This policy covers the polymarket.layback.trade site: the public pages, the in-browser trading app and the desktop app download links. Last updated: 2026-08-25.
What we collect on public pages
Public pages use first-party cookies only: lbx-locale remembers the language you chose (Portuguese, English or Spanish) for up to one year; lbx_aid is a random identifier for this browser, kept for up to 400 days, which lets us count visitors and measure the funnel without knowing who you are; lbx_attr keeps for 90 days the origin of your visit (the campaign or link that brought you here); and lbx_consent stores for one year your answer to the cookie notice, where it is shown. These identifiers are randomly generated: they contain nothing and derive from nothing personal, not your wallet and not your key.
Audience measurement and marketing
We record product usage events (page views, app opens, downloads, sign-ins with success or error, orders submitted and filled) in our own service, on the same domain, tied only to the random identifiers above. We do not store your IP address in those records: only the country. The desktop app sends the same usage events with a random installation identifier created on first run. To measure ad campaigns we use Google tags (Google Analytics 4 and Google Ads) and Meta's Pixel in the browser and, for the funnel conversions (download, login and first bet), we also send the same event from our server to Meta's Conversions API and GA4's Measurement Protocol. That server send includes the random identifier (hashed for Meta, as-is for GA4), campaign click ids when present (gclid/fbclid), and the request's IP and browser, neither of which is written to our database. In the European Union, the European Economic Area, the United Kingdom and Switzerland both the tags and those server sends run only after you accept the cookie notice; declining keeps marketing off and the site works normally.
Hosting and access logs
The site is hosted on Vercel. As with any web service, each request produces access logs with IP address, browser, URL and timestamp, used for security and operations. The host also derives an approximate country and city from the IP, which we use for language detection and regional availability. The public /api/geo endpoint shows exactly what the site sees about your own request.
Signing in with your wallet
Sign-in uses your wallet. The private key stays in your browser and is never sent to our servers. The server receives only your public wallet address and a signed challenge; with that it creates a session identified by an httpOnly cookie. Session records (address and expiry) stay on the server until they expire or you sign out.
Trading
Orders are built and signed in your browser and sent to Polymarket's public APIs. We are non-custodial: we hold no funds and no keys. Orders may carry Layback's builder attribution, signed by our server, which never sees your key or your funds.
Regional availability
The trading surface follows Polymarket's regional restrictions. To apply them, we check the country the host derives from your IP at sign-in.
Your choices and rights
- Clearing your browser cookies removes the language preference, resets the random identifier and the campaign origin, and ends the session.
- Where the cookie notice is shown, declining keeps the marketing tags and the server-side conversion sends off; the choice lives in the
lbx_consentcookie and can be remade by clearing cookies. - Signing out of the app ends the session on the server.
- For questions or data requests, including requests under laws such as GDPR and LGPD, write to contato@layback.trade.
Changes to this policy
When our practices change, this page changes with them, with the updated date at the top. We do not sell personal data.
