Privacy Policy
Effective 7 September 2026.
This policy explains what ALIEN SOFTWARE LLC, a Wyoming limited liability company ("Clobber", "we", "us") does with personal data. It covers this website, the dashboard, and the Clobber API.
#1. Two different roles, and why it matters to you
We handle personal data in two capacities, and almost every question about your data has a different answer depending on which one applies.
As a controller, for the people we deal with directly: the person who signs up, the members of an Organization, billing contacts, people who email us, and visitors to this website. We decide what to do with that data, and this policy describes it.
As a processor, for data our customers put into their environments through the API. A Clobber customer operates its own market and its own relationship with its own end users. If you are one of those end users, we are not your counterparty and we have no relationship with you: we run software on behalf of the business you traded with. We act on that business's instructions, under the Data Processing Addendum at clobberhq.com/legal/dpa/, and your rights are exercised against them, not us. If you contact us directly we will point you to them, because we usually cannot identify you and are not permitted to act on your request without their instruction.
#2. What we collect as a controller
Account data. Name, work email address, the Organization you belong to, your role, and authentication data. If you sign in with a third party identity provider we receive your identifier and email address from them, never your password.
Verification data. Before an Organization may create a production environment we verify it: the legal entity, its registration details, its beneficial owners, the markets it intends to operate, the jurisdictions it serves, and the authorisations it holds. This includes personal data about signatories and owners, and it includes the result of screening those people against published sanctions lists.
Billing data. Company details, billing address, tax identifiers, invoices and payment history. We never see or store your card number: payment details go directly to our payment processor.
Usage and technical data. API requests, timestamps, the key used, IP address, user agent, response codes and latency, dashboard interactions, and error reports. This is what makes rate limiting, abuse detection, billing and debugging possible.
Communications. Emails, support requests and the correspondence around them.
Website data. Aggregate visit statistics. We use Cloudflare Web Analytics, which is cookie free and does not fingerprint or track visitors across sites. We run no advertising trackers and sell nothing to anyone.
#3. Why we use it
| Purpose | Basis under GDPR |
|---|---|
| Providing the Service, and administering your account | Performance of a contract |
| Billing, collections and tax | Contract, and legal obligation |
| Verifying an Organization before production access | Legal obligation, and our legitimate interest in not enabling unlawful markets |
| Sanctions screening | Legal obligation |
| Security, abuse prevention, rate limiting, fraud detection | Legitimate interests |
| Support and service communications | Contract, and legitimate interests |
| Improving and measuring the Service, in aggregate | Legitimate interests |
| Product and marketing email | Consent where required, otherwise legitimate interests, with an unsubscribe link in every message |
| Responding to legal process | Legal obligation |
#4. Cookies
The dashboard sets a session cookie so you stay signed in, and a small number of preference cookies. They are strictly necessary and there is no version of the product that works without them. This website sets no cookies at all. We use no advertising, retargeting or cross site tracking cookies anywhere.
#5. Who we share it with
Subprocessors and service providers, listed with what each one does at clobberhq.com/legal/subprocessors/. Each is bound by contract to process data only on our instructions and to protect it.
Nobody else, for money. We do not sell personal data, we do not share it for cross context behavioural advertising, and we do not disclose customer market data to anyone.
In a corporate transaction, if we are acquired or merged, subject to this policy continuing to apply.
Under legal process, as described next.
#6. Legal process, and what we can actually produce
We comply with valid legal process, and we cooperate with lawful investigations. We also think you should know exactly what that means before it happens to you.
What we require. A subpoena, court order, warrant or equivalent that is valid in a jurisdiction that reaches us. We review each request, we produce only what it actually requires, and we push back on requests that are overbroad or defective.
What we tell you. Unless we are legally prohibited, or notice would defeat the purpose of an emergency request, we notify the affected customer before we produce anything, in time for them to seek protective treatment. This commitment is in the Terms as well as here.
What exists. Account and billing records; verification records; API access logs; and the journal, which is the ordered, append only record of every command an environment sent, with the credential that sent it and the moment it arrived.
What does not exist. The identity of our customers' end users. We do not hold it. A request about an individual trader belongs with the business that operates that market, not with us, and we will say so.
Preservation. A valid preservation request suspends deletion for anything in scope, including the retention periods below.
#7. International transfers
We operate from the United States and use providers there and elsewhere. Where personal data covered by European or United Kingdom law is transferred, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, which are incorporated in the Data Processing Addendum, together with the additional measures described there. A copy of the clauses is available on request at [email protected].
Customer data inside an environment stays in the region that environment is pinned to. Regions are chosen by the customer and an environment never spans them.
#8. How long we keep it
| Data | Retained |
|---|---|
| Account and Organization records | While the account is open, then 12 months |
| Verification and sanctions screening records | 5 years after the relationship ends, as anti money laundering practice expects |
| Invoices and tax records | 7 years, as tax law requires |
| The journal of an environment | The life of the environment, then 12 months |
| API access logs | 30 days |
| Support correspondence | 3 years |
| Marketing contact records | Until you unsubscribe, then a suppression record so we do not contact you again |
Longer where a legal hold, a preservation request or a dispute requires it.
#9. Your rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to processing, receive it in a portable form, and withdraw consent. Under United States state privacy laws you may also have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing, which is straightforward for us because we do neither. We will not discriminate against you for exercising any of these.
Write to [email protected]. We respond within 30 days, and we may need to verify your identity first. If you are an end user of a Clobber customer, see section 1: your request goes to them.
If you are in the European Economic Area or the United Kingdom and you are unhappy with our response, you may complain to your local supervisory authority.
#10. Security
We describe our security measures at clobberhq.com/legal/security/. If a security incident affects your personal data, we notify affected customers without undue delay and within 72 hours of becoming aware, and we notify individuals and regulators where the law requires it.
#11. Children
The Service is for businesses. It is not directed at anyone under 18 and we do not knowingly collect their data. If you believe we have, write to [email protected] and we will delete it.
#12. Changes
We will post any updated version here with a new effective date, and we will email account administrators before a material change takes effect.
Contact: [email protected]