Privacy Policy
1. Who is the data controller
The data controller for the purposes of the EU General Data Protection Regulation (“GDPR”) and the Swiss Federal Act on Data Protection (“FADP”) is:
- Dannon Jake von und zu Liechtenstein, sole proprietor operating TraderReflect
- St. Gallen, Switzerland
- Privacy questions and data-subject requests: privacy@traderreflect.com
- General support: support@traderreflect.com
- Legal notices: legal@traderreflect.com
- Security disclosures: security@traderreflect.com
There is currently no requirement for us to appoint a Data Protection Officer (DPO) under FADP Art. 10 or GDPR Art. 37; we will do so if that ever changes.
2. What personal data we collect
The tables below list every category of personal data we hold, why we hold it, and the legal basis under GDPR Art. 6(1) / FADP Art. 31. Where we mention specific technical field names (e.g. signupIp), these are the exact fields in our database.
2.1 Account and identity
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, name, profile image (avatar), time zone, language preference | Create and maintain your account; personalise the interface; send transactional email | Contract (Art. 6(1)(b)) |
| Hashed password (never stored in plaintext; bcrypt cost factor 12) | Authenticate you when you sign in with a password | Contract |
| Multi-factor authentication credentials: WebAuthn/passkey public keys and counters, encrypted TOTP secret (AES-256-GCM), enrollment timestamps | Protect your account against unauthorised access | Contract + legitimate interest in security (Art. 6(1)(f)) |
Signup and login metadata: IP address, browser user-agent, Accept-Language header, timestamps of first signup and last login | Fraud prevention; account-cluster analysis (see Section 6); investigating unauthorised access attempts | Legitimate interest |
| Failed-MFA attempt counter and lockout timestamp | Rate-limit brute-force attempts against your MFA | Legitimate interest in security |
2.2 Trading, journal, and analytics data
| Data | Purpose | Legal basis |
|---|---|---|
| Every trade you log or import: symbol, direction, entry/exit prices, quantity, P&L, R-multiples, timestamps, session dates, associated broker account | Populate your journal and derive your analytics | Contract |
Trade edit history: every field you change on a trade, with old and new values and a timestamp (TradeEditLog) | Give you an auditable history of your journal; help resolve support issues | Legitimate interest |
| Per-trade notes and metadata: rich-text notes, tags, self-grades, mood entries, per-rule adherence grades, screenshots (see Section 4) | Journal + analytics + gamification features you interact with | Contract |
| Daily journal content: pre-market plan, EOD review, day mood, day comments (with screenshots), bias, key levels, checklist ticks | Same as above | Contract |
| Playbook: setups, rules, per-day rule grades, playbook adherence history | Same as above | Contract |
| Broker/prop-firm account metadata: account name, broker name, prop-firm name, account size, starting balance. Broker credentials: if you connect Tradovate, you enter your Tradovate username and password on our sign-in form; those values are forwarded over TLS to Tradovate’s authentication endpoint and the access token Tradovate returns is what we store (not the plaintext password). If a future broker integration cannot be authenticated this way, the disclosure here will be updated before that broker is available to users. | Import your trade history; identify which account each trade belongs to | Contract |
Onboarding responses: chosen broker, primary account type, account size band, typical strategy, playbook setups and rules picked from the starter templates (Playbook.tradingSetup) | Personalise your dashboard, discipline habits, and starter playbook | Contract |
| Prop-firm account balance history | Track your drawdown against firm limits | Contract |
| Derived analytics: profit factor, win rate, drawdown, R distributions, discipline scores, TraderReflect Score axes, weekly / monthly aggregates | Show you the analytics you signed up for | Contract |
2.3 Gamification and rewards
| Data | Purpose | Legal basis |
|---|---|---|
| Reflect Points balance, transaction history, and tier | Deliver the points and tier system | Contract |
| Achievements unlocked, streaks, weekly challenges | Same as above | Contract |
| Reward redemptions (which items you redeemed, when, for how many points) | Fulfil rewards; keep audit trail of payouts | Contract |
| Cashback ledger: amounts, Stripe charge / payout IDs, payment fingerprints tied to each cashback event | Deliver cashback correctly; prevent double payouts; investigate disputes | Contract + legitimate interest in fraud prevention |
2.4 Referrals
| Data | Purpose | Legal basis |
|---|---|---|
| Your referral code, who you referred, who referred you, status of each referral, cash earned, and any payout notes | Attribute referrals; pay out referral rewards | Contract |
| Public referral preview: your first name and last initial may be shown to someone landing on the site with your referral code, so they can see who invited them | Give referred users a human-readable attribution | Legitimate interest; you can request removal of this preview by emailing us |
