Dernière mise à jour le 17 août 2026
01 Scope and who is responsible
This policy explains what personal data EdgeMarket collects, why, for how long, who else sees it, and what you can do about it. It covers edgemarket.co, the EdgeMarket application, and the EdgeMarket browser extension. It does not cover third-party sites we link to, nor the trading venues you use — they have their own policies.
- Controller
- Yando Pte. Ltd., a private limited company incorporated in Singapore, operator of EdgeMarket.
- Registration number
- UEN 202018750D (Accounting and Corporate Regulatory Authority, Singapore).
- Registered office
- 68 Circular Road, Singapore 049422.
- Contact
- support@edgemarket.co.
- Representative in the EU
- EdgeMarket has no establishment in the EU or the EEA and has not designated a representative there. Article 27(2)(a) of the GDPR does not require one where the processing is occasional, does not involve special categories of data on a large scale, and is unlikely to result in a risk to people’s rights. The only identifying data we collect is an email address; payment data never reaches us. If the scale of our European use changes, we will designate a representative and name them here.
- Representative in the UK
- None designated, for the same reason and under the equivalent exemption in the UK GDPR.
- Data protection officer
- None is required. EdgeMarket is not a public body, it does not monitor people on a large scale, and it processes no special categories of data. Privacy requests go to the contact address above.
- Applicable regimes
- Singapore law governs the service, and the Personal Data Protection Act 2012 (PDPA) is our home regime. The GDPR and the UK GDPR also apply to us, and this policy is written to meet them. If you live in a US state with its own privacy law, we honour the rights it gives you whether or not its thresholds are met.
Why European law binds a Singapore company: the GDPR follows the people it protects, not the address of the company. We publish the site in thirteen languages, several of them European, and we take payment from customers in Europe — so we offer a service to people in the EU, and their law applies to us. The United Kingdom works the same way.
This policy is published in English, and the English text is the one that binds.
02 What we collect
Account data
What is needed to open and secure an account: your email address, a password stored as a hash and never in clear text, your interface language, the date the account was created, and the plan you are on.
What you tell us when you sign up
The onboarding answers: the trading experience you declare, how you came to the site, and the markets you follow. They shape what you see first, and nothing else.
How you use the product
Your watchlists, the alerts you configure, and your display preferences. If you arrived through a referral link, we also store the referral code that brought you.
Billing data
Payments run through Stripe. Card details are entered on Stripe infrastructure: no full card number ever passes through EdgeMarket, and none is stored by us. From Stripe we receive and keep what is needed to run a subscription and to keep our books — the Stripe customer and subscription identifiers, the last four digits and the brand of the card, the billing country, and the invoice and payment history.
Technical logs
Like any service exposed on the internet, EdgeMarket produces logs: IP address, date and time, requested URL, HTTP status, user agent, and error traces. They are generated by Cloudflare in front of the service and by our servers at OVH. They exist for security, abuse prevention and debugging — not to profile you.
Audience measurement
Measurement works in three states, and the difference between them is what gets stored on your device. Before you answer, Google Analytics 4 runs in a mode that writes nothing at all — no cookie, no identifier, nothing that can recognise you on a later visit — and reports page views and the events below without them. Accept, and the same tool is allowed to set the cookies listed further down, and Google Ads is switched on. Refuse, and both stop completely: nothing is loaded and nothing is sent. What is collected in the first two states: the pages you open and the order you open them in, the events listed below, an approximate location derived from your IP address, and the type of device and browser. Google assigns your browser an identifier stored in a cookie; it is not linked to your account, and we do not send Google your email address, your account identifier, or any wallet address you look up. Google Ads goes one step further than measurement: it also adds your browser to the advertising audiences Google builds for our campaigns, which is how an advertisement can follow you to another site. That is part of what you are agreeing to, and it is the reason the question is asked before anything loads.
The events we record are a closed list, and it is short: choosing a plan, opening a payment, a payment being refused and why, creating an account, signing in, opening a screen of the dashboard, a chart read completing, opening an operator record, adding an address to a watchlist, configuring an alert, and seeing or clicking a locked block. They carry the plan you are on — one of three categories, not an identity — and never the content you were looking at. The address bar is sent without its query string, so a session token, a chosen plan or a wallet address never reaches Google.
Say no and none of this happens: nothing is loaded, no request is sent to Google, and no cookie is written. Say nothing and the difference is narrower than it sounds — audience measurement runs, but in a state where **no cookie and no identifier is created**, so the counts are of visits rather than of people, and Google Ads stays off entirely. The site behaves identically in all three cases: nothing is withheld and nothing is degraded because you declined.
What you look up
Public identifiers you submit — a wallet address, a market, a ticker — are processed to run the query and may appear in logs. They are public on-chain or public market data; we do not try to attach a real-world identity to them, and we do not ask you to prove that an address is yours.
Support correspondence
What you write to us, and what we reply, kept so that we can follow up and so that we can prove what was agreed.
