Legal
Privacy Policy
How triStack AlgoTrader collects, uses, shares, protects and deletes personal data, and how you exercise your rights under India's Digital Personal Data Protection Act, 2023. Your instance is yours, but we operate it, so this is a full policy and not a claim that we hold nothing.
- Last updated
- 23 August 2026
- Last reviewed
- 23 August 2026
- Applies to
- trade.quantgrid.in and the triStack AlgoTrader service
The 30-second version
- Your trading data, your strategy code and your broker credentials live on your own instance, in your own database, not in a shared platform database.
- We still operate that instance, so we are the Data Fiduciary for what is on it. This policy is written on that basis rather than on a claim that we cannot see anything.
- You register your own developer app at your own broker and hold your own key. Revoke it at the broker and access stops immediately, including ours.
- We do not sell personal data, do not trade on our own account, and do not package your order flow as market data.
- Card details go to a payment gateway. They never reach our servers.
- This marketing website runs no analytics and no tracking. The only thing it stores in your browser is which appearance you picked.
- Ask for a copy of your data, correct it, delete it or withdraw consent at [email protected]. We respond within 30 days.
This summary is for orientation only. The sections below govern.
1. Scope and who we are
This Privacy Policy explains how Tristack Technologies LLP handles personal data when you visit trade.quantgrid.in, discuss an instance with us, have one provisioned, use it, or contact us. It applies to this marketing website and to the triStack AlgoTrader instance we operate for you at trade.quantgrid.in.
triStack AlgoTrader is the brand and the product. Tristack Technologies LLP is the limited liability partnership that operates it, contracts with you, issues your invoice and answers for the personal data described here. Where this policy says triStack AlgoTrader does or does not do something, it is Tristack Technologies LLP making that commitment.
Under the Digital Personal Data Protection Act, 2023 (the DPDP Act) we are the Data Fiduciary for the personal data described here, and you are the Data Principal. We are also an intermediary for the purposes of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and we publish the Grievance Officer details those rules require in section 16.
triStack AlgoTrader is hosting infrastructure. It is not registered with SEBI in any capacity, gives no investment advice, publishes no signals, and never holds your funds or securities: those stay with your own broker throughout. See Compliance for the full position.
The Data Fiduciary, and how to reach it
- Legal entity
- Tristack Technologies LLP
- LLPIN
- ACP-3743
- GSTIN
- 07AAYFT2516N1ZF
- Registered office
- B-35, Vinoba Kunj Apartments, Sector 9, Rohini, Delhi 110085, India
- Privacy contact
- [email protected]
- Grievance Officer
- Ashutosh Mishra, [email protected] (see section 16)
- Operations
- trade.quantgrid.in/status
Write to [email protected] for anything about your personal data, and to the Grievance Officer in section 16 if a request is not handled to your satisfaction. Email is answered Monday to Friday, 8:00 AM to 5:00 PM IST.
2. Where your data actually lives
This product has an unusual shape, and the shape determines the rest of this policy, so it is stated before anything else.
- On your instance. Your broker credentials, your order and execution records, your positions, your logs and your strategy code are written to a database belonging to your instance alone, on its own volume. There is no shared schema and no tenant column, so there is no query, correct or incorrect, that returns your rows to another customer.
- On our infrastructure. The host your instance runs on, its metrics, its infrastructure logs, the encrypted backups of your database, and the allocation record for your dedicated egress address.
- In our own records. Your onboarding details, your order form, your billing contact details, your invoices and our correspondence with you. These are ordinary business records and are not on your instance.
Isolation is a real boundary and it is worth what it costs. It is not, however, a claim that your data is beyond our reach: we operate the machine. Section 6 says exactly when we go near it.
