OGuard

Privacy Policy

Version 3 — effective 31 July 2026

This Policy sets out exactly what data OGuard holds about you, who receives it, and how long we keep it. Two clauses matter more than the rest: clause 3 explains that we do not verify anyone's identity, and clause 8 explains that your trading history is deleted after 60 days while most other records currently have no deletion schedule at all.

1.Who we are and what this covers

This Privacy Policy explains what personal data OGuard Financial Services Corporation (“OGuard”, “we”, “us”), the operator of the OGuard platform, collects when you use it, why we collect it, who we share it with, and what you can do about it. We are the controller of that data.

To reach the controller about anything in this Policy, use the contact address below. It is the address every data request, objection and complaint should go to.

It covers the website at oguard.io, the trading terminal, and the support inbox. Where these Terms and this Policy differ on a data question, this Policy governs. Contact us about anything in it at support@oguard.io.

2.What we collect

2.1 What you give us

Registration details
Your email address, full name, phone number, date of birth, and a referral code if you enter one. These five fields, plus the referral code, are everything the registration form asks for.
Account credentials
A hash of your password — never the password itself. If you enable an authenticator app, we store its secret and your recovery codes encrypted. If you sign in with Google, we store the identifier Google gives us for your account instead of a password.
Withdrawal details
The TRON wallet addresses you give us to withdraw to, and any label you save against them.
Support messages
Everything you write to us through the in-app support inbox or by email, and our replies.
Your acceptance of these documents
Which version of the Terms of Service and Privacy Policy you accepted, and when.

2.2 What we record as you use the platform

Sessions
Each time you sign in we record the sign-in and sign-out time, the IP address you connected from, and your browser’s user-agent string (which identifies your browser, its version, and your operating system). This is what powers the device list in your security settings.
Activity timestamps
When you were last active, so we can show session status and expire idle sessions.
Trading records
Your orders, executed trades, positions, realised profit and loss, and the fees charged on each execution.
Money movements
Deposit and withdrawal requests and their status, the deposit address generated for your account, and the on-chain transaction identifiers of transfers to and from it.
Earn records
Your locked positions, their rate and term, and the schedule and status of each payment.
Email records
A log of the transactional emails we sent you — the type, subject, destination address, and whether delivery succeeded.
Administrative actions
An append-only audit record of actions our staff take on an account, including who acted, what they did, and the IP address they acted from.

2.3 What we do not collect

No tracking, no advertising

OGuard runs no third-party analytics, advertising, session-replay, heat-mapping or A/B-testing service. We do not build an advertising profile of you, we do not sell or rent your personal data to anyone, and we do not use it for automated decision-making that produces legal effects for you.

We also do not collect identity documents — see clause 3 — and we do not ask for your country of residence.

3.We do not verify your identity

There is no identity check on this platform

OGuard performs no identity verification and collects no identity documents. There is no document upload, no selfie check, no third-party verification provider, and no in-person check. Accounts are approved manually by a member of our team on the basis of the details you typed into the registration form and nothing else.

We say this plainly because it cuts both ways. It means we hold far less sensitive data about you than a regulated broker would — no passport scan, no proof of address, no biometric data. It also means we have not confirmed that anyone on this platform is who they say they are, including in any dealings that touch your account.

Please do not send identity documents through the trading terminal, the support inbox, or any web form. If you do, we have no process designed to handle them.

We may introduce identity checks in future, including for existing accounts. If we do, we will update this Policy first and tell you what changes.

4.Why we use your data, and our legal bases

To provide the Service — performance of our contract with you
Creating and running your account, executing your instructions, holding and moving your balance, running Earn positions, and answering your support messages. Without this data we cannot provide the Service.
To keep accounts secure — our legitimate interests, and yours
Authenticating you, running two-factor checks, detecting and blocking automated abuse, rate-limiting sign-in attempts, recording sessions so you can spot access you do not recognise, and keeping an audit trail of staff actions.
To operate and improve the platform — our legitimate interests
Diagnosing faults, investigating incidents, and maintaining the reliability of the system.
To communicate with you — performance of our contract
Sending verification codes, approval notices, withdrawal confirmations and other transactional email. These are not marketing and you cannot unsubscribe from them while your account is open.
To meet legal obligations, or establish and defend legal claims
Where we are required to keep or disclose records, or where we need them to resolve a dispute with you or a third party.

