Data handling
Privacy policy
This policy describes the data processing visible in the current FXVeritas service and distinguishes active functions from gated or future functions.
Public file principles
These rules apply to every FXVeritas public research page. They are not a ranking.
- Research Confidence is not a safety rating.
- Regulator verified does not mean a broker is safe.
- Unknown does not mean unsafe. Unverified does not mean fraudulent. Unregulated does not automatically mean a scam.
- Protection unknown does not mean no.
- Commercial or affiliate relationships do not change research labels, verification status, Research Confidence, or editorial conclusions.
- FXVeritas does not recommend a broker because data has been verified.
Scope
FXVeritas provides public research pages, optional account authentication and first-party community review features. No database-backed contact form is provided in this release.
The legally required public identity of the controller and the applicable privacy-law framework remain subject to human legal review and are not invented here.
Data processed by current features
Supabase authentication may process an email address, authentication identifiers and session information when a user signs in. Authentication uses session cookies.
A signed-in user may submit a broker review, ratings and review text. The service stores the user reference, broker reference, moderation state and email-verification state needed to operate and moderate that feature.
FXVeritas does not currently provide a public contact-upload workflow. Users should not send passwords, payment credentials, client lists or unnecessary sensitive information.
Analytics and outbound-event measurement
FXVeritas does not currently represent general analytics or outbound-click measurement as active. The codebase contains a gated product-event foundation that does nothing unless explicitly enabled.
If enabled after privacy approval, the intended record is limited to an event name, research or commercial stream, broker or placement reference, locale, surface and event time. The application contract does not intentionally store a user ID, email address, full destination URL, persistent advertising identifier, IP address or user-agent string.
Infrastructure and service providers
FXVeritas uses Vercel for website hosting and delivery, and Supabase for database and authentication functions. These providers may process network, device, security and service-log information under their own operational controls.
Google Workspace is the current email provider. The verified public contact address is brokers@fxveritas.com.
Retention and publication
Account, review, moderation, security and public-record data may require different retention periods. Final periods and any jurisdiction-specific legal bases remain under human legal review.
A submitted statement is not automatically verified or published. Personal, confidential or irrelevant information should not be published merely because it was submitted.
Rights, security and contact
Depending on applicable law, individuals may have rights relating to access, correction, deletion, restriction, objection or portability. Privacy and data-rights enquiries can be sent to brokers@fxveritas.com.
Service providers may process data in more than one country. Transfer mechanisms, supervisory-authority wording, minimum age, detailed retention and controller disclosures require human legal review. No system can guarantee absolute security.