3. What is collected
The table below is the complete list of categories, what each contains, where it comes from and which of the three places in section 2 it is held in.
| Category | What it includes | Where it comes from | Where it is held |
|---|---|---|---|
| Onboarding and account data | Your name, the entity you contract through if any, your email address, the sign-in credentials for your instance (the password is stored only as a one-way hash), and the record of who is authorised to administer the instance. | You, during onboarding. | Our records and your instance |
| Billing contact details | What a GST invoice must be made out to: billing name, address, state and PIN code, a contact mobile number, and your GSTIN if you have one. The GSTIN is optional, because only a registered business has one. | You, before the first invoice. | Our records |
| Billing records | Your order form, the invoices we raise, the periods they cover, and the payment references our payment gateway returns with the amount and status of each payment. Card, UPI and net-banking credentials are entered on the gateway's own page and never reach us. | You and the payment gateway. | Our records |
| Instance configuration | The hostname issued to you, the size of the instance, the dedicated egress IP addresses allocated to it, which brokers you have connected, and the operational settings you choose. | You, and our provisioning system. | Our records and your instance |
| Broker credentials | The API key, application identifier, secret and access token your own broker issues against your own developer application, plus whatever else that broker's login requires if you configure automatic session renewal. Held encrypted at rest. Section 5 sets out exactly what happens to them. | You, and your broker at the point of authorisation. | Your instance only |
| Trading data | Orders, executions, positions, holdings and funds read from or sent to your broker: symbol, exchange, side, quantity, price, product type, order status, broker order id and timestamps, together with the engine's own record of what it did and why. | Your broker API, and your strategies. | Your instance only |
| Your strategy code | The scripts, node graphs, schedules and parameters you write or import. These are your intellectual property and we claim no rights in them. | You. | Your instance only |
| Operational and technical data | Host and process metrics, the dedicated egress addresses in use, backup catalogues, and infrastructure and access logs including error traces. This is what monitoring and incident response are made of. | Automatically, from operating the instance. | Our infrastructure |
| Support correspondence | Emails, contact-form submissions, and any logs, screenshots or code excerpts you choose to send us while we work on an issue. | You. | Our records |
| Website request metadata | For trade.quantgrid.in, the marketing site you are reading: the page requested, the referring page, the browser user agent and the IP address the request came from, as any web server necessarily sees them. This site runs no analytics and no tracking scripts, so there is nothing beyond the request itself. | Automatically, from the request. | Our infrastructure |
We do not collect special-category data, we do not run credit checks, and we do not buy personal data from data brokers or list vendors. We do not ask for your PAN, your bank statements or your broker ledger, and you should not send them to us.
4. Why, and on what lawful basis
The DPDP Act allows processing either with your consent or for certain legitimate uses. Each purpose below names the categories from section 3 that it draws on, and the basis we rely on. Where we rely on consent, you can withdraw it, and section 11 explains how.
| Purpose | Categories used | Basis |
|---|---|---|
| Provision your instance, operate it, and keep it patched, backed up and monitored | Onboarding and account data, instance configuration, operational and technical data | Performance of the contract you enter into under our Terms, which is a legitimate use under the DPDP Act because you gave the data voluntarily for this service. |
| Let you sign in to your instance and administer it | Onboarding and account data | Performance of the contract. |
| Connect your instance to your own broker and run the strategies you configure | Broker credentials, trading data, your strategy code | Your explicit consent, given when you enter your own broker credentials or complete your broker's authorisation flow, together with performance of the contract. |
| Keep the order and event record on your instance, so that either of us can reconstruct what happened | Trading data, operational and technical data | Performance of the contract, and our legitimate use in keeping records of a service that places orders. |
| Allocate and route your dedicated egress address, and keep the infrastructure secure | Instance configuration, operational and technical data | Legitimate use for the security of the service and the prevention of misuse. |
| Deliver the alerts you switch on, such as Telegram notifications for fills, rejections and errors | Onboarding and account data, trading data | Your consent, which you withdraw by turning the alert off or unlinking the chat. |
| Invoice you, take payment, and meet tax and accounting obligations | Billing contact details, billing records | Performance of the contract, and compliance with Indian tax and GST law, which requires an invoice to carry the customer's name and address and, where you have one, your GSTIN. |
| Answer support requests and investigate an incident on your instance | Support correspondence, operational and technical data, and, where you ask us to look, data on your instance | Performance of the contract. Section 6 sets out the limits on this access. |
| Send service messages: invoices, maintenance notices, incident notices, changes to these documents | Onboarding and account data | Legitimate use. These are not marketing messages and cannot be switched off while your instance is in service. |
| Serve this website and keep it reachable | Website request metadata | Legitimate use for the availability and security of the site. No analytics, no profiling and no advertising. |
We do not use your data for automated decisions that produce a legal effect on you, and we do not profile you for advertising. Your strategies are automated, but they are yours: they execute the rules you wrote, on the schedule you set.
