§ 01
Effective date and version
This Privacy Policy is effective 2026-07-14, version 2.2. It replaces the prior April 2026 version in full. Previous versions are available in this page's commit history at github.com/tradeloop or on request from [email protected].
We will notify affected account holders before any material change takes effect where law or contract requires notice, with a summary of what changed and why. Non-material edits (typo fixes, link updates, cross-reference repairs) are tracked in git history without a separate notice.
§ 02
Who we are — the data controller
TradeLoop is operated by the legal entity disclosed below, an India-incorporated company. For the purposes of the EU and UK General Data Protection Regulation we are the data controller; for the purposes of the India Digital Personal Data Protection Act 2023 we are the data fiduciary; for the California Consumer Privacy Act / California Privacy Rights Act we are the business.
Our registered office address is finalising and will appear here as soon as paperwork completes. In the meantime it is available on request from [email protected].
Data Protection Officer / Grievance Officer
India's DPDP Act §13 mandates a named Grievance Officer. The EU and UK GDPR recommend a Data Protection Officer (DPO) for any processor performing systematic monitoring at scale. TradeLoop's tilt-signature engine systematically evaluates trader behaviour against per-trader baselines, so a single named officer covers both roles:
- Name: Varun, founder (acting Grievance Officer / DPO until the role is split).
- Email: [email protected]. We aim to acknowledge every DSR / privacy query within one business day (24h max).
- Escalation: unresolved complaints may be lodged with the supervisory authority in your jurisdiction — see §13 below.
§ 03
Why we process your data — lawful basis
Under GDPR Article 6 and the DPDP Act §6, every processing activity has a named lawful basis. The table below mirrors the DPIA at docs/DPIA.md §1.2 exactly — if you find a divergence, that's a documentation bug; please email [email protected].
| Processing purpose | Lawful basis | Reference |
|---|---|---|
| Account creation, authentication, session management | Contract | GDPR Art 6(1)(b) · DPDP §6 |
| Trade ingestion via broker webhooks / CSV / browser extension | Contract | GDPR Art 6(1)(b) |
| Behavioural-risk detection (tilt-signature engine) | Contract | GDPR Art 6(1)(b) — the analysis service you requested |
| Legacy captured-payment, refund, and invoice remediation | Contract + Legal Obligation | GDPR Art 6(1)(b) + 6(1)(c); India GST + Income Tax |
| Daily debrief / weekly intel email | Legitimate Interest, with one-click opt-out | GDPR Art 6(1)(f) — balancing test in DPIA §7 |
| Consent-gated browser funnel analytics (Render) | Consent | GDPR Art 6(1)(a) — privacy controls |
| Authenticated operational product events (Render) | Legitimate Interest | GDPR Art 6(1)(f) — service operation and improvement |
| Aggregate page views and Web Vitals (Cloudflare Web Analytics) | Legitimate Interest | GDPR Art 6(1)(f) — cookie-free, aggregate measurement |
| Optional authenticated product-event mirror (PostHog) | Inactive | No production deploy key; consent required before enablement |
| Live chat support (Crisp) | Consent | GDPR Art 6(1)(a) — cookie banner |
| Error monitoring + session replay (Sentry) | Legitimate Interest (replay: Consent) | GDPR Art 6(1)(f) for errors; 6(1)(a) for replay |
| Aggregated cohort analytics (Pulse, Lift Study) | Legitimate Interest, with restriction right | GDPR Art 6(1)(f) — balancing test in DPIA §7 |
| Security, fraud prevention, audit log | Legitimate Interest + Legal Obligation | GDPR Art 6(1)(c) + 6(1)(f) |
§ 04
Data we collect — categories
The categories below mirror docs/DPIA.md §1.3 exactly. We do not process any "special category" data under GDPR Article 9 (health, biometric, racial, political, religious, sexual-orientation data). We do not process children's data — see §10.
- Identity: email and name. Billing address, GSTIN, or PAN can exist only on a legacy invoice record or after a separately authorised future purchase flow; checkout is currently closed.
- Authentication: bcrypt password hash, TOTP secret (Fernet-encrypted), refresh tokens, recovery codes. Plaintext passwords are never stored.
- Financial — trades: trade fills (instrument, side, quantity, entry / exit prices, fees, timestamps, P&L, broker, order id). Sourced from broker webhook / WebSocket or your own CSV upload.