What we never ask for
We never ask for a private key, a seed phrase, or an exchange API key with trading or withdrawal permission. EdgeMarket executes no orders and holds no funds; it has no use for those secrets. Anyone asking you for them in our name is not us. No feature asks for an exchange key of any kind today, read-only included; if one ever does, this policy will say so before it ships.
03 Why we process it, and on what legal basis
- Providing the service
- Opening your account, delivering the plan you subscribed to, sending service messages. Basis: performance of the contract.
- Billing and accounting
- Taking payment, issuing invoices, keeping the records the law requires. Basis: performance of the contract and legal obligation.
- Security and abuse prevention
- Detecting intrusion attempts, scraping, credential sharing and payment fraud; applying rate limits. Basis: legitimate interest in keeping the service usable and in enforcing the data use limits.
- Support
- Answering your questions and keeping a trace of the exchange. Basis: performance of the contract and legitimate interest.
- Improving the product
- Understanding which pages and features are used, and which are never opened. Basis: for the cookieless state that runs before you answer, our legitimate interest in knowing which pages are used — it places nothing on your device, which is what would otherwise require your permission. For the cookies and for Google Ads, your consent, asked for before either is enabled and withdrawable at any time from the link in the footer. Withdrawing stops the measurement from the next page onward; it does not erase what was already sent, which you can ask Google to delete under the section on your rights.
- Commercial messages
- Newsletters and product announcements go out only if you opt in. Basis: consent, which you can withdraw at any time — every message carries an unsubscribe link, and withdrawing stops the next one. Service messages are a different thing: invoices, security notices and changes to these documents are part of the contract, they are not marketing, and they continue for as long as the account exists.
- Legal claims
- Establishing, exercising or defending a legal claim. Basis: legitimate interest.
We do not sell personal data, and we do not carry out automated decision-making producing legal effects concerning you. The rankings and scores EdgeMarket publishes are measurements of public market activity, not evaluations of our users.
04 How long we keep it
The principle: each category is kept for as long as the purpose that justified collecting it requires, then deleted or anonymised. In practice:
- Account data and preferences
- Kept while the account is open, then for 90 days after the account is closed, so that you can come back without starting over. After that, deleted or anonymised. Ending a paid subscription does not close the account and does not start this clock — see the refund and cancellation policy.
- Invoices and accounting records
- 5 years. Required by the Singapore Companies Act (section 199) and by the GST Act.
- Technical logs
- 90 days — the window we need to investigate an incident, at Cloudflare as on the OVH infrastructure.
- Support correspondence
- 24 months, so that a dispute can be followed through.
- Audience measurement
- Before you accept, the events carry no browser identifier, so there is nothing for Google to attach to you and nothing to keep beyond its own aggregate reporting. Once you accept, Google Analytics keeps the event and user data attached to your browser identifier for the retention period set on the property — two or fourteen months on a standard property — and deletes it automatically once that period is reached, on a monthly cycle. Age, gender and interest data are capped at two months whatever that setting says. Your answer to the consent question is kept by us for 6 months, then asked again.
Deleting your account does not delete the accounting records attached to it: we are required to keep those for the five years above, and we keep nothing beyond them.
05 Who else processes it
We use a small number of processors. Each acts on our instructions, for the purpose stated, and nothing more. The list below covers every processor in place today; the entries still marked in red are contractual details being confirmed, not additional recipients.
- Stripe
- Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, United States. Payment processing, subscription management, invoicing, tax calculation and payment fraud prevention.
- Cloudflare
- Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94103, United States. Serving and caching the site, TLS termination, filtering of attacks and abusive traffic.
- OVH
- OVH SAS, 2 rue Kellermann, 59100 Roubaix, France. Hosting of the application and of the database it writes to.
- Telegram
- Telegram FZ-LLC, Dubai, United Arab Emirates. Only if you turn on Telegram alerts, and only to deliver the alerts you asked for. Turn them off and nothing further is sent.
The payment contract for this account is with Stripe Payments Singapore Pte. Ltd. Stripe, Inc. remains involved as part of the same group for the processing described above.
Transactional email — password resets and account messages — is sent through Cloudflare Email Sending, operated by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94103, United States. Cloudflare processes the recipient address and the content of those messages in order to deliver them. Transfers outside the EEA and the UK rely on the European Commission’s standard contractual clauses and the UK addendum, the same as for the delivery and network protection described above. We do not send marketing email.
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States, process the data described above — through Google Analytics 4 from your first page, without any identifier until you accept, and through Google Ads only if you do. Refuse, and no data reaches them by this route.
Signing in with Google is offered. If you use it, Google Ireland Limited and Google LLC process your Google account identifier and the email address attached to it, so that we can create or recognise your account. Choosing an email and password instead avoids this entirely.
Beyond those processors, we disclose data only where the law requires it — to a competent authority acting through the proper channel — or where it is necessary to establish or defend a legal claim. If the business is transferred, data may pass to the acquirer, subject to this policy.
