Privacy Policy

Last updated: May 13, 2026

1. Information We Collect

When you use OilSignal we collect:

  • Account information — name, email address, and password (encrypted)
  • Contact information — phone number if you enable SMS alerts
  • Payment information — processed by Stripe. We never store card numbers.
  • Brokerage credentials — IBKR account ID and gateway URL for Auto tier users
  • Usage data — signals viewed, alerts received, positions logged
  • Device data — browser type, IP address, and timezone for security purposes

2. How We Use Your Information

  • To provide and improve the OilSignal service
  • To send you signal alerts via SMS, email, and push notification
  • To process subscription payments through Stripe
  • To execute automated trades on your behalf (Auto tier only, with your explicit consent)
  • To send transactional emails such as account confirmation and password reset
  • To detect and prevent fraud or unauthorized access

We do not sell your personal information to third parties. Ever.

3. Third-Party Services

OilSignal uses the following third-party services to operate:

  • Supabase — database and authentication (supabase.com)
  • Stripe — payment processing (stripe.com)
  • Twilio — SMS notifications (twilio.com)
  • Resend — email delivery (resend.com)
  • Cloudflare — hosting and CDN (cloudflare.com)
  • Interactive Brokers — trade execution for Auto tier (ibkr.com)

Each service has its own privacy policy governing their use of your data.

4. Data Security

We take security seriously. Your password is encrypted using industry-standard bcrypt hashing. All data is transmitted over HTTPS. Brokerage credentials are stored encrypted and only used for trade execution. We perform regular security reviews and follow Supabase row-level security policies to ensure only you can access your data.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we delete your personal data within 30 days. Signal history and anonymized usage data may be retained for service improvement purposes.

6. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your account and data
  • Export your data in a portable format
  • Opt out of non-essential communications

To exercise any of these rights, contact us at [email protected]

7. Cookies

OilSignal uses essential cookies for authentication and session management only. We do not use tracking, advertising, or analytics cookies.

8. Canadian Privacy Law

OilSignal operates from British Columbia, Canada and complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) and BC's Personal Information Protection Act (PIPA).

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on the dashboard.

10. Contact

For privacy questions or data requests, contact us at [email protected]