2.5 Payments
| Data | Purpose | Legal basis |
|---|---|---|
| Stripe customer ID and subscription ID | Bill your subscription; link the Stripe portal to your account | Contract |
| Payment method fingerprint — a hash returned by Stripe that uniquely identifies your payment method without revealing the card number | Prevent multi-account trial abuse; power the account-clustering system in Section 6 | Legitimate interest in fraud prevention (Art. 6(1)(f)) |
| Subscription status: current plan, period start / end, trial dates, most recent payment-failure timestamp, lifetime amount paid | Show your subscription state and gate paid features | Contract |
| Dispute / chargeback timestamps | Handle disputes and prevent repeat abuse | Legal obligation + legitimate interest |
Stripe Identity KYC data (government-issued photo ID, selfie / liveness check, and the verification result) — collected only when you initiate a large cashback payout (currently the ≥ $50 threshold, per the Rewards catalogue). The ID document and selfie are handled entirely by Stripe on Stripe’s infrastructure; TraderReflect receives only the pass/fail result and a verification timestamp (User.kycVerifiedAt). | Prevent cashback fraud on high-value payouts; comply with anti-money-laundering obligations that apply to payout services | Legitimate interest in fraud prevention + legal obligation |
2.6 Preferences and notifications
| Data | Purpose | Legal basis |
|---|---|---|
| Your notification preferences (per notification type), your marketing opt-out status, opt-in state for the public leaderboard, saved comparisons, breakeven threshold and other display preferences, AI Coach consent flag | Respect your choices about how the Service behaves and communicates with you | Contract; consent for marketing (Art. 6(1)(a)) |
| In-app notifications delivered to your bell icon (with a 30-day TTL sweep) | Feature functionality | Contract |
2.7 Accountability + social
| Data | Purpose | Legal basis |
|---|---|---|
| Accountability pairings (if you opt into a pair) with another user for shared discipline tracking | Feature functionality; requires mutual opt-in | Consent |
| Leaderboard entry (name, avatar, tier, discipline score, streak, weekly P&L) — opt-in only, off by default | Show the leaderboard to other logged-in users who choose to view it | Consent (you flip Opt in to leaderboard in Settings) |
| Optional shared P&L cards you generate for social sharing | Feature you explicitly invoke; you control what is included | Consent |
2.8 Support and marketing surfaces
| Data | Purpose | Legal basis |
|---|---|---|
| Waitlist entries (email, optional name, optional referral code, optional source) | Notify you when signups open | Consent |
| Support contact submissions (name, email, message, and your user ID if signed in) | Reply to your question | Legitimate interest (handling your own inquiry) |
3. What personal data we do NOT collect
- We do not collect biometric data beyond the WebAuthn public keys you register voluntarily as a second factor.
- Analytics that are shown to you (the TraderReflect Score, discipline scores, tier, performance metrics) are informational and do not automatically enrol or exclude you from anything. Automated decisions that DO produce a legal or similarly significant effect are limited to three narrowly-scoped systems — account clustering, Discipline Certification gating on Major cashback redemptions, and revenge-trade flagging — each described in Section 6b together with your right to a human review.
- We do not use behavioural advertising cookies or third-party ad networks.
- We do not track your activity across other websites.
- We do not sell personal data to any third party.
- We do not use your data to train general-purpose machine-learning models.
Note on tables enumerated above. Some smaller records (import batches, trade edit history, saved-comparison snapshots, feature-flag participation, accountability-pair invites, weekly-challenge progress, announcement dismissals, processed webhook receipts) are not itemised in Section 2 but are captured in the export you receive via the POST /api/user/export endpoint. If a table is not there and you believe it should be, email privacy@traderreflect.com.
4. Screenshots and uploaded files
Screenshots you attach to trades, day comments, or notebook entries, and files you upload via the journal, are stored in a private object bucket at our storage provider (Supabase Storage, hosted on AWS in the region configured in our Supabase project). Objects live under a path prefix scoped to your user ID (journal/<yourUserId>/…) and are served exclusively via short-lived signed URLs (4-hour TTL, subject to change).
Access enforcement is server-side: our sign endpoint verifies that the requesting session owns the underlying storage path before minting a signed URL. Because the URL contains a cryptographic token, do not share a signed URL with anyone you would not want to see the image — anyone with the URL can view the file until the token expires.
