§ 01
How we use sub-processors
These are the third-party services TradeLoop uses to deliver its product. Each is bound by a written agreement (a Data Processing Agreement, "DPA") where required by GDPR Article 28, the DPDP Act §11, the UK GDPR, or the California CCPA. The execution status of each DPA is shown in the table below and is updated as new agreements are countersigned.
Before we add a new sub-processor, we notify Pro and Prop Trader subscribers at least 30 days in advance via email and via an updated commit to this page. To object to a new sub-processor, email [email protected] and we will work with you in good faith on an alternative. You may also cancel your subscription at any time per the Cancellation Policy before the new sub-processor's processing begins.
The full vendor inventory (with SOC2 / ISO attestation status, last quarterly review date, and risk-assessment notes) lives internally at docs/policies/VENDOR_REGISTER.md; the executed DPAs are tracked at legal/DPA_REGISTER.md. Both are internal records — for vendor-specific DPA references applicable to your account, email [email protected].
§ 02
Brokers are not sub-processors
TradeLoop integrates with broker APIs (Zerodha Kite Connect, Upstox, Angel One, Dhan, MetaTrader 5 brokers, Tradovate, cTrader, MatchTrader, TopstepX). The integration is two-way: TradeLoop calls these brokers to fetch your trade fills on your behalf, and the brokers send TradeLoop signed webhooks when new trades execute. Brokers are not TradeLoop sub-processors under GDPR Article 28 — you (the trader) are the data subject, the broker is the source of truth for your own trade data, and TradeLoop ingests from them on your behalf with your explicit OAuth / paste-token authorisation. Brokers operate under their own regulatory and privacy frameworks (SEBI in India, FINRA / NFA in the US, etc.) and their own privacy policies apply to your relationship with them.
§ 03
Current sub-processor register
The register below is canonical. The columns are: vendor (with a link to their public privacy policy); the processing purpose; the categories of data they receive; their primary hosting jurisdiction; the risk tier we assign (CRITICAL / HIGH / MEDIUM / LOW per docs/policies/VENDOR_REGISTER.md §1); the DPA execution status; and the date we last reviewed the vendor's posture.
| Vendor | Purpose | Data categories | Jurisdiction | Risk tier | DPA | Last reviewed |
|---|---|---|---|---|---|---|
| Render | Application hosting (FastAPI + Postgres + Redis + MT5 worker) and encrypted backups | All user data + broker tokens (encrypted at rest) | Singapore (primary) · US (Render HQ) | CRITICAL | Not yet — Wave 0.7 in progress | 2026-05-14 (initial) |
| Vercel | CDN for the React/Vite frontend; edge static asset serving | IP addresses, request headers, static asset cache | Global edge (CDN) | CRITICAL | Not yet — Wave 0.7 in progress | 2026-05-14 (initial) |
| Cloudflare | DNS, WAF, TLS termination, DDoS protection, and cookie-free aggregate Web Analytics | IP addresses and request/TLS metadata at the edge; aggregate page views and Web Vitals in Web Analytics | Global edge | CRITICAL | Not yet — Wave 0.7 in progress | 2026-07-11 (analytics disclosure review) |
| Razorpay | Payment processing (UPI / cards / wallets) for INR subscribers | Email, billing name, GSTIN, billing address, payment IDs (no raw card data — Razorpay tokenises) | India | CRITICAL | Standard merchant DPA — confirmation in progress (Wave 0.7) | 2026-05-14 (initial) |
| Resend | Transactional email (verification, password reset, intervention notifications, weekly brief) | Email addresses, email content | United States | HIGH | Not yet — Wave 0.7 in progress | 2026-05-14 (initial) |
| Sentry | Error monitoring + session replay (PII-scrubbed before send via app/main.py::_scrub_string) | IP, browser metadata, scrubbed error payloads, replay (consent-gated, masked text by default) | United States | HIGH | Not yet — Wave 0.7 in progress | 2026-05-14 (initial) |
| BetterStack | Uptime monitoring and public status page | Public endpoint probe responses; no user PII | European Union (Germany) | HIGH | Not yet — Wave 0.7 in progress | 2026-05-14 (initial) |
| PostHog | Optional authenticated product-event mirror; inactive unless a server API key is configured | When enabled: user ID and scrubbed event properties; no production deploy key is currently declared | US + EU regions available | MEDIUM | Not yet — Wave 0.7 in progress | 2026-07-11 (inactive configuration verified) |
| Plausible | Legacy marketing-analytics integration; browser shim is disabled and retained only for compatibility | None while disabled | European Union (Germany) | MEDIUM | EU intra-region — DPA verification in Wave 0.7 | 2026-07-11 (disabled shim verified) |
| Crisp | Live chat support (consent-gated post-Wave 0.1 cookie banner) | Visitor IP, email if provided, chat transcripts | European Union (France) | MEDIUM | Not yet — Wave 0.7 in progress | 2026-05-14 (initial) |
| GitHub | Source code, CI, dependency scanning | Code, CI logs, secrets metadata (no production user data transits GitHub) | United States | LOW | Covered by GitHub Customer Agreement | 2026-05-14 (initial) |
Last updated · 2026-07-11. Quarterly review cadence; the next scheduled review is published in docs/policies/VENDOR_REGISTER.md §7.
§ 04
How we handle sub-processor changes
When we add or remove a sub-processor we follow a predictable, customer-friendly process. The exact procedure is documented internally in docs/policies/VENDOR_REGISTER.md §4 (additions) and §5 (offboarding); the commitments surfaced here are the customer-facing summary:
- 30 days' email notice to every Pro and Prop Trader subscriber before a new sub-processor begins processing. The notice is sent from
[email protected]with the subject "TradeLoop sub-processor update — effective <date>". - Public page update on this page at the same time as the email notice. Customers who don't open the email can still see the change here.
- Right to object by emailing [email protected]. We will work with you in good faith on an alternative or, where no alternative is possible, you may cancel your subscription before the new sub-processor takes effect.
- Vendor offboarding includes API-key revocation, request for confirmation of data destruction per the DPA's data-deletion clause, and a follow-up confirmation email to customers when the vendor's deletion certificate is on file.
§ 05
Change history
The dated history below complements the live register above. When we add or retire a sub-processor we land an entry here in the same commit so a customer auditing the change can reconstruct the timeline.
- 2026-07-11: initial publication of this page. The sub-processor list above represents the live set of vendors as of this date; it pre-existed but had not been published in this customer-facing format. Future additions and removals will appear below this entry.
Older changes pre-dating this page are tracked internally in docs/policies/VENDOR_REGISTER.md §6 (retired vendors) and §7 (quarterly review log) and are available on request from [email protected].
§ 06
Contact
Questions about a specific sub-processor, the DPA terms we have with them, or your right to object to a new sub-processor — email [email protected]. Our broader privacy notice (data categories, rights, complaint channels) is at /privacy; security disclosure at /security.