5. Broker credentials and trading data
This is the most sensitive thing the service touches, so we will be exact about it.
How the connection is made
You register your own developer application with your own broker and obtain your own API credentials. You enter them into your own instance, or complete your broker’s authorisation flow from it. The credentials and the tokens issued against them are stored on your instance, encrypted at rest, and are never written to application logs. They are not copied into a central store, because there is no central store to copy them into.
Some brokers publish a login page and hand back a token, in which case nothing but the token is ever held. Others publish no login page, or you may choose to have the daily session renewed automatically, and in those cases the instance has to hold whatever that broker’s login requires. Those values are encrypted at rest, are used for nothing except signing in to that broker, and are deleted when you remove the connection.
What is done with it
Broker data is used for exactly three things: running the strategies you configured, showing you your own orders, positions and analytics, and writing the record that lets you reconstruct what happened and when. Nothing else.
What is never done with it
- It is never sold. Not to data buyers, not to brokers, not to research firms, not to anyone.
- It is never traded on. triStack AlgoTrader operates no proprietary trading book. Your orders are not a signal we act on, front-run or hedge against.
- It is never aggregated and resold as market data. Your order flow is not packaged as sentiment, flow or analytics.
- Your strategy code is never reused. We do not run it on any other account, do not study it to build a product, and claim no licence to it beyond operating your instance for you.
You can revoke access from your broker’s own console at any moment. It takes effect immediately, stops the instance trading, and cannot be undone by us. You can also delete a broker connection inside your instance, which destroys the stored credentials at once. Historical order records stay for the period in section 9, because they are the record of trades that really happened in your account.
6. Our access to your instance
Managed hosting means somebody operates the machine, and it is honest to say who and when. We hold administrative access to the infrastructure your instance runs on. We need it to patch the host, restart a stuck process, take and restore backups, and investigate an incident.
What that access is used for, and what it is not:
- Operations. Patching, upgrades, restarts, capacity, backups and monitoring. These touch the machine and the database as a whole rather than reading individual records.
- Support you asked for. If you raise an issue and ask us to look, we look at what is needed to answer it, and no further. Tell us if you would rather send an excerpt than have us open the instance.
- A security or integrity incident. If your instance is compromised, is attacking something, or is exhausting shared infrastructure, we act on it and tell you.
- A legal obligation. A court order, a regulator’s direction or a lawful request from a government agency, complied with to the minimum extent the request covers, and told to you unless we are legally barred.
We do not read your strategy code for our own purposes, do not browse your order book out of interest, and do not use anything on your instance to inform any trading. Administrative actions are logged. If you want a record of when your instance was accessed by us, ask and we will produce it.
7. Sharing and processors
We do not sell personal data, and we do not share it for anyone else’s marketing. We share it only with the processors below, each bound by contract to process it only on our instructions and only for the function named.
