Privacy Policy
1. Data controller
TraderGap, operated from Italy. Contact for privacy matters: legal@tradergap.ai.
2. What we collect
- Account data: email, password (hashed), display name, preferences, plan and trial status.
- Trading data you provide: trades, accounts, strategies, notes, screenshots, psychology check-ins, forecasts, prop-account details.
- Imported / synced data: trade history from CSV files you upload or from broker connections you authorise (read-only).
- Billing data: subscription status, invoices and payment metadata — processed by Stripe. We never receive or store your full card number.
- Support and communications: tickets, messages to our AI help desk, emails you send us.
- Technical data: IP address, device/browser information, log and security data.
- Onboarding survey (optional): trading experience, markets traded, goals.
3. Why we process it, and on what legal basis (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Providing the Service and your account | Performance of a contract |
| Billing, invoicing, tax records | Contract / legal obligation |
| AI analyses you request | Contract (and consent where required for AI terms) |
| Security, fraud and abuse prevention | Legitimate interest |
| Product improvement using aggregated/anonymised data | Legitimate interest |
| Service emails (e.g. billing, security) | Contract |
| Marketing emails, newsletter, waitlist | Consent (withdrawable anytime) |
| Compliance with legal obligations | Legal obligation |
4. Who we share it with (processors)
We use carefully selected providers, each bound by a data-processing agreement, and we share only what is necessary:
- Supabase — database and authentication (hosting region: EU)
- Vercel — application hosting and delivery
- Stripe — payments and subscription billing
- Anthropic — AI processing of the content you submit to AI features
- Resend — transactional and notification emails
- Cloudflare — bot protection (Turnstile)
- MetaApi — MetaTrader read-only account connection (only if you enable it)
- Market and macro data providers (e.g. price and economic-calendar vendors) — these receive queries, not your personal trading data
We do not sell your personal data and we do not share it for third-party advertising.
5. International transfers
Some providers are outside the EEA (for example in the United States). Where that happens, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
6. Retention
We keep your account and trading data for as long as your account exists. After deletion we remove or anonymise your data within a reasonable period, except where we must keep records to meet legal obligations (for example invoices, typically 10 years under Italian tax law). Backups are purged on a rolling schedule.
7. Your rights (GDPR Art. 15–22)
You have the right to access, rectify, erase, restrict, port and object, and to withdraw consent at any time. You can export or delete your data from within the app, or write to legal@tradergap.ai. We respond within one month. You may lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali) or your local authority.
8. Security
Data is encrypted in transit. Database access is protected by row-level security so users can only reach their own records. Passwords are hashed. Access to production systems is restricted. MetaTrader connections use a read-only investor password: we cannot place, modify or close orders, and we never move funds. No system is perfectly secure; we will notify you and the authorities of a personal-data breach as required by law.
9. Children
The Service is not intended for anyone under 18 and we do not knowingly collect their data.
10. Changes
We will post updates here and notify you of material changes.