5. Cookies
We only use cookies that are strictly necessary to run the Service (authentication and security). We do not use analytics or advertising cookies. See our Cookie Policy for the full list.
6. Anti-abuse profiling
We automatically group accounts that share characteristics such as IP address, payment- method fingerprint, user-agent, and language header. These groupings are called “account clusters” internally and are used to detect trial abuse (one person creating multiple accounts to stack trials, referral bonuses, or cashback), payment fraud, and coordinated attacks against the Service.
The legal basis for this is our legitimate interest under GDPR Art. 6(1)(f) in preventing fraud and protecting the Service. Clusters are used only for internal risk review; they are not shown to other users. You may request information about your cluster membership under Section 8 (Your rights).
Effect on rewards. If your cluster is under review or has been classified as suspected abuse, cashback payouts and Major reward redemptions from your account may be paused pending human review by an administrator. You may request an explanation of the pause and dispute the classification by writing to privacy@traderreflect.com; see Section 6b.
6b. Automated decisions with significant effects
Three narrowly-scoped systems produce decisions that affect real value or your ability to use parts of the Service. GDPR Art. 22 gives you the right to obtain human intervention, to express your point of view, and to contest each of these decisions. Contact privacy@traderreflect.com to invoke that right.
| System | What it does | Effect | Human review path |
|---|---|---|---|
| Account clustering | Groups accounts sharing IP, payment fingerprint, user-agent, and locale headers to flag likely multi-account abuse. | Cashback payouts and Major reward redemptions may be paused while the cluster is under review; a confirmed-abuse classification can lead to account suspension. | Email privacy@. A human administrator will review the flag against the underlying signals within 10 business days and either release the pause or provide a written explanation. |
| Discipline Certification | Daily job (/api/cron/discipline-cert) evaluates your rolling discipline score, journaling streak, and rule-adherence against three numeric thresholds and sets User.disciplineCertActive to true or false. | The certificate is REQUIRED for Major reward redemptions (cashback ≥ $50, funded- account credits, large gift cards). Without it, Major redemptions are blocked; Minor redemptions remain available. | Email privacy@ with a summary of your recent activity. A human will recompute against the criteria manually and, where automation misread a break or journal entry, restore certification. |
| Revenge-trade flagging | The src/lib/revenge-detection.ts heuristic flags a trade as a “revenge trade” when its pattern matches signals like rapid re-entry after a loss, over-sized re-entry, or repeated same-symbol chase behaviour. The flag is stored on the trade with a confidence score. | Flagged trades count against the “No revenge trades” discipline habit for that day, which lowers the day’s discipline score and, indirectly, the points and tier progress you earn. | You can dispute a flag by editing or deleting the trade. To dispute the heuristic itself, email privacy@; a human will review the flagged trade against the algorithm’s reasons and clear it if appropriate. |
7. Administrative access and impersonation
A small, explicitly allow-listed group of TraderReflect administrators can:
- view your account’s data as part of support, debugging, or abuse review;
- reset your password (which forces a re-authentication or a password-reset flow);
- grant or revoke complimentary Pro access;
- export or delete your account when you request it in writing;
- temporarily impersonate your account — that is, view the Service as you see it and, where necessary, take actions as your account. Impersonation is gated behind multi-factor authentication and a 30-minute admin step-up session, is time-limited, and is recorded in an internal audit log.
This is a real capability, not a hypothetical one. Every administrative action is logged with the admin’s identity, the time, the action, and the target user; this log survives account deletion so we can investigate abuse retrospectively.
8. Your rights
Under the GDPR and Swiss FADP, you have the following rights with respect to your personal data:
- Access — obtain a copy of the personal data we hold about you. You can do this yourself from Settings → Data & Privacy → Export my data; the download is a comprehensive JSON dump covering every table where you have data.
- Rectification — correct inaccurate or incomplete data. Most fields are editable directly in the Service (Settings, Profile, per-trade edit dialogs).
- Erasure — delete your account and associated data. Use Settings → Danger Zone → Delete account. Deletion is immediate: your User row is removed and every user-owned row cascades with it; your screenshots are purged from private storage as part of the same request.
- Portability — receive your data in a structured, machine-readable format. The JSON export in Settings is exactly this.
- Objection — object to processing based on legitimate interest, including profiling for anti-abuse. Email privacy@traderreflect.com if you wish to object; we will assess whether we have overriding legitimate grounds and respond within thirty (30) days.
