Jockey

Jockey legal

Privacy Notice

What Jockey is designed to collect, why it is used, and the controls around it.

Pre-launch counsel draftEffective September 1, 2026 · Version 0.5

This document is a product safeguard and disclosure draft. It is not final legal clearance and does not enable public access or real-money execution.

01

Pre-launch status

This Privacy Notice describes the intended data practices for Jockey’s private first-party desk. It must be reviewed against the final entity, vendors, hosting region, customer locations, and regulatory role before public launch. Jockey currently has no public customer database and no payment processor.

02

Data we may process

  • Account and contact information you provide, including name, business contact details, age and eligibility attestations, consent records, and support communications.
  • Agent and security information, including hashed access-code material, permissions, authentication events, device or network metadata, IP address, and audit records.
  • Venue-connection status and evidence. Jockey is designed so venue passwords, private signing keys, passkeys, and long-lived secrets remain outside prompts and ordinary application records.
  • Trade instructions and operational records, including canonical market identifiers, side, size, limit, approvals, route, venue references, fills, cancellations, errors, positions, balances, fees, reconciliation evidence, and P&L.
  • Technical and usage data, including browser information, timestamps, logs, reliability measurements, and security incidents. The public landing page is designed without advertising trackers.
03

Why we process data

  • Provide, secure, troubleshoot, and improve Jockey; authenticate authorized users and agents; enforce limits and geography; route and reconcile instructions; produce receipts and audit evidence; prevent fraud and abuse; support recovery and legal compliance; and communicate about the service.
  • We do not sell personal information or use trade records for behavioral advertising. If that changes, this notice and any required choices must change before the practice begins.
04

How data may be shared

  • With a connected venue or service provider only as needed to perform an instruction you authorized or operate Jockey under contract.
  • With professional advisers, auditors, insurers, regulators, law enforcement, or courts when reasonably necessary and legally permitted or required.
  • In a corporate transaction subject to appropriate confidentiality and notice obligations.
  • Jockey does not authorize a software agent to export personal or financial data merely because the agent can submit a trade request.
05

Service providers and data inventory

Before public launch, Jockey must publish or make available an accurate list of material hosting, authentication, communications, observability, support, and backup providers; the categories of data each receives; processing locations; retention periods; and the contractual safeguards in place. A provider must not be added merely because its SDK is convenient. Jockey must first document purpose, minimize fields, restrict access, and verify deletion and incident obligations.

06

Retention and deletion

Jockey should keep personal data only as long as needed for the stated purpose, security, dispute handling, tax, audit, venue, and legal obligations. Trade, consent, security, and immutable audit records may require longer retention than ordinary support data. Final schedules and deletion exceptions must be approved by counsel before launch. Backups expire through documented retention cycles; deletion from active systems may not immediately remove an encrypted backup copy.

07

Security

Jockey uses least-privilege access, scoped agent keys, encryption boundaries, integrity-checked audit records, restricted logs, backups, recovery testing, maintenance stops, and fail-closed execution gates. No system is completely secure. If an incident creates a legally required notice obligation, Jockey will follow the applicable notice process after confirming the responsible entity and affected data.

08

Incident response and account notice

Jockey must maintain a written incident plan covering containment, evidence preservation, credential rotation, provider coordination, legal assessment, customer and regulator notice, recovery, and post-incident review. A public security contact and a non-email recovery path must exist before live use. Notice timing and content depend on applicable law; this draft does not promise a deadline that may be inaccurate for a future entity or jurisdiction.

09

Cookies and similar technology

The intended public site uses only technology necessary for security, session continuity, preferences, and core operation. It does not currently use behavioral advertising cookies or cross-site tracking. Before any nonessential analytics or advertising technology is added, Jockey must update this notice, inventory the vendor and data flow, and provide consent or opt-out controls where required.

10

Precise location and identity evidence

Actual-location and identity evidence can be sensitive. Jockey should request it only when needed to enforce a venue, legal, security, or account rule; should prefer a pass/fail or coarse result over retaining precise coordinates or identity images; and must document the provider, purpose, retention, access, and deletion rules before collection. Jockey must not sell precise location data or use it for advertising. A failed or unavailable check stops the affected route rather than inviting an evasion workaround.