Where we rely on legitimate interests, we have considered whether they are outweighed by your rights. You can object — see clause 10.

5.Who we share your data with

We do not sell your personal data. We share it only with the service providers below, only so far as each needs it to do its job, and only under contract.

Amazon Web Services (AWS) — hosting and database
Runs our servers and stores our database. AWS therefore holds, at rest, everything described in clause 2. Our infrastructure is hosted in AWS regions in the European Union.
Cloudflare — network protection and bot detection
Sits in front of the site. It sees the IP address, user-agent and request metadata of every visit, and runs the Turnstile challenge shown on sign-in, registration and password reset. Cloudflare processes this at the network edge location closest to you, which may be anywhere in the world.
Google — sign-in
Only if you choose “Continue with Google”. Google tells us your Google account identifier, your email address and your name; we tell Google nothing about your trading, your balance, or your activity on OGuard. If you never use the button, we share nothing with Google.
Resend — transactional email
Delivers our emails. It receives your email address, your name where the message uses it, and the content of the message — which for a verification or approval email includes the code or temporary password it carries.
Our execution venue — order execution
A third-party liquidity provider executes your orders. It receives the trading instructions placed on your account and holds the resulting order, trade and position records. It does not receive your name, email address, phone number or date of birth.
The TRON network — deposits and withdrawals
Deposits and withdrawals are transactions on a public blockchain. Wallet addresses, amounts and timestamps are published permanently and publicly by the network itself, visible to anyone, and cannot be deleted or corrected by us or by anyone else.

We may also disclose your data where we are legally required to, where it is necessary to establish or defend a legal claim, or to a buyer if we sell our business — in which case this Policy continues to apply until you are told otherwise.

On-chain data is permanent and public

Once a deposit or withdrawal is confirmed, the address, amount and time are on a public ledger forever. Anyone can read them, and they can potentially be linked to you by anyone who knows one of your addresses. No right in clause 10 — including deletion — can reach that data. Nobody, including us, is able to remove it.

6.International transfers

Our infrastructure is hosted in the European Union. Some of the providers in clause 5 are established in the United States, and Cloudflare processes traffic at edge locations worldwide, so your data may be transferred outside the European Economic Area.

Where it is, we rely on the transfer mechanisms those providers make available — including the European Commission’s Standard Contractual Clauses and, where applicable, an adequacy decision covering the destination country.

Transactions on the TRON network are not a transfer to a country at all: they are published to a public, globally distributed ledger, and no transfer mechanism applies to or protects them.

7.Cookies

We use cookies only to sign you in and keep you signed in. We set no advertising or analytics cookies.

oguard_session
Your signed-in session. Set when you sign in and lasts 7 days. It cannot be read by JavaScript, is sent only over HTTPS in production, and is restricted to oguard.io. Deleting it signs you out.
oguard_admin_session
The equivalent cookie for our administration site. It is never set on a customer account.
oguard_mfa_pending
A short-lived cookie that carries you from the password step to the two-factor step during sign-in. It lasts 5 minutes and is cleared as soon as you finish signing in.
Google sign-in transients
If you use “Continue with Google”, we briefly set cookies holding a one-time security value and the page to return you to. They exist only for the duration of the sign-in and are cleared afterwards.
Cloudflare cookies
Cloudflare sets its own cookies for security and bot detection, including for the Turnstile challenge. These are set by Cloudflare, not by us, and are governed by Cloudflare’s privacy documentation.

All of these are strictly necessary to sign in and stay signed in securely. Blocking them will prevent you from using your account. You can delete cookies through your browser at any time.

8.How long we keep your data

8.1 What is deleted automatically

A job runs once a day and permanently deletes the following, 60 days after each record was created:

  • your orders;
  • your executed trades;
  • your realised profit-and-loss records; and
  • your transaction records.

This means your trading history older than 60 days is gone and we cannot restore it. If you need records for tax or your own accounts, export or save them before they age out.

8.2 What has no automatic deletion

We are being exact rather than reassuring here

Everything not listed in 8.1 has no automatic deletion schedule and is currently kept for as long as your account exists — and, unless you ask us to delete it, after it closes. That includes:

  • your registration details, account record and acceptance of these documents;
  • your session history, including the IP addresses and user-agents recorded at each sign-in;
  • your support messages;
  • the log of emails we sent you;
  • your deposit and withdrawal requests, deposit addresses and withdrawal addresses;
  • your Earn positions and their payment schedules; and
  • the audit record of administrative actions on your account.

