Information you provide
GridCove stores your account email, a salted password hash, plan and subscription status, alert preferences, support messages, and account timestamps in the hosted Microsoft SQL Server account database. When you connect a supported exchange, GridCove receives the exchange-specific API credentials you enter, such as an API key and secret or a Coinbase API-signing key. Those credentials are encrypted before their protected values are stored and are not displayed back to your browser or owner support screens.
Trading and service information
To operate and display the bot, GridCove processes exchange account permissions, balances, supported market data, open orders, fills, bot settings, recovery state, event history, errors, worker health, and control commands. Funds remain at the exchange. GridCove does not intentionally request or store an exchange password, seed phrase, blockchain private key, or withdrawal-enabled credential.
Technical information
GridCove and its hosting provider may process IP address, browser and device type, requested pages, login and security events, timestamps, error logs, and similar technical data needed to deliver, diagnose, protect, and improve the hosted service. The public site does not intentionally use advertising trackers.
Stripe billing
Stripe processes Checkout, payment details, billing, receipts, fraud prevention, subscription management, and legal compliance under its own privacy terms. GridCove receives limited data such as Stripe customer, Checkout, and subscription identifiers; email; amount; currency; payment mode; status; and subscription period so it can activate, renew, cancel, or expire Pro access. GridCove does not receive the full card number.
Browser and email alerts
If you enable browser alerts, GridCove stores a push endpoint and browser-generated encryption keys used to deliver notifications. The endpoint may involve the browser vendor’s push service. If email alerts are enabled, GridCove sends selected operational messages through the configured email provider. You can change these preferences from your account.
Support-chat processing
Tickets may include your name, email, subject, messages, status, replies, and any chat transcript you choose to attach. Support chat stores a random session identifier, messages, timestamps, and whether an automated Groq or built-in reply was used. Messages that look like passwords, API keys, recovery codes, or long private tokens are rejected and intentionally not stored. When Groq support is enabled, a limited recent history and question are sent server-to-server to Groq to produce a support response. Use a human ticket if you prefer not to use automated chat.
Cookies and local storage
GridCove uses secure, HTTP-only cookies for customer and owner sign-in. The support widget may keep a random chat identifier in browser local storage. The bot interface may store non-secret display preferences and seen-alert references locally. These technologies are used for authentication, continuity, security, and product operation rather than advertising.
How information is used and shared
Information is used to provide hosted automation, authenticate users, enforce plans, verify exchange permissions, display status, process controls, send alerts, manage subscriptions, answer support, prevent abuse, comply with law, and improve reliability. It may be processed by service providers such as SmarterASP, Stripe, the email provider, browser push providers, the exchange or exchanges you connect, and optional Groq only for those functions. GridCove does not sell personal information or exchange credentials.
Retention
Customer, subscription, trading-state, audit, and support records are retained while needed to operate the account, protect security, meet accounting or legal duties, resolve disputes, and preserve restart-safe bot operation. Un-escalated support chats are removed after approximately 90 days under the current configuration. Closing an account does not require immediate deletion of records that must be kept for legal, security, billing, or dispute purposes.
Security
GridCove uses HTTPS, SQL access controls, password hashing, protected server folders, encrypted exchange credentials, per-customer and per-exchange state separation, restricted owner screens, secret filtering, signed payment webhooks, and server-side entitlement verification. Database and private application-key backups are maintained separately because both are needed for a complete recovery. No system can promise perfect security. Secure your email and exchange account, use unique passwords, keep withdrawals disabled, and report suspected compromise promptly.
Your choices and rights
Depending on your location, you may have rights to ask about, access, correct, delete, restrict, or obtain a copy of personal information controlled by GridCove, and to complain to a regulator. Some records may be retained where law, security, transaction, or active-order obligations require it. Send requests to support@gridcovecrypto.com.
Children and changes
GridCove is not directed to anyone under 18 and does not knowingly collect children’s information. This notice may be updated as the service, providers, or legal requirements change; the date above will be revised.