PRIVACY POLICY
Last updated: May 29, 2026
TradingPact (“we,” “us,” or “our”) operates the TradingPact platform, a trading discipline enforcement service. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website and services.
1. Information We Collect
We collect the following categories of information:
Account information
- Name, email address, and authentication credentials managed through Better Auth, our authentication system.
- Profile image, if you choose to add one to your account.
Brokerage credentials & connection data
- MetaAPI account tokens used to connect your MT4/MT5 broker account. These tokens are provided by MetaAPI’s secure system — we do not collect or store your broker login username or password directly.
- API keys generated for trade-intent evaluation are hashed using SHA-256 before storage. We never store raw API keys at rest.
Trading data
- Brokerage account metadata (account name, broker name, equity, balance).
- Open positions, trade history, and P&L data obtained through your broker connection via MetaAPI.
- Position snapshots captured during real-time enforcement monitoring.
- Daily P&L aggregations and discipline streak records.
Risk pact & discipline data
- Pact configurations (rule types, thresholds, lock durations).
- Risk audit records for every trade evaluation — including the decision (ALLOW, SOFT_ALLOW, or DENY), triggered rules, and source (trade intent or enforcement).
- Unlock request history, including escalation levels and partner approvals.
Journal entries
- Emotional tags, trade notes, and screenshots you attach to journal entries. This content is entirely user-generated and optional.
Usage & analytics data
- Pages visited, features used, and interaction patterns collected via PostHog for product analytics.
- Anonymized page load performance data collected via Google Analytics.
Payment information
- Subscription and billing data processed by Stripe. We do not store your full credit card number — Stripe handles all payment data in accordance with PCI DSS standards.
2. How We Use Your Data
We use collected information to:
- Enforce your trading pacts — evaluate trade intents against locked policies and return ALLOW/SOFT_ALLOW/DENY decisions.
- Monitor live positions — if you enable real-time enforcement, we monitor open positions via MetaAPI WebSocket streaming and may force-close positions that violate your locked rules.
- Track discipline — generate P&L analytics, discipline streaks, and risk audit history.
- Facilitate accountability — share relevant pact and violation data with your designated accountability partners, if you configure them.
- Send transactional notifications — unlock requests, pact violations, partner approvals, and subscription confirmations via email.
- Process payments — manage your subscription and billing through Stripe.
- Improve the product — analyze aggregated, anonymized usage patterns to improve features and performance.
- Monitor errors — capture and resolve application errors via Sentry to maintain service reliability.
We do not sell your personal data or trading data to third parties. We do not use your trading data for any purpose other than providing and improving the TradingPact service.
3. Third-Party Services
We integrate with the following third-party services, each governed by their own privacy policies:
- MetaAPI (metaapi.cloud) — broker connection for MT4/MT5 accounts. MetaAPI handles the secure connection to your broker and provides us with account data and position streams. We do not transmit your broker password to MetaAPI; you connect directly through their provisioning flow.
- Better Auth — authentication, user management, and session handling.
- Stripe (stripe.com) — payment processing and subscription management. Stripe is PCI DSS Level 1 certified.
- PostHog (posthog.com) — product analytics and feature usage tracking. You may opt out via browser settings.
- Vercel (vercel.com) — hosting, deployment, and web analytics.
- Sentry (sentry.io) — error tracking and performance monitoring. Error reports may contain request metadata but are stripped of sensitive trading data.
- Resend (resend.com) — transactional email delivery for notifications and alerts.
- Neon (neon.tech) — serverless PostgreSQL database hosting with encryption at rest.
4. Data Storage & Security
Your data is stored in a PostgreSQL database hosted on Neon with encryption at rest and in transit. All API communications use HTTPS/TLS.
We implement the following security measures:
- API key hashing — trade-intent API keys are hashed using SHA-256 before storage. Raw keys are only shown once at creation time and cannot be recovered.
- Encryption in transit — all data transmitted between your browser, our servers, and third-party services uses TLS encryption.
- Rate limiting — API endpoints are rate-limited via Upstash Redis to prevent abuse.
- Bot detection & application shield — Arcjet provides bot detection and application-level security.
- Secure token generation — all secrets and tokens use cryptographically secure random generation.
We do not store your broker login credentials (username/password). Broker connections are established through MetaAPI’s secure token-based system.
5. Cookies
We use cookies for essential functionality and analytics:
- Session cookies (essential) — used to maintain your authenticated session. These are necessary for the service to function and cannot be disabled.
- Analytics cookies (optional) — placed by PostHog to understand product usage patterns. You may disable these in your browser settings or use a tracking blocker.
- Performance cookies (optional) — placed by Google Analytics to measure page load performance. These collect anonymized performance data only and are gated by your cookie consent choice.
6. Data Retention
We retain your trading data and account information for as long as your account is active. When you delete your account:
- All personal data, trading data, pact configurations, risk audits, journal entries, and analytics are permanently deleted via cascading database deletion.
- Stripe subscription data is handled per Stripe’s retention policies.
- Authentication data is removed when your account is deleted.
- Anonymized, aggregated analytics data (which cannot identify you) may be retained for product improvement.
If you cancel your subscription without deleting your account, your data remains accessible for 30 days. After that period, or upon explicit deletion request, we permanently remove all personal and trading data from our systems.
7. Your Rights
You have the right to:
- Access — request a copy of all personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Deletion — request permanent deletion of your account and all associated data. You can initiate this from your account settings or by contacting us.
- Portability — export your trading data, risk audit history, and journal entries in a standard format.
- Opt-out — disable non-essential analytics tracking via browser settings or by contacting us.
To exercise any of these rights, contact us at contact@tradingpact.com. We will respond to your request within 30 days.
8. Accountability Partners
If you designate an accountability partner or coach, they will have limited access to:
- Your pact configurations and lock status.
- Unlock request history and whether they need to approve or deny an unlock.
- Aggregate discipline metrics (streaks, violation counts).
Partners do not have access to your broker credentials, API keys, financial details, or journal entries. You can revoke partner access at any time from your pact settings.
9. Children’s Privacy
TradingPact is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will promptly delete it.
10. International Data Transfers
Your data may be processed and stored in countries where our service providers operate (including the United States and European Union). By using TradingPact, you consent to the transfer of your data to these jurisdictions. We ensure that all transfers are protected by appropriate security measures and contractual safeguards.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will notify you via email and update the “last updated” date at the top of this page. Continued use of the service after changes constitutes acceptance of the revised policy.
12. Contact
If you have questions about this Privacy Policy or how we handle your data, contact us at contact@tradingpact.com.