Privacy Policy

What personal data Qash Global collects, why we use it, who we share it with, how long we keep it, and the rights you have over it.

Version 1.0Effective 2 August 2026

1. Who is responsible for your data

Qash Global is the controller of the personal data described in this policy — we decide what is collected and why.

For any privacy question, to reach our data protection contact, or to exercise the rights in section 9, email [email protected].

2. Scope

This policy covers the personal data we handle when you visit qashglobal.com, register an account, connect a broker account, or contact our support team. It does not cover your broker, whose own privacy policy governs the data it holds about you.

3. What we collect

Account and profile data — your name, email address, password (stored only as a hash by our authentication provider), the affiliate link you registered through, and your USDT wallet address.

Identity verification data — the identity documents you upload, together with the information they contain such as your date of birth, nationality, document number and address, and the outcome of our review.

Financial and account data — the broker account number you connect, its read-only credential (encrypted), and the values and operations we observe on it: daily account values, deposits, withdrawals, fee sweeps, closed trades, settlements, claims and affiliate rebates.

Support data — messages, tickets and attachments you send us.

Technical data — IP address, browser and device information, and log records of how you use the platform, collected automatically.

We do not knowingly collect special category data. Where an identity document reveals such data incidentally, we use it only to verify your identity.

4. Where it comes from

  • directly from you, when you register, upload documents, or contact us;
  • from your broker, through the read-only access you authorise when you connect an account;
  • from our authentication provider, when you sign in — including through Google if you choose that option; and
  • automatically from your device when you use the platform.

5. Why we use it, and our legal basis

Where the GDPR or an equivalent regime applies, we rely on the following bases:

  • To create and operate your account, connect your broker account, calculate performance and settlements, and process claims — performance of our contract with you.
  • To verify your identity, screen against sanctions lists, detect fraud and meet anti-money-laundering obligations — compliance with a legal obligation, and our legitimate interest in preventing fraud.
  • To provide support and respond to your messages — performance of our contract and our legitimate interest in running the service well.
  • To keep the platform secure, diagnose faults and prevent abuse — our legitimate interest in a secure, functioning service.
  • To operate the affiliate programme, including showing an affiliate that a referred user generated settled profit — performance of our contract with both parties.
  • To send you service messages about your account, settlements and claims — performance of our contract. These are not marketing and you cannot opt out of them while you hold an account.
  • To send marketing, where we do so — your consent, which you may withdraw at any time.
  • To establish, exercise or defend legal claims and to meet accounting and record-keeping duties — our legitimate interest and compliance with a legal obligation.

Where we rely on legitimate interests we have considered whether that interest is overridden by your rights; you may object as described in section 9.

6. Who we share it with

We do not sell your personal data. We share it with:

  • Clerk — authentication and account management;
  • Railway — application hosting and database infrastructure;
  • your broker — we hold read-only access to the account you connect, and identify that account to them;
  • identity verification providers we engage to check the documents you submit;
  • professional advisers, such as auditors and lawyers, under a duty of confidence; and
  • regulators, law enforcement and courts, where we are legally required or permitted to disclose.

Our service providers act on our instructions under a written contract and may not use your data for their own purposes.

If our business is transferred, personal data may pass to the acquirer, who would remain bound by this policy until it lawfully notifies you of a change.

7. International transfers

Our service providers operate internationally, so your data may be processed outside the country where you live.

Where data leaves a jurisdiction that restricts transfers, we rely on an adequacy decision where one exists, and otherwise on standard contractual clauses together with any additional safeguards the circumstances require. You may request details of the safeguards we rely on using the contact details above.

8. How long we keep it

We keep personal data only for as long as we have a lawful reason to. In practice that means:

  • Account and profile data — while your account is open, and for a limited period afterwards so we can deal with questions, disputes or claims that arise from your use of the service.
  • Identity verification records — for the minimum period anti-money-laundering law requires after our relationship ends. This is a legal obligation, so we cannot delete these records on request before that period expires.
  • Financial, settlement and claim records — for as long as accounting and tax law requires us to keep them.
  • Support correspondence — for as long as needed to resolve your issue and to handle any follow-up or dispute arising from it.
  • Technical logs — for a short period, long enough to investigate security incidents and diagnose faults.

When a retention period ends we delete the data or irreversibly anonymise it.

9. Your rights

Subject to the conditions and exemptions in the law that applies to you, you have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected;
  • have data erased, where we no longer have a lawful reason to keep it;
  • restrict how we process your data while a dispute about it is resolved;
  • receive data you gave us in a portable, machine-readable format, and have it transmitted to another controller where technically feasible;
  • object to processing we carry out on the basis of legitimate interests, and to object at any time to direct marketing; and
  • withdraw consent, where we rely on it, without affecting processing already carried out.

To exercise any of these, email [email protected]. We will respond within one month, and will tell you if we need longer because the request is complex. We may ask you to verify your identity first. Exercising these rights is free unless a request is manifestly unfounded or excessive.

Some data cannot be deleted on request because we are legally required to retain it — identity verification records in particular. We will tell you when that applies.

You also have the right to complain to the data protection supervisory authority in the country where you live or work. We would appreciate the chance to address your concern first.

10. Cookies

We use strictly necessary cookies only. These keep you signed in, maintain your session and protect against cross-site request forgery. The platform does not function without them, so they are set without consent, as the law permits for essential cookies.

We do not currently use advertising or third-party analytics cookies. If that changes we will ask for your consent first, where consent is required, and update this policy.

11. Automated decision-making

Identity verification and fraud screening may involve automated checks. Where an automated check alone would produce a legal or similarly significant effect on you — such as refusing your account — a member of our team reviews the outcome before it is applied. You may ask for human review, express your point of view and contest a decision by contacting us.

Performance figures and settlement amounts are calculated automatically from observed broker data. These are arithmetic, not profiling, and they do not evaluate your personal characteristics.

12. Security

We protect your data with encryption in transit and at rest, encrypted storage for broker credentials, access controls limiting staff access to those who need it, and audit logging of administrative actions.

No system is perfectly secure. Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant authority within the timeframes the law requires.

13. Children

The platform is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

14. Changes to this policy

We will update this policy as the service changes. Each version carries a version number and effective date. Where a change materially affects how we use your data, we will notify you directly rather than relying on this page alone.