) and we store the date and time of the first download, which is when, if you are a consumer, the right of withdrawal is lost (see the Purchase Terms). The server also keeps technical logs (IP address, time and resource downloaded), deleted after 14 days at most.
  • Purpose and legal basis: to deliver the software and its updates and to be able to prove when performance of the contract began (performance of the contract, Art. 6(1)(b) GDPR) and to protect the servers (legitimate interest, Art. 6(1)(f) GDPR).
  • Retention: the date of the first download is kept with the order (section 3.c).
  • Third parties contacted by the installer: the installer downloads third-party components from their official sources (for example Docker, Caddy or PostgreSQL and, on a Mac, Homebrew and Colima) and uses public domain-name services (sslip.io and nip.io) to give your installation an HTTPS address. Those third parties receive your machine's IP address and process it under their own policies.

f) Server technical logs

  • What: the servers of grider.xyz, docs.grider.xyz, get.grider.xyz, registry.grider.xyz and scanner.grider.xyz (which your browser asks for the range-study data) record, for each request, the IP address, date and time, the address requested, the result, the referring page and technical browser data. The IP is also used on the spot to rate-limit requests.
  • Purpose and legal basis: security only —detecting abuse and attacks, diagnosing errors and rate-limiting—, based on our legitimate interest in protecting our servers and their data (Art. 6(1)(f) and Recital 49 GDPR). You can object (section 7).
  • Retention: deleted after 14 days at most.
  • Recipients: Oracle (hosting), as processor; and the competent authorities, in a security incident.

g) Support, contact, complaints and security reports

  • Email: if you write to us, we process your name, your email and whatever you tell us in order to reply. Legal basis: performance of the contract or your request (Art. 6(1)(b) GDPR) or our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). Our email is handled by Zoho Mail, in its European Union data center, as processor.
  • Complaints: if you complain through the complaint form, by email, by phone or by post, we process your details and your complaint to give you a reference code, a receipt and a reply, as the law requires (Art. 6(1)(c) GDPR; Art. 21 of the Spanish consolidated Consumer Protection Act) and, if it concerns an order, to perform the contract (Art. 6(1)(b) GDPR).
  • Retention: messages, withdrawals and complaints that concern an order are kept with the order (6 years); other enquiries and complaints are deleted 24 months after they are closed.
  • Discord and Telegram: these are third-party platforms with their own privacy policies, which process your data as independent controllers. We see your username and the messages you send us. Do not share your keys, your seed phrase, your install URL or your token there.
  • Security reports: if you report a vulnerability to us, we process your details to handle the report under the security policy and to meet our notification obligations (Art. 6(1)(c) GDPR). If you ask us to, we credit you in the public notice.

h) WalletConnect (Reown) in the installed application

The installed application lets you connect mobile wallets through WalletConnect, a Reown service. Installations carry no identifier (Project ID) of the seller: if you want that feature, you configure your own Project ID in your installation (Admin → Config → "WalletConnect Project ID (your own)") and the relationship is directly between you and Reown. The seller receives no data from those connections.

i) The software you install

GRIDer Pack runs on your own machine and keeps your keys, credentials, orders, positions and history there. The seller does not access that data. Your installation talks directly to the exchanges, the blockchain networks and, if you configure them, your Telegram bot and WalletConnect. If you process other people's personal data with the software, you are the controller of that processing.

4. Recipients

We do not sell your data or disclose it to third parties for their own purposes. The following may access it, only as far as necessary:

  • Oracle (Oracle Cloud Infrastructure): hosts our servers in its Madrid (Spain) region, as processor;
  • Zoho (Zoho Mail): our email, in its European Union data center, as processor;
  • Umami Software, Inc. (Umami Cloud): the website analytics, as processor, only if you accept it (section 3.a);
  • cookieconsent.com (TermsFeed): receives your IP when your browser downloads the cookie notice script (section 3.b);
  • Discord and Telegram, if you contact us through those platforms, as independent controllers;
  • the tax authorities, courts and other authorities, where the law requires it; and, in a security incident, the competent cybersecurity and data protection authorities, as far as the notification requires.