| Processor | What it handles | Location |
|---|---|---|
| Amazon Web Services (AWS) | Supplies the compute, storage and network your instance runs on, the volume the isolated database sits on, and the storage the encrypted backups are written to. Every category held on the instance or on our infrastructure physically sits here. The provider supplies capacity and does not use your data for its own purposes. | Mumbai, India (the AWS ap-south-1 region). Instances are provisioned here by default, and any other region is agreed with you in writing beforehand and recorded on your order form. |
| Payment gateway | No payment gateway is in use: this site does not currently collect payment, and no payment data of yours has reached any processor through it. When one is introduced it will receive your name, email address, mobile number, the amount, and a reference that lets us match a payment to your account. Card, UPI and net-banking credentials are entered on the gateway's own page and never reach us: we would get back a reference, the amount and the status. The gateway will be named here, and you will be notified under section 15, before it collects anything. | India, when one is introduced. |
| Amazon Simple Email Service (Amazon SES) | Delivers account verification, provisioning details, maintenance and incident notices, and password resets. Receives your name, your email address and the contents of those messages. | Mumbai, India (the AWS ap-south-1 region). |
| Telegram | Delivers alerts from your instance, and only where you have linked a Telegram chat to it. Receives the chat identifier and the alert text, which carries details of your own orders: symbol, side, quantity and status. Link no chat and Telegram receives nothing about you. | Outside India. |
| Cloudflare | Resolves and serves this marketing website and the application hostname. It handles request metadata (IP address, page requested, user agent, timing) in order to route and serve the request. It carries traffic rather than storing your account records. | Global edge network. A request is answered by the location nearest you, which may be outside India. |
Beyond those processors, we disclose personal data only when:
- you tell us to, for example by linking a Telegram chat or asking us to raise a connection problem with your broker;
- a law, a court order, a regulator, or a lawful request from a government agency requires it, in which case we disclose the minimum the request covers and, unless we are legally barred, we tell you;
- it is needed to establish, exercise or defend a legal claim, or to investigate fraud or abuse of the infrastructure;
- the business is merged, acquired or reorganised, in which case data moves to the successor under this same policy and we notify you before it takes effect.
Your broker also receives data from your instance: the orders your strategies place. That is the purpose of the service, and your relationship with your broker is governed by their agreement and their privacy policy, not by this one.
8. Cookies and local storage
This website sets no cookies of its own, runs no analytics and carries no tracking scripts. There is no advertising pixel, no retargeting tag, no social widget and no cross-site tracking. The Cookie Policy sets out the same position item by item, and the two are revised together.
| What | Purpose | Type | Control |
|---|---|---|---|
| Appearance preference | Remembers whether you chose the light or dark rendering of trade.quantgrid.in, so it is not reset on every visit. Stored under the key "tsat-theme". | Preference, in browser local storage | Clear site data for this domain in your browser and it returns to following your system setting. |
| Sign-in session on your instance | Your instance keeps you signed in between page loads. It is on a different hostname from this website, it is your deployment, and nothing about it is shared with this site. | Set by the application, not by this website | Sign out of the instance, or clear site data for that hostname. |
Our edge network may set an operational cookie in order to route or protect a request. If we ever add an optional cookie or a third-party script, we will ask for your consent before it runs and revise this section and the Cookie Policy in the same change.
9. How long it is kept
We keep personal data only as long as the purpose in section 4 lasts, or as long as a law requires, whichever is longer. When a period ends, data is deleted or irreversibly aggregated.
| Data | Retention period |
|---|---|
| Onboarding and account data | For as long as your instance is in service, then 12 months after it is decommissioned. |
| Broker credentials and access tokens | On your instance, for as long as the broker account is connected. Access tokens expire on your broker's own schedule, which for most Indian brokers is daily. Everything is destroyed with the instance, and you can delete a connection yourself at any time. |
| Trading data, logs and strategy code on your instance | For as long as the instance exists. It is your data on your deployment: you can export it or delete it whenever you choose. On termination it is available to you for 30 days and is then destroyed with the instance. |
| Backups of your isolated database | Rolling, on the schedule stated in your order form, and each backup is deleted on its own expiry. Backups made before termination expire on that same schedule after the instance is decommissioned. |
| Billing contact details | For as long as your instance is in service, then 12 months. Details already printed on an issued invoice stay on that invoice for the period below. |
| Billing records and invoices | 8 financial years, as required by Indian tax and company law. |
| Infrastructure and access logs | 180 days, then deleted or aggregated beyond re-identification. |
| Support correspondence | 24 months after the conversation closes. |
| Website request metadata | 30 days. |
Audit and financial records are the exception to erasure. Where Indian tax, company or information-technology law obliges us to retain a record, we retain it for the statutory period even if you close your account and ask for deletion. In that case we restrict the record so it is used for nothing except meeting that obligation, and we delete it when the period expires.
