← Back to home
Privacy Policy
Last updated: 2026-09-20
1. What We Collect
We collect only what is necessary to operate the Service:
- Account data: email address and hashed password (if you register with email/password)
- OAuth data: your email and a Google user ID (if you sign in with Google)
- cTrader tokens: access and refresh tokens issued by cTrader's OAuth flow — used to place orders and read positions on your behalf
- Billing data: your Stripe customer ID and subscription status (we never see your card details)
- Log data: IP address, user agent, and request timestamps — retained for 30 days for security and debugging
2. What We Do NOT Collect
- Your cTrader username or password (cTrader's OAuth never shares these)
- Your card number or CVV (Stripe handles all card data)
- Your positions, orders, or P/L history — these stream from cTrader directly to your browser and are never stored on our servers
3. How We Use Your Data
- To authenticate you and maintain your session
- To place orders and read positions on your cTrader accounts
- To process subscription billing via Stripe
- To send transactional emails (trial reminders, payment receipts)
- To detect abuse and secure the Service
4. Third-Party Processors
We share the minimum necessary data with these processors:
- Supabase — database hosting (PostgreSQL)
- Render — application hosting
- Stripe — payment processing
- Google — OAuth identity provider
- cTrader (Spotware) — trading API
We do not sell or rent your data to anyone.
5. Data Retention
Account data is retained as long as your account is active. When you delete your account, we remove your email, hashed password, and cTrader tokens within 30 days. Billing records required by law are retained for 7 years.
6. Your Rights
You may request to:
- Access a copy of your personal data
- Correct any inaccurate data
- Delete your account and associated data
- Export your data in a portable format
To exercise any of these, email [email protected].
7. Security
We use industry-standard measures: HTTPS everywhere, hashed passwords (bcrypt), HttpOnly cookies for sensitive tokens, encrypted databases at rest (via Supabase), and access controls on our infrastructure. No system is 100% secure — if you believe your account is compromised, contact us immediately.
8. Cookies
We use only essential cookies:
- Session cookie for authentication
- Temporary OAuth cookies during cTrader connection flow (expire in 10 minutes)
We do not use tracking or advertising cookies.
9. Children's Privacy
The Service is not intended for anyone under 18. We do not knowingly collect data from minors.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be announced via email or on the dashboard.
11. Contact
Privacy questions: [email protected].