GM Markets Ltd. (“GM Markets”, “we”, “us”) operates the GM Markets product at gm.markets. This policy explains what personal information we collect when you use the product, how we use it, who we share it with, and the rights you have. It applies to visitors of our marketing site, users of the app, and people who interact with our support channels.
We aim to collect the minimum data required to run a safe, working product. We do not sell personal information. Wallet keys for your embedded Privy wallet stay with you — we never see or hold them.
The data controller for the personal information covered by this policy is GM Markets Ltd., a company incorporated in the British Virgin Islands. Contact details are at the end of this page.
We work with sub-processors (listed below) to deliver the product. Where a sub-processor is a data controller in its own right (for example, an OAuth provider you use to sign in), its own privacy policy also applies to the data you provide to it.
We use Privy (Privy.io) as our authentication and embedded-wallet provider. Depending on the method you choose, Privy collects and passes to us:
Certain flows may require identity verification to meet legal obligations, sanctions screening, and withdrawal-limit tiers. When required, you will be asked to provide:
KYC processing is carried out by qualified sub-processors under separate data-processing agreements. Identity documents are retained only for as long as we are legally required to do so.
When enabled, we use PostHog to understand how the product is used and to identify bugs and rough edges. Events include pages viewed, features used, and error surfaces reached. Where user profiles are created, PostHog is configured to identify only authenticated users, and to collect the minimum necessary properties. Session recording, when enabled, masks form inputs by default. You can request that we exclude your account from analytics at any time (see “Your rights”).
We use Sentry to capture unhandled errors and performance regressions. Sentry events may include stack traces, request URLs, browser and OS metadata, wallet address (as a pseudonymous user identifier), and short-lived breadcrumbs of user actions leading up to an error. We do not intentionally send sensitive fields (private keys, seed phrases, KYC document contents); scrubbing rules are applied server-side.
If you contact us over Telegram, Discord, or email, we retain the message content, the identifier you contacted us from, and any attachments you send. These are used to help you and to improve the product.
The marketing site (this page and the rest of gm.markets) uses server-side page-view counts and Web Vitals to keep the site fast and to plan content. We do not use behavioural advertising cookies on the marketing site.
We do not sell personal information. We do not use your data to train third-party AI models. We do not run behavioural advertising on the marketing site.
Where GDPR or the UK GDPR applies to you, we rely on the following legal bases:
GM Markets Ltd. is based in the British Virgin Islands. Our sub-processors operate globally, including in the United States, the European Union, the United Kingdom, and other regions. Where we transfer personal data internationally, we rely on appropriate safeguards, including standard contractual clauses (or their equivalent) and, where required, additional technical and organisational measures.
On-chain records (see below) are outside our control and cannot be deleted.
We apply administrative, technical, and physical safeguards designed to protect personal information, including access controls, encryption in transit and at rest for server-side data, and independent review of the trading and custody stack. Details of the security model live at /security. No system is perfectly secure — you can help by using a passkey, enabling app-lock and biometric-on-trade, keeping your withdrawal address whitelist current, and never sharing your anti-phishing phrase or key export material.
To report a security concern, email [email protected]. A responsible-disclosure programme is documented at /security.
Depending on where you live, you may have some or all of the following rights over the personal information we hold about you:
To exercise any of these rights, email [email protected] from the email you use to sign in, or from an email tied to your KYC record. We may ask for reasonable evidence of identity before acting.
Deposits, withdrawals, trading-balance mints and burns, and trade fills are recorded on public blockchains. These records are permanent and outside our control. If you ask us to delete your account, we will delete or de-identify server-side profile data, close your session, and stop notifications — but we cannot alter or remove on-chain history. Anyone who knows a wallet address can inspect its activity forever. Treat wallet activity accordingly.
GM Markets is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us and we will delete it.
We update this policy from time to time. Material changes will be notified at least 30 days before they take effect, either in the app, by email to your registered address, or by a prominent banner on the marketing site. Continued use after the effective date constitutes acceptance.
For privacy questions, requests, or complaints:
See also the Terms of Service, the Legal index, and the Security model.