Privacy Policy
Last updated: April 5, 2026
This Privacy Policy describes how Private Parachute, Inc. ("Parachute," "we," "us," or "our") collects, uses, and protects your information when you use the Parachute Bot Trader platform ("Service").
1. Information We Collect
Account Information
When you create an account, we collect your email address, name, and avatar preference. Account authentication is handled through Supabase.
Kalshi API Credentials
To operate the trading bot on your behalf, we store your Kalshi API key ID and private key. Your private key is encrypted at rest using AES-256-GCM encryption and is decrypted only in memory during bot execution. We never store your private key in plaintext, and we never have access to your Kalshi account password.
Trading Telemetry
The bot generates data about its trading activity, including fills, settlements, positions, heartbeats, market scans, execution orders, and trading signals. This data is stored in our database to power the monitoring dashboard.
Usage Data
We collect login events, IP addresses, and anonymous page view analytics (via Vercel Analytics). We use Sentry for error tracking, which may collect stack traces and browser information when errors occur.
Lead Form
If you submit the interest form on our landing page, we collect your name, email address, Kalshi account status, and intended investment basis.
2. Information We Never Collect
- Your Kalshi account password
- Your bank account or payment card information (handled entirely by Stripe)
- Personal financial data beyond what the trading bot generates
3. How We Use Your Information
- To operate the trading bot on your Kalshi account
- To display your trading performance and bot status on the dashboard
- To send you transactional emails (account invites, password resets, alerts)
- To process your subscription payments via Stripe
- To diagnose and fix software errors
- To improve the Service
4. Third-Party Services
We use the following third-party services to operate the platform:
- Supabase — database, authentication, and realtime subscriptions
- Stripe — subscription billing and payment processing
- Resend — transactional email delivery
- Vercel — web application hosting and anonymous analytics
- Sentry — error monitoring and performance tracking
- Kalshi — event contract trading platform (via your API credentials)
Each of these services has its own privacy policy governing the data they process on our behalf.
5. Data Retention
Trading telemetry is subject to automated retention policies: market scans are retained for 30 days, bot heartbeats for 14 days, and execution data for 90 days. Account data (credentials, profile, trading configuration) is retained until you request deletion.
6. Data Security
We take the security of your data seriously. API credentials are encrypted with AES-256-GCM. All data is transmitted over HTTPS. Database access is controlled by row-level security policies. However, no system is perfectly secure, and we cannot guarantee the absolute security of your data.
7. Cookies
We use a functional session cookie for authentication (managed by Supabase). Vercel Analytics collects anonymous usage data without using cookies that track personal information. We do not use advertising or third-party tracking cookies.
8. Your Rights
You may request a copy of your data or request deletion of your account and all associated data by contacting us. Account deletion will remove your profile, credentials, trading configuration, and telemetry data. It will not affect your Kalshi account.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service.
10. Contact
Questions about this Privacy Policy? Contact us at derek@parachute.fund.