Effective July 1, 2026
Privacy Policy
Scope
This Privacy Policy explains how TAC handles information for its internal and invited-user site, portal, API, and brokerage OAuth connection workflows.
Information We Collect
We may collect account information such as email address, account name, role, account status, API-key metadata, and login-session identifiers. We store generated API keys only as one-way hashes after initial display.
When you connect a brokerage account, we may collect brokerage connection metadata, OAuth tokens or refresh tokens, account mode, order, position, configured-check, snapshot, and job information needed to operate enabled brokerage workflows.
We also collect technical and usage information such as endpoint, method, status code, latency, timestamp, user agent, IP address, and operational logs.
How We Use Information
We use information to authenticate users, manage accounts and API keys, provide route research and model-indication workflows, operate brokerage connections, maintain usage history, secure the application, troubleshoot issues, and comply with operational or legal obligations.
How We Share Information
We do not sell personal information. We may share information with service providers that host, authenticate, store, monitor, or support the application; with connected brokerage or OAuth providers as needed to complete authorized workflows; with internal operators; or when required for security, legal, or compliance purposes.
Brokerage OAuth Data
OAuth connection data is used to provide the brokerage-account features enabled for your account. If you disconnect a brokerage account or ask an operator to remove access, TAC will stop using that connection for future workflows, subject to reasonable retention of logs and records needed for security, audit, or legal purposes.
Security
We use reasonable administrative and technical safeguards for the application, including access controls, hashed API keys, and protected handling of OAuth tokens. No system can be guaranteed completely secure, so users should protect credentials and report suspected unauthorized access promptly.
Cookies And Local Storage
The site may use browser storage for theme preferences and authentication-session handling. We do not use advertising cookies in this internal application.
Retention
We keep information for as long as needed to provide the application, maintain security and audit records, support internal operations, comply with obligations, or resolve disputes. Access may be deactivated or deleted by a TAC operator when no longer needed.
Children
The application is not intended for children or public consumer use.
Contact
Questions or requests about privacy should be sent to the TAC administrator or operator who provisioned your account.