- Financial — payment: legacy Razorpay payment / order IDs, plan tier, billing email, and billing GSTIN may remain where a captured charge, refund, dispute, or invoice must be reconciled. We do not store raw card data. Checkout is unavailable and the current private-beta journey collects no payment details.
- Behavioural — derived: tilt-signature firings, per-trader baselines, archetype scores, counterfactual cost estimates, Trader Health Index. Computed by our engine modules from your trade data. While processing is unrestricted, de-identified values may contribute to cohort aggregates protected by publication floors. We never sell them.
- Operational: login timestamps, IP addresses (transient — kept for security audit log), broker connection metadata, audit-log entries (HMAC-chained).
- Analytics and campaign: after analytics opt-in, a randomised anonymous id, event name and time, route, referrer, UTM labels, and browser user agent. Signed-in events may also link to your account. Limited result metadata may include Tilt Type, score band, status, and parsed-trade count. We do not put quiz answers, symbols, trade rows, email, or broker balance in these event payloads.
- Communication preferences: daily-debrief enabled, weekly-intel enabled, push subscription endpoint, Telegram chat id (when linked).
§ 05
Browser extension and Live Link
TradeLoop Live Link is an optional browser extension for supported broker pages. Manual Send reads the trade-history table visible in the current tab and sends a snapshot over TLS to your own TradeLoop journal. If you separately enable Live Link, it checks that visible table every 15 seconds while the tab is open and normally sends a new snapshot when the table changes. It may also revalidate the current snapshot when Live Link is enabled or the tab becomes visible again.
- Stored locally: the TradeLoop import token you provide, your selected destination ledger, and your explicit Live Link and warning preferences are kept in
chrome.storage.localfor that browser profile. They are not stored in Chrome Sync. - Sent to TradeLoop: the import token as the request credential; the visible trade table as CSV; the current page URL and title; scrape time; supported broker, manual or Live Link mode, extension version, optional table signature, and selected destination-ledger identifier. The API returns import, update, and duplicate counts for the extension to display.
- Optional warnings: after you separately enable Seatbelt warnings, the extension observes newly visible losing rows and the current lot or volume field in that tab to decide whether to show its own dismissible pause overlay. Those warning inputs and decisions stay in the browser; they are not sent to TradeLoop.
- Never read or changed: it does not read broker passwords, session cookies, or unrelated browsing history. It never submits an order form or places, modifies, cancels, or blocks an order.
The local token and preferences remain until you replace them, clear the extension's storage, or uninstall it. Imported rows follow the trade-fill rules in the retention section below. The extension sends data only to the TradeLoop API; the hosting providers named in the recipients and sub-processors section process it under the same controls as other trade imports.
§ 06
Who receives your data — recipients and sub-processors
We use a small set of carefully-selected third-party services ("sub-processors") to deliver TradeLoop. Each is bound by a written Data Processing Agreement (where required) and is listed publicly. The full register is at /sub-processors with vendor, purpose, data categories, hosting jurisdiction, risk tier, and DPA-execution status.
The current list (also in docs/DPIA.md §1.5 and docs/policies/VENDOR_REGISTER.md):
- Render (Singapore) — application hosting, Postgres, Redis, encrypted backups
- Vercel (global edge) — CDN, static frontend hosting
- Cloudflare (global) — DNS, WAF, TLS termination, DDoS protection, and cookie-free aggregate page views / Web Vitals
- Razorpay (India) — payment processing only
- Resend (US) — transactional email (verification, reset, intervention, brief)
- Sentry (US) — error monitoring with PII-scrubber active before-send
- BetterStack (EU / Germany) — uptime monitoring; public probe responses only
- PostHog (US / EU regions) — optional authenticated product-event mirror; not enabled in the current production deploy manifest
- Plausible (EU / Germany) — legacy integration retained in the register, but the browser shim is disabled and sends no data
- Crisp (France) — live chat support, consent-gated
- GitHub (US) — source code and CI hosting; no production user data transits GitHub
We do not sell, license, or rent your personal data. We do not run third-party advertising. We do not feed trade data into unrelated machine-learning pipelines — ours or anyone else's. Brokers (Zerodha, Upstox, Angel One, Dhan, Tradovate, cTrader, MatchTrader, TopstepX, MetaTrader 5) are not sub-processors under GDPR Article 28 — the trader is the data subject and the broker is the source of truth for the trader's own trade data; we ingest from them on your behalf.
We give affected account holders notice before adding a sub-processor where law or contract requires it. You may object by emailing [email protected] and we will work with you in good faith on an alternative.
