Governing document
ORDANE Privacy Policy
One of four. The Rulebook governs the account. The Terms of Service govern the relationship. The Refund Policy governs the fee. This document governs your data.
Status: in force since 2026-08-04. This policy governs the handling of personal data from that date. Ordane Instant Accounts are on sale, so the checkout described below is live and the data it collects is collected today, not one day.
This policy describes what the site does today, checked line by line against the code that runs it. Where a system does not exist yet, this document says so and names it as pending. It does not describe a data flow Ordane has not built. Changes produce a new version with a dated entry in the changelog at §13.
§1What this document is
- PV-1. A privacy policy is usually a description of what a company would like to be allowed to do. This one is a description of what happens. Every claim below was written against the site's own source: the pages, the browser script, and the seven server functions behind them.
- PV-2. Most of this document is about what Ordane does not collect. That is not modesty. It is the shortest honest version, and you can verify the largest claims in it yourself in under a minute. §4 tells you how.
- PV-3. Where a processor, a provider, or a platform is not chosen yet, this document leaves a visible gap rather than a comfortable sentence. The gaps block publication until they are filled.
§2Who is responsible for your data
- PV-4. The controller is Ordane Markets Ltd. The jurisdiction of incorporation, registration number and registered address are not specified in this version.
- PV-5. This version does not identify an appointed representative for readers in the European Union or the United Kingdom. Where a representative is required, their identity and contact details must be published here.
- PV-6. Contact for everything in this document, including every request under §10: [email protected]. One address, monitored, no form to fill in.
§3What we collect, and when
Four moments. Nothing is collected outside them.
| Moment | What is collected | Where it is held |
|---|---|---|
| You join the launch list | Your email address and the time you signed up. Nothing else. | Our host |
| You start a checkout | Full name, email address, country, phone number, and a discount code if you enter one. | Our host |
| You pay | The receiving address generated for your order, the transaction id, the amount received, the order id, the price, and the timestamps. | Our host, and the public ledger of whichever network you pay on. See §7. |
| You request your first withdrawal | Identity verification documents. Once. See §8. | Pending, see §8 |
- PV-7. Visiting a page also produces the ordinary request data every web server receives: your IP address, your browser type, the page, and the time. Our host handles it. We run nothing on top of it. See §4.
- PV-8. We do not collect a mailing address, a date of birth, a tax number, or a card number, because we never ask for them. Open the checkout page and count the fields: there are four, plus an optional code.
- PV-9. We never receive card details. There is no card rail. Payment is made in cryptocurrency, thirteen ways in total: USDT on TRON, Ethereum, BNB Chain, or Solana; USDC on Ethereum, BNB Chain, or Solana; or directly in BTC, ETH, SOL, TRX, BNB, or DOGE. USDT on TRON (TRC-20) is the recommended default. Whichever one you pick, a card number has nowhere to go.
- PV-10. Two different things, and only one of them records anything. The Trader Area demonstration runs entirely in your own browser: no login, nothing stored on our side, and prices generated rather than taken from a market. Close the tab and nothing of it remains, here or there. A purchased account is separate: it runs on the platform named in Terms of Service clause T-29, and that platform records account activity, orders, positions, balances, and the login metadata required to operate and audit a simulated account. Ordane reads that data to apply the published rules in the Rulebook and to answer a dispute about them, and for nothing else.
§4Cookies, analytics, and local storage
- PV-11. Ordane sets no first-party cookies. The only cookies on this site come from Google Analytics and Microsoft Clarity, and only if you accept the analytics banner. If you decline, or dismiss the banner without accepting, no analytics cookies are set.