Because most of your data is on your own instance, you control most of this schedule yourself. Deleting a strategy, a log or a connection on the instance deletes it, subject only to backups already taken, which expire on their own cycle.
10. How it is protected
We apply reasonable security safeguards appropriate to the sensitivity of the data, as the DPDP Act requires. In concrete terms:
- Isolation as a deployment boundary. Your instance is a separate process with a separate database on a separate volume. There is no code path in which another customer’s request reads your data, because there is no shared application serving both of you.
- A dedicated egress address. Your broker traffic leaves from an address reserved to you, which is what makes broker-side whitelisting meaningful. A shared address would mean every customer trading from the same whitelisted source.
- Encryption in transit and at rest. All traffic runs over TLS. Broker credentials and account secrets are encrypted at rest with a key held per instance.
- Credentials are never logged. Keys, secrets and tokens are excluded from application logs, error traces and telemetry.
- Access control. Passwords are stored only as one-way hashes. Administrative access to infrastructure is limited to the people who need it to operate the service, and administrative actions are logged.
- Backups you can get back. Backups are encrypted and held under the same isolation as the instance itself, and a restore can be requested.
- An order trail you can read. Every request the engine makes, every broker response and every decision in between is recorded on your instance, and the record is yours to read and export.
We hold no security certification and we do not claim one. The controls are described in more detail on the security page. No system is perfectly secure, so please use a strong unique password on your instance, keep your broker two-factor to yourself, and disconnect broker accounts you no longer use.
11. Your rights as a Data Principal
Exercise any of these by emailing [email protected] from the address registered on your account, or through the contact page. We acknowledge within 3 working days and respond substantively within 30 days of verifying who you are.
Right to access information
Ask for a summary of the personal data we hold about you, what we are doing with it, and which processors have received it. We return it in a readable format. Most of it is already yours to read: your orders, logs and strategies are on your own instance and exportable from it without asking us.
Right to correction and completion
Ask us to correct anything inaccurate, complete anything incomplete, or update anything stale. Account, billing and connection details can be corrected directly, either on the instance or by writing to us.
Right to erasure
Ask us to erase personal data that is no longer needed for the purpose it was collected for. On your instance you can do most of this yourself. Erasure across our records is subject to the statutory retention in section 9, and to backups already taken, which are not selectively edited but expire on their own schedule.
Right to withdraw consent
Where we rely on consent, you can withdraw it as easily as you gave it: delete a broker connection to stop broker-data processing, unlink your Telegram chat to stop alert delivery, or write to us. Withdrawal takes effect going forward and does not make earlier processing unlawful. Withdrawing consent for broker access necessarily stops your strategies trading that account.
Right of grievance redressal
If a request is not handled to your satisfaction, escalate to the Grievance Officer in section 16. You may complain to the Data Protection Board of India if we fail to resolve it.
Right to nominate
You may nominate another individual to exercise these rights on your behalf if you die or become incapacitated. Send the nominee’s name, relationship and contact details to [email protected] and we will record it. A nomination here covers your personal data with us only: it has no effect on the funds or securities held at your broker, which follow the broker’s own nomination process.
If you are in the EEA or the UK
We honour the equivalent GDPR rights for visitors in the European Economic Area and the United Kingdom: access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and the right to lodge a complaint with your local supervisory authority. Where we rely on a legitimate interest, it is the operation and security of a service you asked for. triStack AlgoTrader is built for Indian markets and Indian brokers, and is not offered to residents of jurisdictions where it would need a licence we do not hold.
Duties that come with these rights
The DPDP Act asks Data Principals not to file false or frivolous complaints, not to impersonate another person when providing data, and to give authentic information when exercising the right to correction. We may refuse a request that is manifestly unfounded or repetitive, and we will say why.
12. Children
triStack AlgoTrader is not for anyone under 18. You must be 18 or older to contract with us, which matches the requirement to hold a trading account with an Indian broker. We do not knowingly collect personal data from a child, we do not profile children, and we do not direct advertising at them.
If we learn that an account belongs to someone under 18, or to a person with a disability who has a lawful guardian, we will suspend it and delete the associated personal data unless a law requires us to keep a record. If you believe a child has given us personal data, write to [email protected] and we will act on it promptly.