5. International transfers

Our servers are in Oracle Cloud Infrastructure's Madrid (Spain) region and our email is in Zoho's European Union data center: neither hosting nor email involves transferring your data outside the European Economic Area. Their data processing agreements only allow access from outside the EEA —for example, by their technical support— with the safeguards the GDPR requires.

The only international transfer we make is for analytics, and only if you accept it: Umami Software, Inc. processes that data on its servers in the United States and the European Union, based on the standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR), included in its data processing agreement (umami.is/dpa). You can ask us for more information on these safeguards.

cookieconsent.com, Discord and Telegram process your data as independent controllers, under their own policies.

6. Retention periods (summary)

  • Analytics, only if you accept it: up to 6 months, at Umami.
  • Cookies that store your choice in the cookie notice: 365 days, in your browser.
  • Server technical logs (websites, license check and downloads): 14 days at most.
  • Each installation on its license's list: 180 days from its last check.
  • License-check data: while the license is in force and for up to 12 months after it expires.
  • Orders, invoices, withdrawals and complaints about an order: 6 years from the last transaction.
  • Other enquiries and complaints: 24 months after they are closed.

After those periods the data is deleted. If there is an open dispute, we block it until it is resolved and only make it available to courts and authorities (Art. 32 LOPDGDD).

7. Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to info@grider.xyz or by post to c/ Henry Dunant 2, 1º B, 23009 Jaén (España), stating which right you are exercising. If we have reasonable doubts about your identity, we may ask for additional information to confirm it. We will reply within one month, which may be extended by two further months in complex cases, and we will tell you within the first month if we need the extension.

Right to object. You can object at any time, on grounds relating to your particular situation, to the processing based on our legitimate interest: the server technical logs (section 3.f) and the shared-license check (section 3.d). Write to info@grider.xyz. We will stop processing that data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or we need it for the establishment, exercise or defence of legal claims (Art. 21 GDPR).

Consent. You can withdraw your consent to the analytics at any time with the "Cookie preferences" button in the footer of every page, without affecting the lawfulness of the processing before the withdrawal.

Some data cannot be erased: data the law requires us to keep (for example, invoices) and data recorded on the blockchain, which we do not control.

If you think we have not handled your data properly, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es; C/ Jorge Juan, 6, 28001 Madrid) or with the supervisory authority of your country.

8. Automated decisions

We do not profile. The order form applies objective rules (country and customer type) to determine whether we can sell you a license; if you disagree with the result, write to us and a person will review it.

9. Minors

The website and the store are not aimed at people under 18 and we do not knowingly process their data.

10. Security

We apply appropriate technical and organizational measures: encrypted connections (HTTPS), restricted access to the servers, data minimization and short retention periods for logs. We keep an internal record of any incident affecting personal data and, if it poses a risk, we notify the Spanish Data Protection Agency without undue delay and, where possible, within 72 hours; if the risk is high, we also tell the people affected.

11. Changes to this policy

If we change this policy, we will publish the new version with its date and, if the change affects the data of your order or license, we will tell you by email.

Change history

  • 2026-10-03 — New policy (3 October 2026): identifies the controller; website analytics (Umami Cloud) now runs only with your consent, through the cookie notice; names the processors (Oracle, Zoho and Umami) and where they process the data; separates the legal bases of the license check and highlights the right to object; and sets the retention periods. Replaces the version of 20 July 2026.
GRIDer

Self-hosted grid trading software. Your environment, your control.

GRIDer is software you install and operate yourself, on your own account and with your own funds. It is not an investment service, it does not manage anyone else’s money, and nothing on this site is investment advice or a recommendation to trade. Trading crypto derivatives involves leverage and a high risk of loss.

Exchange names and logos that appear on this site, such as Hyperliquid, Lighter, Pacifica, Extended, RISEx or Aster, are trademarks of their respective owners. GRIDer is independent software, not affiliated with, sponsored or endorsed by any of them; they are used only to indicate compatibility.

© 2026 GRIDer. Decentralized trading.

grider.xyz