- PV-12. Ordane counts its own traffic, and stores nothing on your device to do it. Every page view is counted by Ordane's own measurement, which runs on ordanemarkets.com and sends nothing to anyone else. It writes no cookie and keeps no identifier in your browser. To join the pages of one visit, our server computes a one-way hash of four things: a secret that changes every day, your IP address, your browser's user agent, and our own domain. Your IP address is used inside that calculation and discarded in the same instant; it is never written to storage. Because the daily secret is replaced every day, the link between your page views expires within twenty-four hours and cannot be rebuilt afterwards, by us or by anyone else. What is recorded: the page, the language, the site that referred you, the campaign tag if your link carried one, whether the device is a phone or a computer, and the country your network resolves to. What is not recorded: what you type, where you click, how far you scroll, your session as video, and anything that identifies you as a person.
- PV-12a. Google Analytics 4 runs only with your consent, and only to count page views and referrers. If you decline the banner, or dismiss it without accepting, it never loads at all.
- PV-12b. What Ordane does not run, at all: Google Tag Manager, Meta Pixel, any advertising pixel, Plausible, Hotjar, A/B testing, and any tag management server. Session recording and heatmaps run only through Microsoft Clarity, named in PV-12c, and only after you accept. Nothing here builds an advertising profile of you and nothing here follows you to another website.
- PV-12c. Microsoft Clarity runs only with your consent. It loads only after you accept the analytics banner. It records clicks, scroll depth, and a replay of the visit so Ordane can see where the site fails. It writes the first-party cookies
_clckand_clskon your device. Name, email, and phone fields on checkout are masked and are not sent as readable text. Clarity is not wired to ads. Microsoft Corporation processes this data. If you decline, or dismiss the banner without accepting, Clarity never loads. - PV-13. You do not have to believe any of it. Open your browser's developer tools on any page of this site, go to Application, and read Cookies and Storage. It takes about thirty seconds. If you have not accepted analytics, the cookie list should be empty except for anything your browser adds on its own. Then open the Network tab and reload: the only measurement request you will see is one short call to
/api/pulse, on this site's own domain, carrying the page address and nothing about you. If you have accepted analytics, you will also see requests to Google and to clarity.ms. - PV-14. One key may be written in your own browser.
ord_analytics_consent_v2holds your answer to the analytics banner:grantedordenied. It holds no identifier, it is never sent to us, and clearing your browser data deletes it. - PV-15. The analytics banner appears on your first visit until you choose Accept or Decline. That choice is stored in
ord_analytics_consent_v2and is not sent to our servers. If we add any other cookie or tracker, the banner and this section will be updated in the same release.
§5Who receives your data
- PV-16. Our host. The site, the launch list, and the order records run on Cloudflare (Pages, Workers, and Workers KV). Cloudflare processes this data on our instructions and for no purpose of its own.
- PV-16a. Microsoft Clarity. After you accept the analytics banner, Microsoft Corporation receives click, scroll, and session-replay data from that visit. Microsoft's privacy statement is published at https://www.microsoft.com/privacy/privacystatement. If you decline, nothing is sent to Microsoft Clarity.
- PV-17. The payment processor, which receives none of it. We ask a third-party crypto payment processor to generate a receiving address for your order. What leaves our server is our API key, the wallet address to forward to, and the address it should call back. Your name, your email, your phone number, and your country are never sent to it. Its name will be published in this clause before the first account is sold: BlockBee (Blockbee Inc., Republic of Panama)
- PV-18. The identity verification provider, once, at your first withdrawal. Not chosen yet. See §8.
- PV-19. Ordane's typefaces are self-hosted. Font files are served from
ordanemarkets.com, so loading them does not send your IP address or browser type to a font provider. Google Analytics and Microsoft Clarity are separate and still receive data only if you accept analytics. - PV-20. Legal authorities, where a law, a regulator, or a court order requires it, including anti-money-laundering obligations. Where we are permitted to tell you, we tell you.
- PV-21. There is no corporate group. Ordane has no parent, no affiliates, and no sister companies, so no data is shared with one.
- PV-22. We do not sell, rent, or trade personal data. We run no advertising and we build no profiles for it. Google Analytics counts aggregate traffic only. Microsoft Clarity records on-page behaviour. Neither is wired to ads.