13. Cross-border transfer
Where your instance runs is a decision, not an accident, and it is confirmed to you in writing before provisioning and recorded on your order form. Ask before you sign if the region matters to you: it is a constraint we can meet, not one we discover afterwards.
Two things can cross a border regardless, and we would rather name them than claim nothing leaves India:
- The edge network that serves this website and resolves the application hostname answers a request from whichever location is nearest the visitor, which may be outside India. It handles request metadata in flight; it does not hold your account records or your trading data.
- Telegram operates outside India. It receives an alert only where you have linked a Telegram chat to your instance, and only the chat identifier and the alert text. Unlink the chat and that transfer stops.
The DPDP Act permits transfer of personal data outside India except to countries the Central Government restricts by notification. We do not transfer personal data to any restricted territory, and if a territory becomes restricted we will move or stop that processing. Wherever data goes, the processor is bound by contract to the same confidentiality, security and purpose-limitation terms set out here.
14. Breach notification
If personal data in our care is breached, we will:
- contain the incident, preserve evidence and begin an investigation as soon as we detect it;
- notify the Indian Computer Emergency Response Team (CERT-In) within 6 hours of becoming aware, for the incident classes the CERT-In directions cover;
- notify the Data Protection Board of India and every affected Data Principal without undue delay, in the form and manner the DPDP Act and its rules prescribe;
- tell you plainly what happened, which of your data was involved, what we have done, and what you should do, such as rotating broker credentials or changing your instance password;
- publish a post-incident summary and the fixes made.
We will not quietly absorb an incident that affected you. If you suspect a security problem, write to [email protected] immediately and revoke API access at your broker’s console, which stops your instance trading at once and does not depend on us doing anything.
15. Changes to this policy
We update this policy when the product, our processors or the law changes. The current version always carries a last-updated date at the top of this page. This version is effective 23 August 2026.
For a material change, meaning one that expands what we collect, adds a purpose, adds a category of recipient, or reduces your rights, we will give notice by email to your registered address at least 14 days before it takes effect. Continuing to use triStack AlgoTrader after a change takes effect means you accept the updated policy. Where the change relies on consent, we will ask for consent again rather than assume it. Introducing the payment gateway named in section 7 is a change of exactly that kind, and it will be notified.
This policy sits alongside our Terms of Service, Refund and Cancellation Policy, Service Delivery Policy, Cookie Policy, Disclaimer and Risk Disclosure.
16. Grievance Officer
In accordance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023, the contact details of our Grievance Officer are published below. The Grievance Officer is the point of escalation for any complaint about how your personal data has been handled.
- Name
- Ashutosh Mishra
- Designation
- Grievance Officer, Tristack Technologies LLP
- [email protected]
- Address
- B-35, Vinoba Kunj Apartments, Sector 9, Rohini, Delhi 110085, India
- Hours
- Monday to Friday, 8:00 AM to 5:00 PM IST
Email is the route to the Grievance Officer, and a complaint sent to [email protected] is on the record from the moment it arrives. A complaint sent by post to the registered address above is equally valid.
Statutory response window. The Grievance Officer acknowledges every complaint within 24 hours of receipt and resolves it within 15 days, as the IT Rules, 2021 require. Data-protection requests under section 11 are answered within 30 days. Please include your registered email address, the instance or broker connection concerned, and what outcome you are asking for, so we can act without a round trip.
If we do not resolve your grievance, you may complain to the Data Protection Board of India under the DPDP Act.
Questions about this document
Write to [email protected], or reach the Grievance Officer, Ashutosh Mishra, at [email protected]. Every policy on this site is published by Tristack Technologies LLP, which operates triStack AlgoTrader and is the entity you contract with.
Registered office: B-35, Vinoba Kunj Apartments, Sector 9, Rohini, Delhi 110085, India · LLPIN ACP-3743 · GSTIN 07AAYFT2516N1ZFSee also Terms, Privacy, Cookies, Refunds, Service delivery, Disclaimer and Risk disclosure.