AutoTrade P2P
← Back to home

Privacy Policy

1. Who is responsible

AutoTrade P2P is operated by CONNECTA DIGITAL SOLUTIONS S.A.C., RUC 20615591221, Jr. Marsella N° 255, Piso 4, Asoc. Pro Viv. Buenos Aires, Peru. For any question about this policy, or to exercise the rights in section 10, write to webbusinesstoolspro@gmail.com or to t.me/AutoTradeP2P.

2. Two kinds of people appear here

This distinction runs through the whole policy, so it comes first. You are the merchant: you signed up, you accepted these terms and you decided to use the app. Your counterparties are the people who trade with you on Binance P2P: they never signed up for anything here, and most of them have never heard of us. Their names and their tax document numbers pass through this system because your business needs them, not because they chose us. Everything we do with their data is on your instructions and for your business, and section 10 explains what that means for both of you.

3. What this covers

The AutoTrade P2P web application, the AutoTrade P2P Windows application and this website. The two applications are the same product and this policy covers both, but they do not keep your data in the same place, so wherever a paragraph below is only true of one of them it says which. It explains what we store, where it is stored, how long we keep it, who else can see it, and — in section 9 — what each design does not protect you from.

4. What we store about you

One line before the list, because it changes what all of it means: this section and the next describe where the data ends up. In the web version it ends up with us, on the servers in section 7. In the Windows version the app collects what it needs for the same jobs, but it writes it to a file on your own PC and sends us none of it, so “we store” below should be read there as “the app stores, on your own machine”.

5. What we store about your counterparties

This is the part to read twice, because these are people who did not choose us.

6. What we do not do

7. Where it lives

In the web version: on a managed PostgreSQL database and on a virtual server, both rented from the providers in section 8 and both located in South America. Your data is not stored in your own country by default, and by using the web version you accept that it is processed on those servers.

Still in the web version: each merchant's rows are isolated at the database level, not only in the application. The database itself refuses to return one merchant's rows to another, and that rule is verified automatically before every release.

In the Windows version: on your own PC, in a file in your user folder, and nowhere else. There is no server of ours in the middle, so nothing in the two paragraphs above applies to it — including the isolation rule, because that database holds exactly one merchant: you.

8. Who else is involved

9. What this does not protect you from

Saying only the reassuring half would be dishonest, so here is the other half. In the web version, encrypting the API key protects against someone obtaining a copy of the database: without the separate key, the copy is useless. It does not protect against someone who gains control of the running engine, because at that point the key is in memory by necessity — the engine has to sign requests to Binance. This is the trade-off you accept when the bot answers your customers while your computer is switched off, and it is the reason we recommend restricting your Binance API key to the engine's IP address.

In the Windows version the trade-off is the other way round: the engine only runs while your PC is on, so nothing answers your customers overnight, and in exchange no server of ours ever holds your key. What that version cannot protect you from is your own computer. The key is encrypted there with Windows DPAPI and tied to your Windows account, which makes a stolen copy of the files useless on another machine, but anyone who is running programs as you — a family member, a stranger with remote access, malware — is on the right side of that lock. There we cannot help you, because we hold nothing to help you with. In that version restrict the key to your own IP address, if it is stable enough for that.

In both versions, never enable withdrawals on that key. The app does not use the permission, and leaving it off is what means that even a leaked key cannot take money out of your Binance account.

10. Your rights, and your customers' rights

Under Peru's Law 29733 on the Protection of Personal Data you can ask us to show you the data we hold about you, correct it, delete it, or object to its processing. Write to the address in section 1 and we will answer within the legal deadline. Deleting your account deletes your orders, your messages, your templates and your encrypted API key — in the web version, which is where we hold them. In the Windows version there is no account of ours to delete: that data is a file on your own PC. The trial fingerprint in section 4 is deliberately kept, because it holds no name and deleting it would simply hand out a second free trial.

For your counterparties' data, you decide what is collected and why, and we process it on your behalf. Correcting one of your customers' details is done in the app. Erasing them is not, yet: write to us and we will do it, and we will tell you what was kept and why. If a customer writes to us directly, we will point them to you, because we cannot judge whether a record is needed for your accounting or your tax obligations. Making sure you have a lawful basis for asking your customers for their identity documents is your responsibility, not ours.

11. How long we keep it

This section is about the web version; in the Windows version we keep nothing, because nothing reaches us. Chat messages: a few days after the order closes, seven by default. Everything else: while your account exists, plus a short window afterwards for backups to roll over. Cancelling a subscription does not delete anything by itself: your account keeps existing, and so does your history, until you ask us to delete it. The activity log is trimmed automatically so it does not grow without limit.

12. What changed, and why we are saying so

For most of its life AutoTrade P2P was one product — a Windows application with no server of any kind — and this page said so without qualifying it: “there is no AutoTrade P2P server”, “everything stays on your PC”, and the API key encrypted with Windows DPAPI so that copying the files to another computer was useless. On 24 August 2026 those sentences were replaced, because a web version had arrived and not one of them is true of it: there the engine runs on servers we operate and your encrypted API key is on them.

What that rewrite got wrong, and what this one fixes, is that it was written as if the web version had replaced the Windows one. It did not. Both versions are alive: the web one you can use today, and the Windows one is in certification at the Microsoft Store. Of that version those old sentences are still true, DPAPI included — which is why this page now names the version it is talking about wherever the two behave differently, instead of describing only one of them.

We spell all this out instead of quietly editing the page because “everything stays on your PC” was published here as an unqualified promise, and for the web version it is not one. Which half of that sentence applies to you depends on which version you chose, and that is exactly the kind of thing a privacy policy exists to tell you.

13. Changes to this policy

If we start storing, sending or keeping something we do not store, send or keep today, this page changes first and the date at the top changes with it.