Skip to content

Vol. 01 · Sub-Processors

The third parties that touch your data — named, scoped, dated.

The complete list of third-party services TradeLoop uses to deliver its product, with what each one processes, where it's hosted, and the status of our Data Processing Agreement with them.

Last updated · 2026-07-11

§ 01

How we use sub-processors

These are the third-party services TradeLoop uses to deliver its product. Each is bound by a written agreement (a Data Processing Agreement, "DPA") where required by GDPR Article 28, the DPDP Act §11, the UK GDPR, or the California CCPA. The execution status of each DPA is shown in the table below and is updated as new agreements are countersigned.

Before we add a new sub-processor, we notify Pro and Prop Trader subscribers at least 30 days in advance via email and via an updated commit to this page. To object to a new sub-processor, email [email protected] and we will work with you in good faith on an alternative. You may also cancel your subscription at any time per the Cancellation Policy before the new sub-processor's processing begins.

The full vendor inventory (with SOC2 / ISO attestation status, last quarterly review date, and risk-assessment notes) lives internally at docs/policies/VENDOR_REGISTER.md; the executed DPAs are tracked at legal/DPA_REGISTER.md. Both are internal records — for vendor-specific DPA references applicable to your account, email [email protected].

§ 02

Brokers are not sub-processors

TradeLoop integrates with broker APIs (Zerodha Kite Connect, Upstox, Angel One, Dhan, MetaTrader 5 brokers, Tradovate, cTrader, MatchTrader, TopstepX). The integration is two-way: TradeLoop calls these brokers to fetch your trade fills on your behalf, and the brokers send TradeLoop signed webhooks when new trades execute. Brokers are not TradeLoop sub-processors under GDPR Article 28 — you (the trader) are the data subject, the broker is the source of truth for your own trade data, and TradeLoop ingests from them on your behalf with your explicit OAuth / paste-token authorisation. Brokers operate under their own regulatory and privacy frameworks (SEBI in India, FINRA / NFA in the US, etc.) and their own privacy policies apply to your relationship with them.

§ 03

Current sub-processor register

The register below is canonical. The columns are: vendor (with a link to their public privacy policy); the processing purpose; the categories of data they receive; their primary hosting jurisdiction; the risk tier we assign (CRITICAL / HIGH / MEDIUM / LOW per docs/policies/VENDOR_REGISTER.md §1); the DPA execution status; and the date we last reviewed the vendor's posture.

VendorPurposeData categoriesJurisdictionRisk tierDPALast reviewed
RenderApplication hosting (FastAPI + Postgres + Redis + MT5 worker) and encrypted backupsAll user data + broker tokens (encrypted at rest)Singapore (primary) · US (Render HQ)CRITICALNot yet — Wave 0.7 in progress2026-05-14 (initial)
VercelCDN for the React/Vite frontend; edge static asset servingIP addresses, request headers, static asset cacheGlobal edge (CDN)CRITICALNot yet — Wave 0.7 in progress2026-05-14 (initial)
CloudflareDNS, WAF, TLS termination, DDoS protection, and cookie-free aggregate Web AnalyticsIP addresses and request/TLS metadata at the edge; aggregate page views and Web Vitals in Web AnalyticsGlobal edgeCRITICALNot yet — Wave 0.7 in progress2026-07-11 (analytics disclosure review)
RazorpayPayment processing (UPI / cards / wallets) for INR subscribersEmail, billing name, GSTIN, billing address, payment IDs (no raw card data — Razorpay tokenises)IndiaCRITICALStandard merchant DPA — confirmation in progress (Wave 0.7)2026-05-14 (initial)
ResendTransactional email (verification, password reset, intervention notifications, weekly brief)Email addresses, email contentUnited StatesHIGHNot yet — Wave 0.7 in progress2026-05-14 (initial)
SentryError monitoring + session replay (PII-scrubbed before send via app/main.py::_scrub_string)IP, browser metadata, scrubbed error payloads, replay (consent-gated, masked text by default)United StatesHIGHNot yet — Wave 0.7 in progress2026-05-14 (initial)
BetterStackUptime monitoring and public status pagePublic endpoint probe responses; no user PIIEuropean Union (Germany)HIGHNot yet — Wave 0.7 in progress2026-05-14 (initial)
PostHogOptional authenticated product-event mirror; inactive unless a server API key is configuredWhen enabled: user ID and scrubbed event properties; no production deploy key is currently declaredUS + EU regions availableMEDIUMNot yet — Wave 0.7 in progress2026-07-11 (inactive configuration verified)
PlausibleLegacy marketing-analytics integration; browser shim is disabled and retained only for compatibilityNone while disabledEuropean Union (Germany)MEDIUMEU intra-region — DPA verification in Wave 0.72026-07-11 (disabled shim verified)
CrispLive chat support (consent-gated post-Wave 0.1 cookie banner)Visitor IP, email if provided, chat transcriptsEuropean Union (France)MEDIUMNot yet — Wave 0.7 in progress2026-05-14 (initial)
GitHubSource code, CI, dependency scanningCode, CI logs, secrets metadata (no production user data transits GitHub)United StatesLOWCovered by GitHub Customer Agreement2026-05-14 (initial)

Last updated · 2026-07-11. Quarterly review cadence; the next scheduled review is published in docs/policies/VENDOR_REGISTER.md §7.

§ 04

How we handle sub-processor changes

When we add or remove a sub-processor we follow a predictable, customer-friendly process. The exact procedure is documented internally in docs/policies/VENDOR_REGISTER.md §4 (additions) and §5 (offboarding); the commitments surfaced here are the customer-facing summary:

  • 30 days' email notice to every Pro and Prop Trader subscriber before a new sub-processor begins processing. The notice is sent from [email protected] with the subject "TradeLoop sub-processor update — effective <date>".
  • Public page update on this page at the same time as the email notice. Customers who don't open the email can still see the change here.
  • Right to object by emailing [email protected]. We will work with you in good faith on an alternative or, where no alternative is possible, you may cancel your subscription before the new sub-processor takes effect.
  • Vendor offboarding includes API-key revocation, request for confirmation of data destruction per the DPA's data-deletion clause, and a follow-up confirmation email to customers when the vendor's deletion certificate is on file.

§ 05

Change history

The dated history below complements the live register above. When we add or retire a sub-processor we land an entry here in the same commit so a customer auditing the change can reconstruct the timeline.

  • 2026-07-11: initial publication of this page. The sub-processor list above represents the live set of vendors as of this date; it pre-existed but had not been published in this customer-facing format. Future additions and removals will appear below this entry.

Older changes pre-dating this page are tracked internally in docs/policies/VENDOR_REGISTER.md §6 (retired vendors) and §7 (quarterly review log) and are available on request from [email protected].

§ 06

Contact

Questions about a specific sub-processor, the DPA terms we have with them, or your right to object to a new sub-processor — email [email protected]. Our broader privacy notice (data categories, rights, complaint channels) is at /privacy; security disclosure at /security.