- Restriction — request that processing be limited while a request is being handled.
- Withdraw consent — where processing is based on consent (marketing, leaderboard opt-in, accountability pairing, AI Coach), you may withdraw at any time from the relevant settings toggle without affecting the lawfulness of processing before withdrawal.
- Complain to a supervisory authority — the competent authority in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch. If you reside in the EU/EEA, you may also contact the supervisory authority in your country of residence.
We do not charge for these requests and will respond within one month of receipt. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse, as permitted by GDPR Art. 12(5).
8b. California, Virginia, Colorado, and other US state residents
If you are a resident of a US state with a comprehensive consumer-privacy law (California CCPA/CPRA, Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MTCDPA, and equivalents), you have specific enumerated rights under those laws. In substance they mirror the GDPR rights in Section 8: the right to know what we collect, the right to correct, the right to delete, the right to portability, the right to opt out of the “sale” or “sharing” of personal data for cross-context behavioural advertising, the right to opt out of automated decision-making of the kind described in Section 6b, and the right to non-discrimination for exercising these rights.
TraderReflect does not sell personal data, does not share personal data for cross-context behavioural advertising, does not use sensitive personal data (as defined by these laws) for advertising, and does not knowingly process the data of anyone under the age of 18. Requests under any of the state laws can be sent to privacy@traderreflect.com. We do not currently accept authorised-agent requests via API; a written signed authorisation from you is required. We respond within the 45-day window each of these laws requires.
9. Data retention
| Category | Retention |
|---|---|
| Account data, trades, notes, journals, playbook, gamification, screenshots | For the life of your account; erased when you delete your account |
| Payments, subscription, and cashback records | Kept for as long as required by Swiss commercial and tax law (currently ten (10) years for accounting records under OR Art. 958f), even after account deletion, in a minimised form linked only to your original user ID |
| Admin audit log entries (any admin action taken on any user) | Retained indefinitely; needed for security investigations and evidence integrity |
| Successful admin login attempts (admin email, IP, user-agent, timestamp) | Retained for up to 24 months for security monitoring, then purged |
| Failed admin login attempts, including attempts against non-existent admin emails (logged so we can spot enumeration attacks) | Retained for up to 90 days, then purged |
| Support conversations | Support messages sent via the in-app contact form are NOT persisted in our application database — they are forwarded via email to our support inbox (currently Google Workspace) with delivery through Resend. Retention of the message body is therefore governed by the retention policies of Google Workspace + Resend (typically up to 24 months) and by our own inbox-cleanup practice. TraderReflect has no reliable purge mechanism for messages already delivered to the inbox. |
| Referral cash ledger and payout notes | Retained for the accounting retention period above |
| Notifications delivered to your bell icon | Automatically purged after 30 days by a scheduled sweep |
10. Sub-processors and third parties
We use the following service providers (“sub-processors”) to run the Service. Each has been chosen for its security posture and offers standard contractual clauses or the EU-U.S. Data Privacy Framework (DPF) for any international transfers where applicable.
| Provider | Role | What they see |
|---|---|---|
| Vercel Inc. (US) | Application hosting + edge network. Currently deployed to Vercel’s London (lhr1) region. | Every request to the Service, including your IP address and browser headers. Payload contents are TLS-encrypted end-to-end. |
| Vercel Analytics + Speed Insights (US) | Aggregate page-view counts and Core Web Vitals | Cookieless. Aggregate, anonymised traffic metrics only. |
| Supabase Inc. (US, with EU / regional hosting depending on project region) | PostgreSQL database + object storage for screenshots | All persisted user data (encrypted at rest by the underlying cloud provider). Storage bucket is private; objects are served only via signed URLs. |
| Stripe, Inc. (US) | Payment processing, subscription management, tax calculation | Your name, email, billing address, payment method, and transaction history for your subscription. Stripe is PCI-DSS Level 1 certified. |
| Stripe Identity (US) — only when you initiate a large cashback payout | Government-ID document scan, selfie / liveness check, verification result | The ID and selfie are handled entirely on Stripe’s infrastructure; we receive only a pass/fail result and a verification timestamp. Not invoked for any other flow — only Major cashback redemptions above the payout threshold. |
| Resend (US) | Transactional email (verification codes, MFA alerts, trial reminders, support inbox delivery) | Recipient email address, name, and the content of the email we send you. |
