Privacy & Data Security Policy
Effective Date: January 1, 2026
1. The VestWits Promise
Unlike retail applications that monetize your behavioral data, VestWits operates as a fiduciary. We do not sell, rent, or lease your Personally Identifiable Information (PII) or trading telemetry to third-party ad networks, high-frequency trading firms, or data brokers. Your data is used strictly for the execution of clearing services and regulatory compliance.
2. Cryptographic Security Enclaves
All sensitive financial data, including Social Security Numbers, banking credentials, and fractional ledger balances, are encrypted at rest using AES-256 military-grade encryption. Data in transit is secured via TLS 1.3 cryptographic tunneling. Our backend infrastructure utilizes hardware-backed security modules to isolate your data from our public-facing web servers.
3. Information We Collect
- Identity Verification Data (KYC): Legal name, date of birth, residential address, and government-issued identification numbers.
- Financial Telemetry: Bank account routing numbers (via secure tokenization), liquid net worth, and tax classification status.
- System Interaction Data: IP addresses, device identifiers, and terminal session durations used strictly for fraud prevention.
4. Regulatory Disclosure Exceptions
Under federal securities law (USA PATRIOT Act, Bank Secrecy Act), we are legally mandated to share specific transactional data with regulatory bodies (such as the SEC and FINRA) and our custodial clearing partners to prevent money laundering and terrorist financing.
5. Telemetry & Secure Session Cookies
We employ stateless JSON Web Tokens (JWT) and secure HTTP-only cookies to authenticate your terminal sessions. We do not deploy third-party marketing pixels on the authenticated dashboard. Any cookies stored on your local machine are strictly necessary for load balancing, multi-factor authentication routing, and CSRF protection.
6. GDPR & Right to Erasure
If you are operating under EU jurisdiction or the CCPA, you retain the right to request a full cryptographic erasure of your non-financial data. Note that SEC Rule 17a-4 mandates the retention of all trade execution logs and communication records for a minimum of 6 years, overriding local erasure laws for those specific financial artifacts.