§ 07
Cross-border data transfers
TradeLoop's primary infrastructure is hosted in Render's Singapore region (ADR-0014 in docs/DECISIONS.md). Some sub-processors operate in other jurisdictions:
For EU / EEA users
Personal data of EU / EEA users is transferred outside the EEA. We rely on Standard Contractual Clauses (SCCs) with each receiving sub-processor, plus a Transfer Impact Assessment per the EDPB's Recommendation 01/2020. SCC execution status by vendor is tracked publicly at /sub-processors and the per-vendor register lives at legal/DPA_REGISTER.md; as of 2026-07-14 this work is in progress with Render, Vercel, Cloudflare, Sentry, Resend, Crisp, and any future enablement of PostHog, and BetterStack. Where SCCs are not yet executed, the relevant processing is suspended for EU / EEA users on request. Email [email protected] to exercise this right.
For UK users
We rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, depending on the vendor's offered form. Execution status as above.
For Indian users
The DPDP Act §16 restricts cross-border transfer to jurisdictions on a Central Government notification list. As of 2026-07-14 Singapore is not on the restricted list; transfer to Render Singapore is permitted. If the restricted-list composition changes, we will migrate or re-paper accordingly.
For California users
We process California residents' data as a "business" under the CCPA / CPRA. We do not sell or share personal information for cross-context behavioural advertising, and we honour the "Do Not Sell or Share" opt-out at the consent banner. California-resident requests (access, deletion, correction, opt-out) follow the same DSR channel as EU users (§9 below).
§ 08
Progress private-beta data boundary
Autopsy processes the statement submitted in the request and does not persist the raw statement. Signed-in traders may keep a derived Autopsy (verdict, sequence, evidence grades, and Constitution references) and one Trading Constitution. Progress Mode is optional, invite-controlled, and requires explicit consent plus an explicit save action. A save stores derived evaluation metrics, evidence summaries, contract rules, comparisons, and recurring-pattern records. It also stores a non-reversible idempotency fingerprint so the same request can be retried safely; it does not store the statement text.
- Analytics: Progress events use a closed, content-free property allowlist. Statement text, trade rows, symbols, credentials, payment details, email, and name are forbidden event properties.
- Invite ledger: a one-way invite-code digest is retained to stop a consumed invite being reused. While Progress is active, a linked participant record stores research status and provenance. After Progress deletion, that linked participant record is deleted; the unlinkable redemption digest remains.
- Feedback: beta feedback and willingness-to-pay research accept predefined categories only. Free-text feedback and free-text willingness notes are not collected by Progress.
- Export: the authenticated Progress export includes profiles, derived evaluations, contracts, rules, comparisons, patterns, beta participation, Progress event rows, and Progress audit records. Its manifest states
raw_statements_stored: false. - Progress deletion: the dedicated control immediately deletes profiles, evaluations, contracts, rules, comparisons, patterns, linked beta participation, and Progress product/tracking events. Subject-linked Progress audit-chain records remain for security and legal integrity under the non-operational audit-retention posture below; the unlinkable invite digest also remains. Progress deletion is narrower than account deletion.
§ 09
How long we keep your data
The table below mirrors docs/DPIA.md §1.6 exactly. Where regulatory holds apply we honour the statutory window; otherwise data is deleted on account erasure within 30 days per the DPDP Act §12 and GDPR Article 17.
| Data | Retention | Trigger to delete |
|---|---|---|
| User account (active) | Indefinite while the account remains active | Account deletion request |
| Trade fills (active user) | Indefinite while account active | Account deletion (cascade) |
| Audit log | Active audit database; no automated expiry currently configured | The planned 365-day active / 7-year archive policy is not operational |
| Interventions / tilt firings | Indefinite while account active | Account deletion (cascade) |
| Broker tokens (Fernet-encrypted) | Until broker is disconnected | Disconnect button OR account deletion |
| Identifiable payment and invoice rows | While account is active | Account deletion after replay tombstone creation |
| De-identified gateway replay tombstone | Current 7-year payment-record policy | Operator purge at policy end; automated expiry is not implemented while checkout is closed. Legal sufficiency and operator purge controls must be confirmed before public checkout is reopened. |
| Marketing email subscription | Until unsubscribe | One-click unsubscribe in every email |
| Consent-gated browser funnel events | 365 days | Expiry or account deletion where linked |
| Authenticated operational product events | 365 days, then aggregate | Account deletion where linked |
| Public Score Cards | Until owner revocation or claimed-account deletion | Public views are aggregate and anonymous. Owner evidence is erased on claimed-account deletion; a subject-free revocation record remains. |
| Historical anonymous cohort snapshots | Retained for historical timeseries | Future snapshots exclude restricted accounts; previously published anonymous snapshots are not rewritten. |
| Sentry session replay | 90 days | Sentry default policy |
| Server logs (Render stdout) | 30 days | Render default policy |
§ 10
Automated decision-making and profiling
TradeLoop's core product is a behavioural-risk detection engine that systematically evaluates your trading against per-trader baselines and triggers automated interventions (email, push notification, signed outbound webhook to your org admin if you are part of a B2B pilot). Specifically, the engine runs ten tilt signatures — revenge sizing, loss-streak escalation, drawdown doubling, overtrading bursts, sizing variance collapse, time-of-day deviation, opening-bell impulse, Friday-afternoon spike, post-win euphoria, drawdown doubling on averaging-down patterns. Every detected pattern fires a dispatch with no human review in the path.