We have not yet set retention periods for these categories. We intend to, and this clause will say what they are when we do. In the meantime, you can ask us to delete data we no longer need — see clause 10.

Some records we may need to keep even after you ask: those required to settle a live Earn position or an outstanding balance, and those we need to defend a legal claim or comply with a legal obligation. On-chain records cannot be deleted by anyone (clause 5).

9.How we protect your data

The measures below are the ones actually in place. We have deliberately not listed anything we do not do.

  • Passwords are hashed, never stored in a form we or anyone else could read back.
  • Authenticator secrets, recovery codes and our credentials for the execution venue are encrypted at rest using AES-256-GCM, under keys held outside the database.
  • Your session token is held in a cookie that JavaScript cannot read, which limits what a script injected into the page could steal. It is attached to requests on the server, so it is never exposed to code running in your browser.
  • Two-factor authentication is available on sign-in, by authenticator app or emailed code, and is mandatory on every withdrawal — a stolen session alone cannot move money.
  • Every withdrawal is approved by a person before funds move, and payouts can only be sent to addresses on an allowlist we control.
  • Sessions can be revoked — individually per device, or all at once for an account.
  • Sign-in attempts are rate-limited and locked out progressively after repeated failures, and registration, sign-in and password reset are protected by a bot challenge.
  • Staff actions on an account are audited to an append-only log, including any action taken while a staff member is viewing an account as you.
  • Our administration site is separately protected behind an access gateway and uses accounts distinct from customer accounts.

What we cannot promise

No system is completely secure. We cannot guarantee that your data will never be accessed, disclosed, altered or destroyed by a breach. We are not certified against any security standard, and we do not currently publish independent audit or penetration-test results.

Our staff can see your account details and, for support purposes, view the platform as you. Every such action is written to the audit log.

10.Your rights

Subject to the law that applies to you, you have the right to:

Access
Ask for a copy of the personal data we hold about you, and information about how we use it.
Correction
Have inaccurate data corrected and incomplete data completed. You can change some details yourself in your account settings.
Deletion
Ask us to delete your personal data where we no longer have a good reason to keep it. We cannot delete what we need to settle a live Earn position or an outstanding balance, to meet a legal obligation, or to defend a legal claim — and nobody can delete on-chain records.
Portability
Receive the data you gave us in a structured, commonly used, machine-readable format, or ask us to send it to someone else where that is technically feasible.
Objection and restriction
Object to processing we base on our legitimate interests, or ask us to restrict processing while a dispute about accuracy or lawfulness is resolved.
Withdraw consent
Where we rely on your consent, withdraw it at any time. This does not affect processing carried out before you withdrew it.

10.1 How to exercise them

Email support@oguard.io from the address registered on your account, and tell us which right you want to exercise. We will respond within one month. We may ask you to confirm control of your account before we act — that check protects you, since we have not verified anyone’s identity by document.

Exercising these rights is free. If a request is manifestly unfounded or excessive we may charge a reasonable fee or decline it, and we will explain why.

If you are unhappy with how we have handled your data, you may complain to the data protection authority where you live or work. Please raise it with us first so we have a chance to put it right.

11.Children

OGuard is not for anyone under 18. We do not knowingly collect data from anyone under 18, and the registration form asks for your date of birth and rejects applicants below that age.

Because we do not verify identity, that check relies on what you tell us. If you believe someone under 18 has an account, tell us at support@oguard.io and we will close it and delete their data.

12.Changes to this Policy

We may update this Policy. When we do, we publish the new version here with a new version number and effective date, shown at the top of this page.

If a change materially affects how we use your data — a new category of data, a new purpose, or a new provider receiving it — we will make reasonable efforts to tell you by email to your registered address, or in the app, before it takes effect. We record which version you accepted when you registered.

13.Contact us

For anything in this Policy, including data requests and complaints, email support@oguard.io, or use the support inbox in the app. Our support inbox is staffed 24 hours a day, seven days a week.

We do not currently have a designated data protection officer. Your request will be handled by our support team.

OGuard Financial Services Corporation, trading as OGuard.

Questions about this document? Email support@oguard.io.