Privacy Policy
Effective 18 September 2026 · Last updated 18 September 2026 · Version 2026-09-18
This policy explains the actual information flows evidenced in the Legion website and platform repositories, including account data, subscriptions, education progress, journal data, enquiries, AI prompts, analytics, tester applications, and client project information.
1. Who Holds Your Information
Legion Algo Labs Limited, trading as Legion Algo Labs, is the New Zealand agency responsible for personal information described in this policy unless a separate client agreement identifies another agency. Contact: support@legionalgolabs.com. Website: https://legionalgolabs.com.
This policy applies to the Legion Algo Labs website and forms, Legion accounts, Legion HQ, Academy, Legion+, Scout, Guardian, Trading Lab, website assistant, subscriptions, support, Android tester applications, and business or software-development services. Separate product privacy policies apply to the standalone Legion Risk and Legion Trade Journal apps.
2. Information We Collect
- Identity and contact information: name, email address, account UUID, profile/display name, phone number or business details if supplied, and support or enquiry details.
- Account and security information: authentication records handled through Supabase, session and device information, password-reset events, access status, security logs, IP address, browser and request metadata.
- Learning and product information: courses, lessons, progress, quiz or knowledge-check activity, achievements, preferences, feature interactions, journal entries, trading notes, saved settings, notification preferences, and account-linked educational activity where the feature is used.
- Subscription and transaction information: seller, plan, status, renewal or expiry information, Stripe customer/subscription identifiers, app-store purchase status, invoices and support records. Legion does not directly receive or store full payment-card numbers.
- Communications and forms: contact, booking and project enquiries, Android tester application details, feedback, complaints, files, and correspondence.
- AI information: the message and limited conversation history submitted to the website assistant, prompts and outputs in other AI Features, and associated operational metadata.
- Technical and analytics information: page views, clicks on app-store and trading-partner links, approximate location derived by providers, browser/device details, referrer, cookie or device identifiers, error and performance information where enabled.
- Client-project information: Client Materials, workflow data, business records, user/customer/employee/supplier information, specifications, credentials shared through an approved secure method, and delivery records needed for the project.
3. Where Information Comes From
We collect information directly when you create an account, use a feature, subscribe, complete a form, contact support, submit a journal entry, use the website assistant, or work with us on a project. Some technical information is collected automatically by the Platform and its providers.
We may collect information indirectly from Stripe, Apple, Google, Supabase, a Client, an authorised representative, a referral source, a service provider, a public source, or another person involved in a project. We first assess whether indirect collection is permitted under Information Privacy Principle 2.
4. IPP3A And Client-Supplied Personal Information
Since 1 May 2026, Information Privacy Principle 3A generally requires a collecting agency that receives personal information from someone other than the individual to take reasonable steps to make the individual aware of the collection and specified matters as soon as reasonably practicable, unless an exception applies or the person has already been made aware.
A Client may provide information about its employees, candidates, customers, users, leads, contractors, suppliers, or other people. The project contract and Data Processing Addendum require the Client to have a lawful basis for supplying it and, where the Client has the direct relationship, to give an accurate notice identifying Legion, the collection and purpose, intended recipients, where the information is held, and access/correction rights. Legion remains responsible for its own IPP3A compliance and does not rely on an unsupported assumption that notice was given.
If another agency processes information solely on our behalf and does not use it for its own purposes, section 11 of the Privacy Act may treat us as the holder. Allocation of notification tasks does not remove the responsible agency's legal obligations. Exceptions are assessed case by case and documented where relied on.
5. Why We Use Information
- Create and secure accounts; authenticate users; provide cross-platform membership and entitlement access; and respond to password, deletion, and support requests.
- Deliver Academy content, progress, journals, preferences, notifications, educational tools, market context, AI Features, and requested services.
- Process and reconcile subscriptions; provide billing support; prevent fraud and duplicate or unauthorised access; and keep tax, accounting, and dispute records.
- Receive and respond to enquiries, meeting requests, tester applications, feedback, complaints, and client instructions.
- Measure website and product use, improve usability and content, diagnose faults, maintain security, and understand conversion events without intentionally sending names, emails, account IDs, or journal content to Google Analytics.
- Design, develop, test, operate, support, and secure client software and automation under documented instructions.
- Comply with law, enforce agreements, establish or defend legal claims, and protect people, systems, rights, and the public.
6. Providers And Recipients
Repository and product evidence shows the following provider categories: Supabase for authentication, database and backend services; Stripe for website checkout and subscription billing; Apple and Google for app distribution, in-app purchases and platform services; Expo and Apple/Google push services for enabled mobile notifications; OpenAI for the website assistant; Google Analytics for website analytics; Google Apps Script/Sheets and Gmail for enquiry and tester workflows; Vercel for production website hosting; and the configured market-data provider for requested calendar or market data.
We may also share limited information with authorised staff and contractors, professional advisers, security and incident-response providers, courts, regulators, law-enforcement bodies where legally required, and a successor involved in a genuine business transaction subject to appropriate safeguards.
External community, broker, proprietary-trading, app-store, and partner links take you to independent providers. Information you submit to them is governed by their policies. Referral parameters may tell the provider that Legion referred the visit or conversion.
We do not sell personal information. We do not permit processors to use client or user information for unrelated purposes merely because they provide infrastructure, except where a provider acts as an independent controller under its own disclosed terms.
7. AI Processing
The website assistant sends your current message and limited chat history to OpenAI through a server-side API to generate a reply. The conversation is kept in your browser during the widget session; the website code does not save it to the Legion database. Hosting and AI-provider security logs or retention may still apply under their configured service terms.
