Privacy Policy
Last updated: 3 April 2026
This Privacy Policy explains how Matrix Escape Ltd. ("we", "us", or "our") collects, uses, stores, and protects your personal data when you visit our website at matrix-escape.net ("Site") or use our products and services ("Services").
We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the ePrivacy Directive 2002/58/EC. We only collect personal data that is necessary for the purposes described in this policy (data minimization principle).
1. Data Controller
The data controller responsible for your personal data is:
Matrix Escape Ltd.
Address: ul. Konarevo 30, 2770 Bansko, Bulgaria
UIC (Unified Identification Code): 208633740
Email: admin@matrix-escape.net
2. Data We Collect
2.1 Account and Authentication Data
When you sign in, we collect your email address. A valid email address is required to use the Services, as it is necessary for authentication and subscription management. We use email-based one-time verification codes for authentication. We do not use passwords. If you do not provide your email address, you will not be able to access or use the Services.
2.2 Payment Data
All payment processing is handled by Stripe, Inc. We do not collect, store, or have access to your full credit card number, CVV, or other sensitive payment credentials. The data we receive from Stripe includes:
- Stripe customer ID
- Email address associated with payment
- Name provided at checkout
- Subscription status, plan, and billing period
- Invoice amounts and payment status
- TradingView username (provided voluntarily at checkout, used solely to grant you access to the purchased indicators on the TradingView platform)
For details on how Stripe handles your payment data, please see Stripe's Privacy Policy.
2.3 Newsletter Subscription
If you voluntarily subscribe to our newsletter, we collect your email address for the sole purpose of sending you newsletter communications. Newsletter subscription is entirely optional and requires your explicit consent (opt-in). We will never automatically add you to the newsletter list through any other interaction with our Services, including purchasing a subscription or signing in to your account.
2.4 Analytics Data
We use Vercel Analytics to collect aggregated usage data such as page views, referral sources, and general geographic region. This data is designed to minimize the collection of personal data and is used solely to understand how our Site is used and to improve the Services. We also collect UTM parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) from inbound links for marketing attribution purposes. These are stored in your browser's local storage and passed to Stripe as session metadata.
2.5 Cookies and Local Storage
We use browser local storage to maintain functionality essential to the Services. The following are stored locally:
- Authentication token (JWT): Required for your session to work — essential
- Plan selection preferences: To remember your chosen plan during checkout — essential
- UTM parameters: Used for marketing attribution and performance measurement. These are not used for profiling or cross-site tracking
- Cookie consent preference: To remember your consent choice — essential
All local storage entries listed above are strictly necessary for the Site to function correctly and do not require separate consent under the ePrivacy Directive. We do not use third-party advertising or tracking cookies. We do not use cookies for behavioral profiling or cross-site tracking.
3. How We Use Your Data
We use your personal data for the following purposes:
- Authentication: To verify your identity and provide access to your account and subscriptions
- Service delivery: To manage your subscriptions, process payments via Stripe, and grant access to purchased indicators on TradingView
- Communication: To send transactional emails (verification codes, payment confirmations) and, only if you opted in, newsletter communications
- Admin notifications: To notify our team of subscription events for operational purposes
- Analytics: To understand how our Site is used and improve our Services
- Marketing attribution: To track the effectiveness of marketing campaigns via UTM parameters
- Fraud and abuse prevention: To detect and prevent unauthorized access, fraudulent transactions, and abuse of the Services
4. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR): Processing necessary to fulfil your subscription and provide the Services you purchased, including authentication, payment processing, and granting access to indicators
- Consent (Art. 6(1)(a) GDPR): For newsletter communications. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal
- Legitimate interest (Art. 6(1)(f) GDPR): For analytics, security, fraud and abuse prevention, and improving our Services. Our legitimate interest is balanced against your rights and does not override your fundamental privacy rights
5. Data Sharing and Processors
We share personal data only with the following categories of recipients:
- Stripe, Inc. — Payment processing. Stripe acts as an independent data controller for payment data
- Vercel, Inc. — Website hosting and analytics
- Secure third-party email delivery provider (transactional email service) — For sending verification codes and newsletter emails
All third-party processors we engage operate under GDPR-compliant data processing agreements (DPAs) or equivalent contractual safeguards. We ensure that each processor provides sufficient guarantees regarding the security and lawful processing of your personal data.
We do not sell, rent, or share your personal data with third parties for their marketing purposes. We do not engage in data brokering.
6. Data Retention
We retain your personal data as follows:
- Account and subscription data: For as long as your account is active, and for up to 5 years after account closure or subscription cancellation, as required by Bulgarian tax and accounting legislation (Accountancy Act, VATR)
- Newsletter email addresses: Until you unsubscribe or request deletion, whichever comes first
- Payment and invoice records: Up to 5 years after the transaction date, in accordance with tax and accounting requirements
- Analytics data: Aggregated and anonymized; retained indefinitely as it is treated as non-personal data due to its aggregated and anonymized nature
After the applicable retention period, personal data is securely deleted or anonymized.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Secure, tokenized payment processing via Stripe (PCI DSS compliant)
- Database access restricted to authorized personnel only
- JWT-based authentication with expiring tokens
8. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you. No decisions about your access, pricing, or account status are made solely by automated means without human involvement.
9. Your Rights (GDPR)
If you are located in the European Economic Area, you have the following rights:
- Right of access (Art. 15): Request a copy of the personal data we hold about you
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete data
- Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations
- Right to restrict processing (Art. 18): Request limitation of processing in certain circumstances
- Right to data portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interest
- Right to withdraw consent (Art. 7): Withdraw newsletter consent at any time without affecting the lawfulness of prior processing
To exercise any of these rights, please contact us at admin@matrix-escape.net. We will respond within 30 days of receiving your request. We may request verification of your identity before processing your request to ensure we protect your data from unauthorized access.
You also have the right to lodge a complaint with your local data protection supervisory authority. In Bulgaria, this is the Commission for Personal Data Protection (CPDP): www.cpdp.bg.
10. International Transfers
Your data may be processed by third-party services (Stripe, Vercel) located outside the European Economic Area. Where such transfers occur, they are protected by appropriate safeguards such as Standard Contractual Clauses (SCCs) or the service provider's participation in recognized data protection frameworks (e.g., the EU-U.S. Data Privacy Framework).
11. Children's Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a child under 18, we will promptly delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. We encourage you to review this page periodically.
13. Contact
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:
Matrix Escape Ltd.
Address: ul. Konarevo 30, 2770 Bansko, Bulgaria
UIC (Unified Identification Code): 208633740
Email: admin@matrix-escape.net