For the purposes of GDPR Article 22 (automated individual decision-making, including profiling) and the DPDP Act §10 (Significant Data Fiduciary profiling obligations), TradeLoop discloses that:
- Right to obtain an explanation: every intervention is accompanied by the evidence trades, the per-trader baseline that the pattern deviated from, and the counterfactual cost estimate. The full structured record is available via
GET /api/v1/me/automated-decisions(Wave 1.1 endpoint, ship target 2026-07-14). - Right to express your point of view: the appeal endpoint at
POST /api/v1/me/automated-decisions/{id}/appealaccepts your reasoning; appeals are reviewed by a human (founder today; customer-success team in the future). - Right to contest the decision: the same appeal endpoint serves this function. If the appeal is rejected, you may lodge a complaint with the supervisory authority in your jurisdiction (§13 below).
- Right to obtain human review: email [email protected] and a human (currently the founder) reviews the disputed intervention within 7 days.
- Right to restriction:
POST /api/v1/me/restrict-processingpauses the tilt engine for your account. Your data is retained but no new interventions fire. While restriction is active, live Pulse and future cohort snapshots exclude your rows, trader counts, and values. Previously published anonymous cohort snapshots are not rewritten.
The full Data Protection Impact Assessment for the engine — covering necessity, proportionality, balancing tests, and residual risks — is at docs/DPIA.md in the public source tree. We do not run any live LLM API call sites; every "AI" surface is deterministic in-house logic (ADR-0023). The limited retrospective review states its evidence boundary directly on the review journey and labels unsupported findings Unverifiable.
§ 11
Your rights as a data subject
You have the rights below under GDPR Articles 15–22 and the DPDP Act §11–§14. For every right we list the endpoint or settings path that fulfils it. Most are self-serve; email [email protected] if anything is unclear or you cannot reach the relevant surface.
- Right of access (GDPR Art 15 / DPDP §11): download a comprehensive machine-readable ZIP of your user-linked data via
GET /api/v1/me/export-data, also available self-serve at Settings → Data. Authentication, revocation, broker, push, invitation, and other bearer secrets are omitted or redacted. If any mandatory data domain cannot be collected, no partial archive is returned. SLA: immediate (typically < 30 seconds for a standard account), regulatory ceiling 30 days. - Right to erasure / right to be forgotten (GDPR Art 17 / DPDP §12): two paths, immediate via
DELETE /api/v1/auth/account(Settings → Data → "Delete my account"; requires typed confirmation and 2FA when enabled), or queued, admin-reviewed viaPOST /api/v1/me/erasure-request(30-day SLA per DPDP §12). The audit-chain record documenting deletion remains in the active audit database, where no automated expiry is currently configured; the planned 365-day active / 7-year archive policy is not operational. The deletion tombstone uses a user-id hash and timestamp rather than the deleted account record. Claimed Score Cards are revoked, unlinked, and stripped of owner evidence and secrets; the slug and revocation status remain. Anonymous unclaimed cards remain controlled by the owner token issued at mint. - Right to data portability (GDPR Art 20): the export above is machine-readable JSON inside a ZIP, including
manifest.jsondescribing every file's schema. - Right to rectification (GDPR Art 16 / DPDP §12): edit your profile in Settings; for trade data, broker-sourced fills are the broker's source of truth — corrections happen at the broker and re-sync. Email [email protected] for anything else.