Other AI Features may process prompts and relevant project or educational context through an identified provider. Do not submit passwords, secret keys, full card details, health information, government identifiers, or third-party confidential information unless a feature expressly requires it, a suitable agreement is in place, and you are authorised.
Legion will not use identifiable journal entries, private AI conversations, or Client personal information to train a Legion proprietary model without a documented lawful purpose, clear notice, and any consent or contractual authority required. De-identified or aggregated information must be assessed for re-identification risk before use.
8. Overseas Processing And IPP12
Cloud, payment, analytics, AI, email, app-store, and support providers may process information in New Zealand, Australia, the United States, or other regions in which they and their subprocessors operate. The exact region can depend on the provider and product configuration.
Where an overseas provider stores or processes information solely as our agent, section 11 may treat Legion as holding that information and IPP12 may not treat the transfer as a disclosure. Legion must still require reasonable safeguards and remains responsible for its agent's handling.
Where information is disclosed to a foreign person or entity for its own purposes, we assess IPP11 and IPP12. We use a permitted basis such as the recipient being subject to the Privacy Act, comparable legal safeguards, enforceable contractual protections, an approved binding scheme, or the individual's informed authorisation. We do not describe every overseas transfer as a disclosure when the statutory agency relationship applies.
10. Marketing And Service Messages
We may send requested account, security, payment, subscription, tester, support, or transaction messages because they are necessary to provide the service or complete the interaction. They are not treated as permission for unrelated marketing.
Commercial electronic messages require an applicable consent basis, accurate sender identification, and a clear functional unsubscribe facility where the Unsolicited Electronic Messages Act 2007 applies. Consent records and opt-outs should be retained as needed to demonstrate compliance, and unsubscribe requests are honoured within the legal period.
11. Security
We use safeguards appropriate to the information and risk, which may include access control, least privilege, authentication, encrypted transport, provider security controls, row-level access policies, environment-secret separation, logging, rate and origin controls, backups, dependency management, and incident procedures.
Users and Clients must protect credentials, limit the personal information they submit, provide secure access paths, promptly remove former personnel, maintain their own backups where agreed, and report suspected incidents. No online system or transmission method can be promised as completely secure.
12. Retention And Deletion
Account, profile, progress, journal, preference, and membership data is normally kept while the account is active and then deleted or anonymised through the verified deletion process, subject to backups and necessary legal, billing, fraud, security, and dispute records.
Contact, booking, support, tester, and client-project records are kept only for the period reasonably required to respond, administer the relationship, evidence consent or scope, protect security, and meet legal or accounting duties. Client agreements should set project-specific return and deletion periods for Client Data.
Analytics retention is governed by the configured Google Analytics property and applicable Google controls. Payment and app-store providers retain their own records under their policies. Backups may persist for a limited recovery cycle and are protected from ordinary use until overwritten or lawfully restored.
This policy applies a category-and-purpose-based retention rule. Legion must approve and maintain operational retention settings for each provider, and project contracts should state any required fixed period. Where a precise period is required by law or contract, that period controls. Information is not kept merely because storage is available.
13. Access, Correction, Portability, And Deletion
You may ask whether we hold your personal information and request access or correction by contacting support@legionalgolabs.com. We may verify identity, clarify scope, transfer a request where legally required, or rely on a lawful withholding ground. We respond within the timeframe required by the Privacy Act 2020.
You may request account deletion through the authenticated in-app flow or the verified assistance process on the Account Deletion page. Deletion does not itself cancel an Apple, Google, or Stripe Subscription; cancel through the seller first. Where technically available, you may export or request a usable copy of information you supplied.
If we do not make a requested correction, you may be entitled to have a statement of correction attached. Deletion is not absolute where retention is reasonably required for law, tax, accounting, fraud prevention, security, a legal claim, or another permitted purpose.
14. Privacy Breaches
We assess suspected privacy breaches promptly, contain them, preserve appropriate evidence, coordinate with providers, assess likely serious harm, remediate, and document decisions.
If it is reasonable to believe a breach has caused or is likely to cause serious harm, the Privacy Act requires notification to the Office of the Privacy Commissioner and affected people as soon as practicable, subject to statutory exceptions or permitted delay. Public notice may be used where individual notice is not reasonably practicable. The regulator recommends notification ideally within 72 hours even if investigation continues.
15. Children And International Users
The Services are designed for adults and are not directed to children. We do not knowingly seek children's personal information through trading, subscription, tester, or client-service features. Contact us if you believe a child supplied information so we can assess and respond appropriately.
People outside New Zealand may have additional mandatory rights. This policy does not remove them. Product availability, lawful bases, consent, cookies, age rules, and cross-border requirements must be separately assessed before Legion intentionally targets a new jurisdiction.
16. Complaints And Contact
Send privacy questions, requests, and complaints to the privacy contact at support@legionalgolabs.com. Please do not email passwords, full card details, secret keys, or unnecessary sensitive information.
If you are not satisfied with our response, you may complain to the New Zealand Office of the Privacy Commissioner at privacy.org.nz. Other regulators or dispute processes may be available depending on your location and the issue.
17. Changes To This Policy
We update this policy when products, providers, data practices, or law materially change. The effective date, last-updated date, and version appear at the top. Material changes will receive additional notice where reasonable or legally required, and a new consent will be obtained where the change cannot lawfully rely on the existing basis.
Product-specific policies: Legion Risk and Legion Trade Journal. See also Account Deletion.
