1) Who We Are (Controller)
TradeCanvas (“we”, “us”, “our”) is the controller of your personal data when you use our website and the no-code trading automation platform (the “Service”).
2) Data We Collect
- Account: name, email, password hash, country/region, communication preferences.
- Broker Connections: OAuth tokens or investor credentials (encrypted at rest), account IDs, connection status.
- Product Data: strategies/bots metadata, presets, templates, backtests, logs and events generated by your bots.
- Usage & Device: pages, buttons, timestamps, IP (for security), browser/OS, crash reports.
- Billing: subscription plan, invoices, masked payment info (handled by our processor).
- Support: messages, attachments, and context you provide.
3) How We Use Data
- Provide and improve the Service (e.g., strategy builder, execution, analytics, templates).
- Authenticate you, maintain security, detect fraud/abuse, investigate incidents.
- Process subscriptions, billing, and account changes.
- Send transactional messages (alerts, logs, confirmations). Marketing only with your consent where required.
- Comply with legal obligations and enforce our Terms.
4) Legal Bases (GDPR/UK GDPR)
We process your data based on one or more of: performance of a contract (providing the Service), legitimate interests (product security, analytics), consent (optional communications), and legal obligations.
5) Cookies & Analytics
We use essential cookies for login/session and optional analytics to understand product usage. You can control cookies in your browser. Some features may not function without essential cookies.
6) Sharing & Processors
We share data with trusted service providers (e.g., hosting, analytics, email, payments) under data processing agreements. We may disclose information if required by law or to protect rights, users, or the Service. We do not sell personal data.
7) Security
We apply industry-standard measures such as encryption at rest for credentials, role-based access, and monitoring. No method is 100% secure; you are responsible for safeguarding your account.
8) Data Retention
We retain data for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. You can request deletion where applicable (see “Your Rights”).
9) International Transfers
Where data is transferred internationally, we use appropriate safeguards (e.g., SCCs) consistent with applicable law.
10) Your Rights
- Access, rectify, or delete your personal data.
- Portability, restriction, and objection (including to direct marketing).
- Withdraw consent at any time (where processing is based on consent).
- Lodge a complaint with your local supervisory authority.
To exercise rights, contact privacy@tradecanvas.app. We may need to verify your identity.
11) Children
The Service is not directed to children under 16. We do not knowingly collect such data. If you believe we have, contact us to delete it.
12) Changes to this Policy
We may update this Privacy Policy. Material changes will be posted with a new “Last updated” date. Continued use indicates acceptance.
13) Contact
Privacy questions? Email privacy@tradecanvas.app. For legal terms, see our Terms & Conditions. For risk, review our Risk Disclaimer.
