What we store.Why we store it.
Last updated: 3 September 2026
This list is the current Prisma schema and auth/payment flows — not a generic privacy template. If a system is not wired, it is not claimed.
2.1Who controls the data
[COMPANY LEGAL NAME] at [REGISTERED ADDRESS] is intended to be the controller once those tokens are filled. Until then, requests go to the support address below.
2.2Account data
On User we store: email (unique), optional phone in E.164, password hash, role, emailVerifiedAt / phoneVerifiedAt, kycStatus (a string flag, default NOT_REQUIRED_YET), locale (en or fa), and timestamps. We do not store a legal name, date of birth, or ID-document file in this schema.
2.3Session and security
Sessions are opaque hashed tokens in an HttpOnly SameSite=Strict cookie named pp_session. The session row may include IP, user-agent, expiry, rotation, and lastSeenAt. Security events (failed login, lockout, reset, verification, session revoke) store type, optional IP and user-agent, and non-secret metadata.
Email/SMS one-time codes are sent through Nixify when that provider is configured. We store destination, purpose, provider request id for audit, attempt count, and expiry — not the code itself as a long-lived secret.
2.4Trading data
Purchases, trading accounts, rule snapshots, orders, fills, positions, risk events, status transitions, ledger entries, and in-app notifications are stored to run the desk and to audit it.
2.5Payments and payouts
Challenge payments: payment intents, detected blockchain transactions, match outcomes, and hold states (underpaid, overpaid, late, wrong asset). We do not store wallet private keys.
Payouts: requests, status transitions, destination address book (asset, network, address), and payment execution records (requested/actual amounts, provider payment id, status).
2.6KYC documents
kycStatus is a field on User used as a payout gate (VERIFIED vs not). There is no document-upload table in this codebase. When a vendor is wired it will be named here. Today that vendor is [KYC VENDOR PENDING].
2.7Purposes
Create and authenticate accounts; take challenge fees; run evaluation and funded books; enforce snapshotted rules; pay USDT withdrawals; prevent abuse; keep an audit trail; answer support mail.
2.8Third parties
Nixify — email/SMS OTP when configured. On-chain payment monitors and payout rails selected per network (providerKey on the network row). Hosting and the PostgreSQL database. [KYC VENDOR PENDING] when identity review is wired. We do not load analytics, ads, or social pixels.
2.9Retention
Sessions last until idle/absolute expiry or logout. Trading, payment, and payout rows are kept while we need them to run and audit the desk. There is no self-serve bulk-export or timed auto-wipe in the product today. Deletion or correction is handled on request where the law that actually applies requires it.
2.10Your rights and contact
Ask support@primeprop.dev to access, correct, or delete account data we hold. We may refuse a deletion that would break a required payment or fraud audit. Governing privacy law is [GOVERNING LAW] until that token is filled.