11

Children and age-restricted use

Jockey is not directed to children and is not intended for anyone under 21. Jockey must not knowingly collect a child's information or permit a child to connect or control a venue account. If Jockey learns that age-restricted access or child data may be involved, it may suspend access, preserve only what law and safety require, and follow a verified deletion and escalation process.

12

International access and transfers

The shipping product is not offered for international use. Before serving another country or transferring personal data across borders, Jockey must identify the responsible entity, legal bases, transfer mechanism, localization rules, data-subject rights, government-access risks, subprocessors, and a local contact or representative where required. A website being reachable does not mean the service is offered in that country.

13

Automated decisions and agents

Software agents may propose or transmit instructions within limits you establish, but the shipping product does not use personal data to make decisions that produce legal or similarly significant effects about eligibility, credit, employment, housing, or insurance. Venue identity, location, eligibility, fraud, and order decisions are controlled by the relevant venue. Jockey must document any future material automated-decision use before enabling it.

14

Privacy requests and appeals

  • Depending on applicable law, you may request access, correction, deletion, portability, restriction, or an appeal, and may opt out of certain sale, sharing, targeted advertising, or profiling practices if they ever occur.
  • Jockey will verify requests proportionately, respond within applicable time limits, and will not discriminate for exercising a privacy right. An authorized agent may be required to prove authority.
  • Some information cannot be deleted while reasonably needed for security, fraud prevention, dispute resolution, tax, financial, audit, or other legal obligations. Jockey will explain an applicable exception where required.
15

Legal holds and government requests

Jockey may preserve information subject to a subpoena, court order, investigation, dispute, or other valid legal hold even when an ordinary retention period or deletion request would otherwise apply. Jockey should review government requests for legal validity and scope, disclose only what is required, document the response, and notify the affected person when lawful and appropriate. This notice does not promise notice where law prohibits it or an emergency makes it inappropriate.

16

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to appeal a denied request. You may withdraw optional electronic-delivery consent, but some records may still be retained or delivered as required by law. Requests may be sent to privacy@jockey.to after the mailbox is operational. Jockey will verify the requester before disclosing account data.

17

No sale, sharing, or targeted advertising

Jockey's intended launch posture is not to sell personal information, share it for cross-context behavioral advertising, use sensitive financial activity for targeted advertising, or exchange it for data-broker enrichment. If a future practice falls within a legal definition of sale or sharing, Jockey must update this notice and provide the required notice and opt-out mechanism before the practice begins. Jockey will honor legally required browser-based opt-out preference signals where applicable.

18

Children, transfers, and changes

Jockey is not for anyone under 21 and is not directed to children. Data may be processed where Jockey and its contracted providers operate, subject to applicable transfer safeguards. Material changes will receive a new version and effective date; changes that require consent will not be treated as accepted merely because a person visited the site.

19

Sources, sensitive data, and inferences

Jockey may receive data directly from you, your authorized agents, connected venues, security and hosting providers, and records generated by your use. Account, transaction, precise-location, identity, and authentication data may be sensitive under applicable law. Jockey should not infer interests or build advertising profiles from trading activity, and must not use sensitive data for a new incompatible purpose without the notice and choice required by law.

20

Deidentified data and legal process

Jockey may use aggregated or deidentified operational information to measure reliability and improve safety only when it takes reasonable steps to prevent reidentification and does not attempt to reidentify it. Jockey will review legal demands for validity, seek to narrow overbroad demands where appropriate, disclose only what is required, and notify the affected person when legally permitted and operationally safe.

21

Account closure and data export

Before live launch, Jockey must provide a documented account-closure path and, where required, a usable export of account and instruction records. Closing Jockey does not close a connected venue account, cancel venue orders, liquidate positions, withdraw funds, erase venue records, or override legally required retention. The closure flow must explain those consequences before confirmation.