§6Automated decisions
- PV-23. One automatic decision exists, and it is the only one. Ordane decides automatically whether a published rule in the Rulebook was breached. Nothing else about an account is decided by a machine: not who may open one, not who is paid, not who is refused. Those rules are numbered, public, and identical for every account, and a breach names the rule, the price and the instant it happened.
- PV-24. A denial has to cite the exact rule by section number, in writing, under G-0. A decision you cannot read is not a decision Ordane is allowed to make.
- PV-25. You can ask a person to review any automatic decision by writing to [email protected]. You get a written answer inside the same deadline as §10.
§7Payments happen on a public ledger
Neither of the documents this policy was drafted against mentions this. It is the single largest privacy fact about paying for an Ordane account, so it gets its own section.
- PV-26. Payment is made in cryptocurrency, on whichever of the networks named in PV-9 you choose. Every one of those networks is a public ledger. The address generated for your order, the amount, the time, and the wallet you paid from are public, permanent, and readable by anyone, with or without Ordane.
- PV-27. We store the receiving address and the transaction id alongside your order, which links your wallet to your name and email in our records. Nobody outside Ordane can make that link from the chain alone. Anyone who already knows your wallet address, by any other route, can see the payment.
- PV-28. We cannot delete anything from a blockchain, and neither can anyone else. Your erasure right reaches what we hold. It cannot reach the ledger. §10 states that limit rather than leaving you to discover it.
- PV-29. If that matters to you, pay from a wallet you do not use for anything else. We would rather tell you before you pay than explain it afterwards.
§8The identity check
- PV-30. Identity verification happens once, at your first withdrawal request. Not at purchase. Not again at every payout. There are no re-verification loops, with one bounded exception: Terms clause T-11 allows a second check only where a legal obligation requires it, named to you in writing, and that second check is still capped by Rulebook clause G-2 like any other review.
- PV-31. The review is bounded by G-2 in the Rulebook, which caps a documented review and states exactly what happens when the cap passes. This document does not restate that deadline: G-2 is its one home, and a number published twice is a number that drifts.
- PV-32. The provider that will run the check is not chosen. Its name, the documents it asks for, where it holds them, and how long it holds them will be published in this clause before the first withdrawal request can be made: not chosen at version 1.0
- PV-33. We do not buy information about you. No data brokers, no enrichment services, no background profiles assembled without your knowledge. What we know about you is what you gave us and what the payment left on the ledger.
§9How long it is kept
- PV-34. The truth as of this version: nothing expires on its own. The launch-list record and the order record are written without an expiry, and no process deletes them today. We write that down instead of claiming data is "securely deleted", because a promise the code does not keep is worse than an inconvenient fact.
- PV-35. A retention schedule, one line per record type with a real number of months against each, will be published in this clause before the first account is sold. The expiry will be set on the record itself, so deletion happens whether or not anyone remembers: not published at version 1.0
- PV-36. Until then, deletion happens when you ask. See §10. We keep only what a legal obligation requires us to keep, for as long as it requires, and we tell you which obligation.
- PV-37. The launch list is one email address and one timestamp. One message to [email protected] deletes it, and there is nothing else attached to it to delete.
§10Your rights, and how to use them
- PV-38. You can ask us to: confirm whether we hold data about you; give you a copy; correct it; delete it; export it in a machine-readable file; restrict or object to a use; or withdraw a consent you gave.
- PV-39. Write to [email protected]. We answer within 15 days. Not "a reasonable timeframe": fifteen days. If a request is genuinely complex and needs longer, we tell you inside those same fifteen days, say why, and give you a date.
- PV-40. No fee, no form, no account required, and no obligation to explain why you are asking.
- PV-41. We may ask you to confirm the email address the record sits under. We will not demand an identity document to exercise a privacy right, with one exception: a request for a copy of verification documents themselves, where handing them to the wrong person is the harm.