| Upstash Inc. (US, multi-region) | Redis-backed rate limiting and short-lived caches | Keyed identifiers (your user ID or IP address) and rate-limit counters. No trade or journal content. |
| Google (US, EU) | (1) Optional social sign-in via Google OAuth. (2) Google Fonts — four typefaces (Inter, Outfit, JetBrains Mono, DM Mono) are loaded from fonts.googleapis.com and fonts.gstatic.com when you first visit the Service. (3) Google Workspace hosts our support / legal / security email addresses; messages you send to us pass through Google’s mail servers. | OAuth: email + basic profile at consent time (only if you use it). Google Fonts: your IP address + browser User-Agent on the initial font request, no cookies, no account identifier — cached in your browser for one year so the request does not repeat on subsequent visits. Google Workspace mail: the content of any support / legal email you send us. See the Google Fonts Privacy FAQ and Google’s general Privacy Policy. |
| Financial Modeling Prep (US) — server-side only | Economic-calendar data source (news / events shown on the dashboard) | Our server sends a request for scheduled economic events. Your IP is not shared — the request originates from Vercel’s infrastructure, not your browser. |
| Yahoo Finance (US) — server-side only | Live ticker / instrument-price data source | Server-side proxy fetch. Your IP is not shared with Yahoo. |
| Cloudflare, Inc. (US) — optional | Edge cache for the ticker proxy when the TICKER_PROXY_URL env var is configured | Cached ticker responses only. No user-identifiable data touches the worker. |
| Anthropic PBC (US) — when the AI Coach is enabled | Generates coaching responses based on your trading data | Only enabled per user with explicit consent (Settings → Preferences → AI Coach). When enabled: a summarised context including recent trades, discipline scores, and journal excerpts is sent to Anthropic’s Claude API to produce a coaching reply. Anthropic does not train on your data per its API terms.AI Coach output is generated by a probabilistic language model and may contain inaccuracies, hallucinations, or misleading statements — it is not investment or financial advice. See Terms §6.1 for the full disclaimer and liability terms. Current status: AI Coach is disabled by default and no data is sent to any AI provider until you turn it on. |
| Tradovate / NinjaTrader (US) — when you connect a broker | Read-only source of your orders, fills, and account information via OAuth | They see nothing new from us; we receive your trading data from them. |
11. International data transfers
Because our sub-processors are primarily based in the United States, personal data is transferred outside Switzerland and the EEA. We rely on:
- the EU-U.S. Data Privacy Framework (DPF) and its Swiss extension, for providers that are DPF-certified;
- Standard Contractual Clauses (SCCs) approved by the European Commission and recognised by the Swiss FDPIC, for providers that are not DPF-certified;
- the UK adequacy decision, for our primary hosting region (Vercel’s London region).
You may request copies of the relevant transfer safeguards by emailing legal@traderreflect.com.
12. Security
We implement technical and organisational measures appropriate to the risk, including:
- TLS encryption in transit and at-rest encryption at the cloud infrastructure layer;
- bcrypt-hashed passwords with a cost factor of 12;
- optional multi-factor authentication using WebAuthn/passkeys and TOTP;
- AES-256-GCM encryption of TOTP shared secrets at rest;
- a private screenshot bucket with server-verified, short-lived signed URLs;
- rate limiting on authentication, MFA, and other sensitive endpoints;
- separate admin session cookies with a 30-minute step-up requirement for privileged actions, plus admin-login alerts to unfamiliar IPs;
- a tamper-resistant admin audit log for every administrative action.
No system is perfectly secure. If you become aware of a vulnerability, please report it privately to security@traderreflect.com.
12b. Data-breach notification
In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, in line with GDPR Art. 34 and equivalent Swiss FADP obligations. The notification will describe: the nature of the breach, the categories and approximate number of records affected, the likely consequences, the measures we have taken to address it, and the steps you can take to protect yourself. We will also notify the FDPIC (Swiss supervisory authority) and any relevant EU supervisory authorities within the timelines those authorities require.
13. Children
TraderReflect is not intended for and is not offered to persons under the age of eighteen (18). We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has provided us with personal data, please contact us and we will delete it.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make a material change, we will update the “Effective” date at the top of this page and, where the change materially reduces your rights or expands processing beyond what was previously described, we will notify existing users by email or in-app banner at least fourteen (14) days before the change takes effect.
15. Contact
Privacy and data-subject requests: privacy@traderreflect.com. General support: support@traderreflect.com. Legal notices: legal@traderreflect.com. Security disclosures: security@traderreflect.com.