- Right to restriction of processing (GDPR Art 18):
POST /api/v1/me/restrict-processingpauses the tilt engine — see §8. - Right to object (GDPR Art 21): you may object to any processing relying on legitimate interest (marketing emails, aggregated cohort analytics, error monitoring) at any time. One-click unsubscribe is in every marketing email; cohort-analytics opt-out flows through the restriction endpoint above.
- Right to withdraw consent (GDPR Art 7(3)): consent for analytics, live chat, and Sentry replay is managed by the cookie consent banner. Re-open the banner from
Settings → Privacyto change your choice at any time. - Right to an explanation of automated decisions (GDPR Art 22): see §8 above for the full Art 22 disclosure and the endpoints that satisfy each Art 22(3) safeguard.
- Right to nominate (DPDP §14): under the DPDP Act, an Indian data principal may nominate another individual to exercise their rights in case of death or incapacity. Email [email protected] to register a nomination.
§ 12
Children's data
TradeLoop is a financial-trading product intended for adults 18 years or older. We do not knowingly collect personal data from anyone under 18. If you become aware that a minor has registered, email [email protected] and we will delete the account and all associated data within 7 days. This page does not market to children; the DPDP Act §9 mandate on processing children's data does not apply because we do not knowingly process it.
§ 13
Cookies, tracking, and consent
TradeLoop uses a small set of essential cookies for authentication (JWT and refresh tokens in browser storage) and session management. Browser funnel events remain off until analytics consent. Authenticated operational account events stay first-party under legitimate interest. Sentry session replay and Crisp live chat also remain off until their purposes are granted. Cloudflare Web Analytics runs separately for cookie-free aggregate page views and Web Vitals; it does not use TradeLoop's anonymous or account ids. The legacy Plausible browser shim is disabled. PostHog is not enabled in the current production deploy manifest.
The banner offers three tiers:
- Strict (default): essential storage only. No first-party funnel events, no chat, and no session replay. Cookie-free aggregate Cloudflare measurement still runs separately.
- Balanced: Strict + first-party pseudonymous product / funnel analytics + masked Sentry error replay.
- Full: Balanced + live chat (Crisp), marketing email, and the broker-sync consent ledger toggle. Transactional email remains part of the service regardless of this preset.
Re-open the consent banner from Settings → Privacy → Cookie preferences at any time to change your choice or withdraw consent. We keep a consent ledger of your choice so a regulator requesting proof of opt-in can be served from a single audit-grade record.
§ 14
Personal data breach notification
If a personal data breach is discovered that is likely to result in risk to your rights and freedoms, TradeLoop will notify the relevant supervisory authority within 72 hours of becoming aware per GDPR Article 33 and the DPDP Act §8(6) ("as soon as practicable"). Affected data subjects are notified directly via the email on file within the same window when the breach is likely to result in a high risk to their rights (GDPR Art 34, DPDP §8(7)). The incident is logged blamelessly at /changelog and the post-mortem is published at docs/INCIDENTS.md in our public source tree.
§ 15
Your right to lodge a complaint
If you believe our processing of your personal data infringes the law, you have the right to lodge a complaint with the supervisory authority in your jurisdiction. We would prefer to fix the problem first — please email [email protected] and the Grievance Officer will reply within one business day. The escalation path is yours; we do not gate it.
- EU / EEA residents: the Data Protection Authority in your member state (e.g. CNIL in France, DPC in Ireland, BfDI in Germany — the full list of DPAs is published by the European Data Protection Board).
- UK residents: the Information Commissioner's Office (ICO).
- Indian residents: the Data Protection Board of India under §27 of the Digital Personal Data Protection Act 2023. Until the Board is operationalised, complaints can be addressed via the Ministry of Electronics and Information Technology.
- California residents: the California Attorney General and the California Privacy Protection Agency (CPPA).
§ 16
Contact us about your privacy
All privacy-related correspondence should be addressed to the Grievance Officer at:
Varun · Grievance Officer / Data Protection Officer
[email protected]
For non-privacy legal correspondence, write to [email protected]. Our broader contact lines (founder, support, security disclosure) are at /contact; the public security disclosure policy is at /security.
§ 17
Changes to this policy
Material changes to this Privacy Policy are announced to affected account holders where law or contract requires notice. The version number bumps and the effective date at the top of the page updates. Continued use of TradeLoop after a material change takes effect constitutes acceptance of the updated policy. Older versions are available via the public git history at github.com/tradeloop or on request from [email protected]. If we ever consolidate, fork, or wind down TradeLoop, we will honour the data-portability and erasure rights in §9 above before any data is transferred or destroyed.