Privacy policy
Who we are
Trading Desk ("we", "us") is run by Luca Cox-Lasnier, trading as Trading Desk, 26 Hampson Close, Milton Keynes, MK13 9DG, United Kingdom. We are the controller of your personal data. Contact: lcoxlasnier@gmail.com.
What we collect
- Account details: your email address and a securely hashed password (we never see your password).
- Your journal (Pro only): trades, results, notes, tags, moods, checklist settings, prop firm rules and screenshots you choose to add. On the Free plan, or without an account, this stays in your browser and never reaches us.
- Subscription details: your plan, subscription status, renewal date and a Stripe customer reference. Card details are handled by Stripe; we never see or store your full card number.
- Billing and tax information that Stripe collects at checkout, such as your name, country and postcode.
- Support messages you send us.
- Technical data: login session tokens kept in your browser so you stay signed in, and basic server logs (such as IP address and time of request) kept by our hosting providers for security.
Why we use it, and our legal basis
- To provide the app, your account, syncing and your subscription: performance of a contract.
- To keep billing and tax records: legal obligation.
- To keep the service secure, prevent fraud and abuse, and fix problems: legitimate interests.
- To send service emails (for example receipts, payment problems or changes to these terms): performance of a contract. We will only send marketing emails if you have agreed, and you can unsubscribe at any time.
We don't sell your data, show ads, or use your trading journal for anything other than running the app for you.
Who we share it with
- Supabase: database, login and file storage for accounts and synced data.
- Stripe and Link (Stripe’s checkout service): payment processing, subscriptions, invoices, receipts and tax. For Pro purchases Link acts as the merchant of record, so it is also responsible for the payment data it collects under its own privacy notice.
- Netlify: hosts the website.
- Professional advisers, or authorities where the law requires it.
High impact news comes from a public economic calendar feed; none of your personal data is sent to it.
Some of these providers may process data outside the UK. Where they do, they use approved safeguards such as the UK International Data Transfer Agreement or Addendum, or adequacy regulations.
How long we keep it
- Account and journal data: until you delete your account. Deleting it removes your synced data and screenshots straight away; copies in our providers' routine backups are overwritten within 30 days.
- Billing records: 6 years, as required for tax.
- Support messages: up to 2 years after your last message.
Your rights
You can ask to access, correct, delete or receive a copy of your data, or object to or restrict how we use it. Much of this you can do yourself: Settings → Your data → Download backup gives you a full copy, and Delete my account erases your account.
How to make a request or complaint
For anything else about your data, including a complaint about how we have used it, contact us in any of these ways:
- In the app: account menu → Help & feedback → Data & privacy
- On our website: the contact form, choosing Data & privacy request or complaint
- By email: lcoxlasnier@gmail.com
We will acknowledge a complaint within 30 days of receiving it, look into it properly, keep you updated and tell you the outcome without undue delay. We will answer data requests within one month; if a request is complex or we receive several from you, we may extend this by up to two further months and will tell you why. To protect your account, we may ask you to confirm your identity first, usually by replying from the email address on your account. Requests are free unless they are clearly unfounded or excessive.
If you are unhappy with our response, you can complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113). We'd appreciate the chance to sort it out first.
How we keep your data safe
- All connections to the app and website are encrypted (HTTPS).
- Database rules make sure each account can only ever read its own data; support messages can be sent but not read back by anyone except us.
- Passwords are handled by our login provider and stored only in securely hashed form.
- Our admin accounts use two-factor authentication, and secret keys are kept on the server, never in the app.
- To stop spam, messages sent through our forms are stored with a scrambled (hashed) form of the sender's connection address, which we can't turn back into the original.
If something goes wrong
If we ever have a personal data breach that is likely to put your rights at risk, we will report it to the ICO within 72 hours of becoming aware of it, and if the risk to you is high we will tell you directly without undue delay, explaining what happened and what you can do.
Cookies and browser storage
We only use essential browser storage: to keep you signed in, remember your settings and, on the Free plan, save your journal on your device. We don't use advertising or tracking cookies.
Children
Trading Desk is for adults. You must be 18 or over to use it.
Changes
If we change this policy in a way that matters, we'll tell you in the app or by email before it takes effect.