- PV-42. Two limits, stated plainly rather than discovered later: we cannot erase a blockchain transaction (§7), and we must keep what a law requires us to keep. Where we refuse part of a request, we say which part and why, in writing.
- PV-43. You can complain to the data protection authority where you live. In Brazil that is the ANPD. Nothing in this document requires you to come to us first, and nothing here waives that route.
§11How it is protected
- PV-44. Every page is served over HTTPS. There is no unencrypted version of any page on this site.
- PV-45. Prices are decided on our server, never in your browser. Editing the page cannot change what you are charged, and no price is trusted from the client.
- PV-46. Keys and secrets live in the host's environment, never in the code and never in a page. No key is ever sent to your browser.
- PV-47. The launch-list form carries a hidden field no human can see. Automated submissions that fill it are discarded and stored nowhere.
- PV-48. What this section does not say: that a breach is impossible, and that we are excused in advance for one. If a breach affects your data we will tell you and the authority, as the law requires, with what happened and what we did about it.
§12Where the data sits, and links out
- PV-49. Our host runs a global network and serves the site from the location closest to you, which means data may be processed outside the country you live in. The legal basis for those transfers is not specified in version 1.0.
- PV-50. The self-hosted font requests described in PV-19 stay on
ordanemarkets.com. Our host's global network may still serve those files from infrastructure outside your country, as described in PV-49. - PV-51. This site links out to third parties, including regulators and news sources cited on the Why Ordane exists page. Those sites have their own policies and we do not control them.
- PV-52. Ordane does not knowingly collect data from children. The minimum age to hold an account is set in the Terms of Service.
§13Changes, and the version that applies to you
- PV-53. A change produces a new version number and a dated line in the changelog below. Nothing changes silently.
- PV-54. "Your continued use is acceptance" is not used here. A change that materially widens what we do with your data is sent to the email address on your account before it takes effect.
- PV-55. Superseded versions stay published, so you can read what changed instead of taking our word for it.
- PV-56. This document, like the Terms of Service and the Refund Policy, exists in English only, and Ordane does not machine-translate any of these three and present the output as binding. The Rulebook is different, and Terms clause T-6 says so rather than leaving you to find out: it is published in eighteen machine-assisted translations as a reading convenience, the English text governs where one differs, and T-6 carries Ordane's dated commitments on that page carrying a visible notice and on a human-reviewed translation. Read T-6 before relying on a Rulebook page that is not in English.
- PV-57. If Ordane's business is ever transferred to another company under Terms clause T-49, your personal data transfers with it, and the acquirer is bound by this Privacy Policy for data already collected under it. A transfer of the business is not a new collection, is not a new purpose, and does not by itself expand what is done with your data.
§14Changelog
| Version | Date | Change |
|---|---|---|
| 1.2 | 2026-08-14 | Section 4 and section 5 updated. Microsoft Clarity heatmaps and session recordings run only after the analytics banner is accepted (PV-12c). Checkout name, email, and phone are masked. The consent key is now ord_analytics_consent_v2, so a previous Accept for Google Analytics alone does not turn Clarity on. PV-12b no longer lists heatmaps and session recording as things Ordane never runs. |
| 1.1 | 2026-08-06 | Section 4 rewritten. Ordane now counts its own traffic, first-party, with no cookie and no identifier stored on your device (PV-12). The own-heatmap that had been running for visitors who accepted the analytics banner was removed from the site, which is why the previous wording of PV-12 was wrong while it ran. Google Analytics is unchanged and still requires consent (PV-12a). The list of what Ordane does not run is now its own clause (PV-12b). |
| 1.0 | 2026-08-04 | Initial public release. |
§15Contact
Any question, any request, any correction: [email protected].
This document governs the handling of personal data by Ordane Markets Ltd under version 1.2.
Version 1.2 · Effective 2026-08-14 · Ordane Markets Ltd