Privacy Policy
Last updated: 26 August 2026
The short version. AutoTrade P2P comes in two versions, and where your data lives depends on which one you use. In the web version, your Binance API key and your order history live on servers we operate, encrypted, and not on your PC. In the Windows version, they stay on your own PC and never reach us. This policy covers both, and it says which version it means whenever the two differ. Section 12 explains why an earlier wording of this page described only one of them.
1. Who is responsible
AutoTrade P2P is operated by CONNECTA DIGITAL SOLUTIONS S.A.C., RUC 20615591221, Jr. Marsella N° 255, Piso 4, Asoc. Pro Viv. Buenos Aires, Peru. For any question about this policy, or to exercise the rights in section 10, write to webbusinesstoolspro@gmail.com or to t.me/AutoTradeP2P.
2. Two kinds of people appear here
This distinction runs through the whole policy, so it comes first. You are the merchant: you signed up, you accepted these terms and you decided to use the app. Your counterparties are the people who trade with you on Binance P2P: they never signed up for anything here, and most of them have never heard of us. Their names and their tax document numbers pass through this system because your business needs them, not because they chose us. Everything we do with their data is on your instructions and for your business, and section 10 explains what that means for both of you.
3. What this covers
The AutoTrade P2P web application, the AutoTrade P2P Windows application and this website. The two applications are the same product and this policy covers both, but they do not keep your data in the same place, so wherever a paragraph below is only true of one of them it says which. It explains what we store, where it is stored, how long we keep it, who else can see it, and — in section 9 — what each design does not protect you from.
4. What we store about you
One line before the list, because it changes what all of it means: this section and the next describe where the data ends up. In the web version it ends up with us, on the servers in section 7. In the Windows version the app collects what it needs for the same jobs, but it writes it to a file on your own PC and sends us none of it, so “we store” below should be read there as “the app stores, on your own machine”.
- Your account. In the web version you sign in with Google, and Google gives us your email address and the identifier of your Google account. We do not receive your Google password. There, signing in with Google is not optional: it is how the app knows whose orders to show you. In the Windows version signing in is optional and only puts your name on the app — access is decided by your Microsoft Store licence, not by us.
- Your Binance API key. In the web version it is encrypted with AES-256-GCM before it is written down, and the key that opens it is not stored in the same database, so a copy of the database on its own does not reveal it. In the Windows version it never reaches us at all: it is encrypted on your own PC with Windows DPAPI and tied to your Windows account, so copying the files to another computer does not let anyone read them. Either way it is a read-and-trade key that you create in your own Binance account, and you can revoke it there at any moment without asking us.
- Your orders and your ads. Order numbers, amounts, currencies, payment methods, prices, commissions and dates, as Binance returns them. Your price rules and every price change the engine makes, so you can audit what it did.
- Your chatbot templates and settings, and the activity log of what the engine did and why.
- A fingerprint of your Binance identity, for the free trial. In the web version, when you connect your API key we take the verified name Binance holds for your account and your country, and we store a keyed hash (HMAC-SHA256) of them — never the name itself. It exists for one purpose: so that the seven-day trial cannot be taken twice by the same person using a second Google account. The keyed hash cannot be reversed into a name without a secret that is not stored with it.
5. What we store about your counterparties
This is the part to read twice, because these are people who did not choose us.
- Their verified name, as Binance returns it, and the opaque identifier Binance uses for them. We keep the name because Binance hides counterparty details 90 days after an order, and your invoicing needs it after that: the masked nickname Binance returns later is useless for accounting.
- The identity or tax document number they type in the chat, when your chatbot asks for it, together with every number they tried that did not validate. Binance does not return this: it only exists because your customer wrote it. Whether to ask for it at all is your decision and your legal responsibility.
- The payment account they used, as Binance returns it with the order: the bank or wallet, the account number and the account holder. We keep it because Binance hides the order details 90 days after the order, and without it you cannot reconcile a payment months later. It is your customer’s financial data and we do not use it for anything else.
- The chat messages of each order, in both directions, so the engine can answer and so you have a record of what was agreed. In the web version these are deleted a few days after the order closes — seven by default. We keep the order itself; we do not keep the conversation forever. In the Windows version nothing is deleted on our side because nothing reaches us: the conversation stays in the file on your own PC until you delete it.
6. What we do not do
- We do not sell your data or your counterparties' data, and we do not share it with anyone except the providers listed in section 8.
- We run no advertising, no third-party trackers and no behavioural analytics.
- We never ask for your Binance password, your funds password or your 2FA codes, and the app has no field to type them. The app cannot release crypto on its own: releasing requires your funds password, which is never stored anywhere — not in the database, not in memory, not “for five minutes”.
- We do not scrape Binance or use session cookies. The app only talks to Binance's official API, signed with your key.
