How GM Markets handles data, cookies, and local storage at a permissionless wallet-connect interface.
1. Scope and identity
This policy covers personal data processed by GM Markets in connection with the website at gm.markets and the GM Markets interface (the "Service"). GM Markets is a software interface running on third-party tokenization infrastructure operated by Flo. References to "we", "us", and "our" mean the operator of the GM Markets interface.
2. Permissionless interface
GM Markets is a permissionless, wallet-connect interface. There is no signup, login, or user account at the GM Markets layer. We do not collect identity documents, names, or government identifiers from users of the interface. Users connect a self-custodial wallet and transact directly on public blockchain networks.
Some downstream services (the token issuer, regulated brokers, vault managers) may have their own requirements that apply at their layer. Those are governed by their own privacy notices.
3. Data we process
When you use the Service we may process the following categories of data:
- Wallet address — the public address you connect to display balances, positions, and transaction history.
- IP address and coarse geolocation — for jurisdictional gating, sanctions screening at the interface layer, abuse prevention, and security.
- Browser and device metadata — user-agent, locale, screen size, referrer, and similar properties used for accessibility, diagnostics, and fraud signals.
- Telemetry and error reports — anonymized page-view counts, performance metrics, and client-side error stacks (analytics is opt-in; see Section 12).
- Local storage — connected-wallet session, UI preferences, and security tokens stored in your browser.
- Voluntary contact data — the email address you provide if you subscribe to the newsletter, email a contact alias, or submit a support request.
4. How we use data
Processing is limited to:
- Operating, maintaining, and securing the Service.
- Preventing abuse, fraud, and unauthorized access.
- Enforcing jurisdictional gating and interface-layer sanctions screening.
- Diagnosing errors and improving performance.
- Responding to your inquiries.
- Sending newsletters you have subscribed to.
- Complying with legal obligations and enforcing our terms.
We do not sell or rent personal data. We do not use personal data for behavioral advertising.
5. Lawful basis (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on the following lawful bases:
- Legitimate interests — operating and securing the Service, preventing abuse, diagnosing issues. We balance these interests against your rights and freedoms.
- Legal obligation — sanctions compliance, lawful requests, record-keeping where required.
- Consent — opt-in analytics, newsletters, and any cookies that are not strictly necessary. You can withdraw consent at any time.
- Contract — limited processing necessary to provide a feature you have requested (for example, a support response).
6. CCPA / CPRA categories
California residents: under the CCPA / CPRA, the categories of personal information we may process are identifiers (wallet address, IP), internet or network activity (telemetry), geolocation (coarse), and commercial information (newsletter subscription). We do not sell or share personal information for cross-context behavioral advertising. You may exercise your rights via the contact in Section 14.
7. Processors and sub-processors
We use vetted third-party processors for hosting, content delivery, error monitoring, analytics, and transactional email. Each processor is contractually bound to confidentiality and data-protection terms aligned with the applicable framework. A current list of categories and named processors is available on request to privacy@gm.markets.
8. Retention
- Diagnostic logs: up to 90 days, then aggregated or deleted.
- Aggregate analytics: retained indefinitely in anonymized form.
- Newsletter subscribers: retained until you unsubscribe or request deletion.
- Support correspondence: retained for up to 24 months after closure of the request.
- Records required by law: retained for the period required by applicable law.
9. International transfers
Personal data may be processed in jurisdictions outside your home country, including the EEA, the United Kingdom, and the United States. Where required, we use Standard Contractual Clauses or equivalent transfer mechanisms to provide an adequate level of protection.
10. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of personal data we hold about you.
- Receive a portable copy of data you have provided.
- Object to or restrict processing.
- Withdraw consent (where consent is the lawful basis).
- Opt out of "sale" or "sharing" under CCPA / CPRA (we do neither).
- Lodge a complaint with a supervisory authority.
To exercise a right, email privacy@gm.markets. We will respond within the period required by applicable law.
On-chain data. Transactions you sign are written to public blockchains and are outside our ability to delete. Nothing in this policy implies that on-chain data can be erased.
11. Children
The Service is not directed at minors. We do not knowingly process personal data of anyone under 18. If you believe a child has provided us with data, contact privacy@gm.markets and we will delete it.
12. Automated decision-making and profiling
We do not make decisions producing legal or similarly significant effects about you solely on the basis of automated processing. Interface-layer rules (for example, jurisdictional gating, sanctions blocks) are rules-based safeguards, not profiling.
13. Cookies and local storage
GM Markets uses a small set of browser technologies to make the interface work. Most of what people call "cookies" on this site is actually first-party local storage; we do not use third-party advertising cookies or cross-site tracking pixels.
Categories
Strictly necessary (always on, no consent required)
wallet_session — remembers your connected wallet across reloads.prefs — UI preferences (theme, slippage defaults, favorites).csrf_token — session security for form submissions.geo_check — short-lived flag to prevent re-running the jurisdictional check on every navigation.
Preferences (always on, no consent required)
locale — your selected language and number formatting.chart_settings — chart timeframe, indicators, drawings.
Analytics (opt-in, off by default in the EEA and UK)
- Privacy-preserving, IP-anonymized page view counts and error reports. No device fingerprinting. Toggle in Settings → Privacy.
Advertising
None. GM Markets does not use advertising cookies and does not allow third parties to set advertising cookies through the interface.
Third-party cookies
Embedded third-party content (for example, video players, status-page widgets) may set their own cookies when you interact with them. Those cookies are governed by the third party's policy.
How to manage or disable
Analytics consent can be toggled in Settings → Privacy. Browser-level controls (cookie settings, "clear site data") will remove our cookies and local storage; doing so will log you out and reset preferences. Strictly-necessary cookies cannot be disabled without breaking core functionality.
14. Updates and contact
We may update this policy. Material changes will be announced on the interface and reflected in the "Last updated" date above. Privacy questions and rights requests: privacy@gm.markets.