06 Transfers outside the EU/EEA
The application and its database are hosted in France, at OVH. But EdgeMarket is operated from Singapore, and some of our processors run international infrastructure — so your data may be processed in a country whose law does not offer the same level of protection as EU law.
Where data protected by the GDPR leaves the EU/EEA, the transfer rests on the European Commission’s standard contractual clauses (implementing decision 2021/914). That is the mechanism in place for Stripe and for Cloudflare, both established in the United States, and for Google where you have consented to measurement. For data protected by the UK GDPR, the same clauses apply together with the UK addendum.
Ask us at support@edgemarket.co and we will send you a copy of the safeguards in place.
07 Your rights, and how to use them
Subject to the conditions of the applicable law, you have the right to:
- access the personal data we hold about you, and obtain a copy;
- have inaccurate data corrected;
- have data erased where we no longer have a valid reason to keep it;
- receive the data you provided in a structured, machine-readable format, and have it sent to another controller where technically feasible (portability);
- ask us to restrict processing while a request is being examined;
- object to processing based on legitimate interest, on grounds relating to your situation;
- withdraw consent at any time, where processing rests on consent — without affecting what was done before;
- lodge a complaint with a supervisory authority.
To exercise any of them, write to support@edgemarket.co from the email address on the account. We may ask for what is strictly necessary to confirm it is you — the point of that check is to protect your data, not to slow the request down. We answer within 30 days. If a request is genuinely complex we may take up to two further months, and we will tell you so, with the reason, within the first month.
If our answer does not satisfy you, you can complain to a supervisory authority:
- Singapore
- Personal Data Protection Commission (PDPC), the authority for the PDPA.
- EU and EEA
- The supervisory authority of the country where you live, where you work, or where the problem happened.
- United Kingdom
- Information Commissioner’s Office (ICO).
09 The browser extension
The EdgeMarket browser extension displays a panel on the Polymarket page showing our five-minute signals, recent large trades and market positioning. It is optional, and everything below applies only if you install it.
What it stores
One item: the widget token you paste into it, kept in the browser's local extension storage on that machine. It is an authorization credential, not a record of what you do. It is never placed in Chrome's sync storage, so it is not replicated to your other devices or to Google. Clearing it in the extension removes it.
What it sends, and where
The extension contacts one host: api.edgemarket.co. It requests the current slot, the recent large-trade flow and market positioning, and sends your widget token as an authorization header so the response matches your plan. No browsing history, no page content, and no personal data are transmitted.
It does not read or modify the Polymarket page. The panel is appended to the document and operates on its own; no page content is inspected, collected or sent anywhere.
Permissions, and why each one exists
- Storage
- Keeps your widget token on this machine. Nothing else is stored.
- Active tab and scripting
- Used only when you click “Pin to this page”, to place the panel on the tab you are viewing. No access is taken without that click.
- Tabs
- Reads only the address of the active tab, to tell you whether the panel can be pinned there. Internal browser pages cannot host it.
- api.edgemarket.co
- Our own service. It is the only host the extension is permitted to contact.
- polymarket.com
- Where the panel is displayed automatically.
- All sites (optional)
- Off by default. If you switch on “Show on every site”, your browser asks you to grant it, and turning the setting off removes the permission again. We never request it at install time.
What it does not do
- It places no trades and asks for no exchange API key.
- It connects to no wallet and never holds funds.
- It contains no analytics, no tracking pixel and no third-party script.
- It loads no code at runtime — everything it executes ships inside the extension package.
10 Security
Below is what is actually in place. We list nothing else: a security claim in a privacy policy is a commitment, and an unverified one is worse than saying nothing.
- all connections are served over TLS, terminated at Cloudflare;
- passwords are stored as bcrypt hashes with a per-password salt, never in clear text;
- API keys are stored the same way, and are shown once at creation and never again;
- no card data reaches us — payment is isolated at Stripe;
- the database is not exposed publicly — it listens on the local interface only — and the application reaches it through a dedicated, non-superuser account, over an encrypted connection;
- the production database is dumped daily by a scheduled job.
No system is invulnerable, and we would rather say so than publish a promise we cannot keep.
If a breach affects your personal data, we notify the Personal Data Protection Commission within 3 calendar days of establishing that the breach is notifiable, and the competent European supervisory authority within 72 hours of becoming aware of it. Where the breach is likely to put you at high risk, we tell you directly, without undue delay, in plain terms.
If you believe you have found a vulnerability, write to support@edgemarket.co before disclosing it publicly.
11 Minors
EdgeMarket is for adults: you must be at least 18 to open an account, the same condition as in the terms of service. We do not knowingly collect data about minors. If you believe a minor has created an account, write to us and we will delete it.
12 Changes to this policy
This policy will change as the service does — in particular when audience measurement or transactional email are wired in. The date at the top of the page is the date of the version in force.
For a change that materially affects your rights, we email account holders and show a notice in the product 30 days before it takes effect. Minor corrections take effect on publication.
13 Contact
Any question about this policy, or any request concerning your data: support@edgemarket.co. The contractual framework is set out in the terms of service.