7. Where it lives
In the web version: on a managed PostgreSQL database and on a virtual server, both rented from the providers in section 8 and both located in South America. Your data is not stored in your own country by default, and by using the web version you accept that it is processed on those servers.
Still in the web version: each merchant's rows are isolated at the database level, not only in the application. The database itself refuses to return one merchant's rows to another, and that rule is verified automatically before every release.
In the Windows version: on your own PC, in a file in your user folder, and nowhere else. There is no server of ours in the middle, so nothing in the two paragraphs above applies to it — including the isolation rule, because that database holds exactly one merchant: you.
8. Who else is involved
- Binance. The app calls its official API with your key. What Binance does with that is governed by Binance's own terms and privacy policy, not by this one.
- Supabase — the managed database and the sign-in service. Web version only.
- Hostinger — the virtual server the engine runs on. Web version only: in the Windows version the engine runs on your own PC and no provider is involved.
- Google — sign-in, and the spreadsheet we use to keep track of subscriptions. That sheet lives in our own Google Drive and holds your email, your Binance nickname, whether your subscription is live and until when, and the payment reference you send us. Nothing about your orders or your counterparties is ever written to it.
- GitHub Pages serves this website, and the typeface is loaded from Google Fonts, which means your browser makes a request to Google's servers when you read this page.
9. What this does not protect you from
Saying only the reassuring half would be dishonest, so here is the other half. In the web version, encrypting the API key protects against someone obtaining a copy of the database: without the separate key, the copy is useless. It does not protect against someone who gains control of the running engine, because at that point the key is in memory by necessity — the engine has to sign requests to Binance. This is the trade-off you accept when the bot answers your customers while your computer is switched off, and it is the reason we recommend restricting your Binance API key to the engine's IP address.
In the Windows version the trade-off is the other way round: the engine only runs while your PC is on, so nothing answers your customers overnight, and in exchange no server of ours ever holds your key. What that version cannot protect you from is your own computer. The key is encrypted there with Windows DPAPI and tied to your Windows account, which makes a stolen copy of the files useless on another machine, but anyone who is running programs as you — a family member, a stranger with remote access, malware — is on the right side of that lock. There we cannot help you, because we hold nothing to help you with. In that version restrict the key to your own IP address, if it is stable enough for that.
In both versions, never enable withdrawals on that key. The app does not use the permission, and leaving it off is what means that even a leaked key cannot take money out of your Binance account.
10. Your rights, and your customers' rights
Under Peru's Law 29733 on the Protection of Personal Data you can ask us to show you the data we hold about you, correct it, delete it, or object to its processing. Write to the address in section 1 and we will answer within the legal deadline. Deleting your account deletes your orders, your messages, your templates and your encrypted API key — in the web version, which is where we hold them. In the Windows version there is no account of ours to delete: that data is a file on your own PC. The trial fingerprint in section 4 is deliberately kept, because it holds no name and deleting it would simply hand out a second free trial.
For your counterparties' data, you decide what is collected and why, and we process it on your behalf. Correcting one of your customers' details is done in the app. Erasing them is not, yet: write to us and we will do it, and we will tell you what was kept and why. If a customer writes to us directly, we will point them to you, because we cannot judge whether a record is needed for your accounting or your tax obligations. Making sure you have a lawful basis for asking your customers for their identity documents is your responsibility, not ours.
11. How long we keep it
This section is about the web version; in the Windows version we keep nothing, because nothing reaches us. Chat messages: a few days after the order closes, seven by default. Everything else: while your account exists, plus a short window afterwards for backups to roll over. Cancelling a subscription does not delete anything by itself: your account keeps existing, and so does your history, until you ask us to delete it. The activity log is trimmed automatically so it does not grow without limit.
12. What changed, and why we are saying so
For most of its life AutoTrade P2P was one product — a Windows application with no server of any kind — and this page said so without qualifying it: “there is no AutoTrade P2P server”, “everything stays on your PC”, and the API key encrypted with Windows DPAPI so that copying the files to another computer was useless. On 24 August 2026 those sentences were replaced, because a web version had arrived and not one of them is true of it: there the engine runs on servers we operate and your encrypted API key is on them.
What that rewrite got wrong, and what this one fixes, is that it was written as if the web version had replaced the Windows one. It did not. Both versions are alive: the web one you can use today, and the Windows one is in certification at the Microsoft Store. Of that version those old sentences are still true, DPAPI included — which is why this page now names the version it is talking about wherever the two behave differently, instead of describing only one of them.
We spell all this out instead of quietly editing the page because “everything stays on your PC” was published here as an unqualified promise, and for the web version it is not one. Which half of that sentence applies to you depends on which version you chose, and that is exactly the kind of thing a privacy policy exists to tell you.
13. Changes to this policy
If we start storing, sending or keeping something we do not store, send or keep today, this page changes first and the date at the top changes with it.