Legal
Privacy Policy
Last updated: March 30, 2026
GEXFlow ("we," "us," or "our") operates gexflow.io and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service.
GEXFlow is operated from South Korea and serves users worldwide. We are committed to protecting your privacy in accordance with applicable data protection laws, including the Korean Personal Information Protection Act (PIPA) and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Information We Collect
Information You Provide
- Waitlist registration: Email address
- Account registration: Email address, password (stored as a cryptographic hash — we never store plaintext passwords), and display name if provided
- Communications: Any information you provide when contacting us for support
Information Collected Automatically
- Log data: IP address, browser type, operating system, referring URL, pages visited, and timestamps
- Cookies: We use essential cookies for session management and authentication. See Section 6 for details.
Information We Do Not Collect
- We do not collect payment or financial account information at this time
- We do not collect trading account credentials or brokerage data
- We do not track your trading activity outside of GEXFlow
2. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the Service
- Manage your account and authenticate your sessions
- Send waitlist updates and early access invitations
- Respond to your inquiries and support requests
- Monitor and analyze usage patterns to improve the Service
- Detect and prevent fraud, abuse, or security incidents
- Comply with legal obligations
We will not sell your personal information to third parties.
3. Legal Basis for Processing (GDPR Users)
If you are located in the European Economic Area (EEA) or the United Kingdom, our legal basis for processing your personal information includes:
- Consent: When you voluntarily provide your email to join the waitlist or create an account
- Contract performance: To provide the Service you have requested
- Legitimate interests: To improve and secure the Service, provided these interests do not override your rights
4. Data Sharing
We may share your information only in the following circumstances:
- Service providers: With third-party vendors who assist in operating the Service (e.g., hosting, email delivery), under contractual obligations to protect your data
- Legal requirements: When required by law, regulation, legal process, or government request
- Business transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected users
- With your consent: When you explicitly authorize us to share your information
We do not share your data with advertisers or data brokers.
5. Data Storage and Security
- Your data is stored on servers located in the United States and/or South Korea
- Passwords are hashed using industry-standard algorithms (PBKDF2-SHA256)
- We use HTTPS encryption for all data transmitted between your browser and our servers
- Access to personal data is restricted to authorized personnel on a need-to-know basis
While we implement reasonable security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
6. Cookies
GEXFlow uses the following cookies:
| Cookie | Purpose | Duration |
| Session cookie | Authentication and session management | 30 days |
| Tester access cookie | Identifies approved beta testers | 30 days |
We do not use third-party advertising or tracking cookies.
You can configure your browser to refuse cookies, but this may limit your ability to use certain features of the Service.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Data portability: Request your data in a structured, machine-readable format
- Withdrawal of consent: Withdraw consent for processing at any time
- Objection: Object to processing based on legitimate interests
To exercise any of these rights, contact us at privacy@gexflow.io. We will respond within 30 days (or sooner as required by applicable law).
Korean Users (PIPA)
Under the Personal Information Protection Act, you have the right to access, correct, delete, and suspend processing of your personal information. You may also designate an agent to exercise these rights on your behalf.
EU/UK Users (GDPR)
You have the right to lodge a complaint with your local data protection authority if you believe we have not adequately addressed your concerns.
8. Data Retention
- Waitlist data: Retained until you request removal or the waitlist is closed
- Account data: Retained for as long as your account is active. Upon account deletion, we will remove your personal information within 30 days, except where retention is required by law
- Log data: Retained for up to 12 months for security and analytics purposes
9. International Data Transfers
If you are accessing the Service from outside South Korea, your information may be transferred to and processed in South Korea or other jurisdictions where our servers are located. By using the Service, you consent to such transfers. We take reasonable steps to ensure your data receives adequate protection in accordance with applicable law.
10. Children's Privacy
GEXFlow is not intended for users under the age of 18. We do not knowingly collect personal information from minors. If we learn that we have collected information from a user under 18, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you via email or through the Service. We encourage you to review this policy periodically.
12. Contact
If you have questions or concerns about this Privacy Policy or your personal data, contact us at:
Email: privacy@gexflow.io
For data protection inquiries specific to Korean law, you may also contact the Personal Information Protection Commission (PIPC) at www.pipc.go.kr.