TradinSolutionsEXECUTION LAYER
Start Free Trial →
HOME/LEGAL

Policies, plainly stated.

Nine documents covering the agreement, the risks, your money, your data and the rules of the community. Written to be read, not to be scrolled past.

Privacy Policy

UPDATED 20 SEP 2026

What we collect, why we are allowed to collect it, who else sees it and what you can do about it. Data Requests explains how to exercise the rights described here.

Who is responsible for your data

TradinSolutions is the controller of the personal data described in this policy, which means we decide what is collected and why, and we are the party you can hold to this policy. TradinSolutions is the trading name of a sole trader — an eenmanszaak under Dutch law, which means an individual rather than an incorporated company — registered with the Netherlands Chamber of Commerce (Kamer van Koophandel) under KvK number 42152786, at Tonkensstraat 55, 9723 ZV Groningen, Netherlands. We are subject to the EU General Data Protection Regulation. Privacy questions and rights requests go to legal@tradinsolutions.com, to contact@tradinsolutions.com, to the support desk, or by post to the address above, and Data Requests sets out the process.

What we collect

Your name and email address; your billing details, which are collected and processed by Stripe — we never see or store your card number; the connection data needed to run the Platform, which means the trading-account identifiers you connect, the tokens or encrypted credentials that keep those connections alive, and the trades, positions and account state those connections read; the content you create on the Platform, such as journal entries, rules, goals and copier configurations; your support messages; the record of what you agreed to at checkout, which is described in its own section below; and basic technical and usage records such as your account's activity on the Platform and the error logs our systems produce.

The record we keep of your checkout acknowledgement

When you subscribe, you tick a box asking us to begin supplying the service immediately and acknowledging that this ends your fourteen-day right of withdrawal. The law asks us, not you, to be able to show later that you gave that acknowledgement, so we record it: the exact wording you agreed to, the date and time, the plan and billing cycle it was given for, the purchase it belongs to, and the network address and browser the acceptance was sent from. The network address is personal data and we keep it for that one purpose — it is not used to profile you, it is not combined with anything else, and it is not shared. Our basis for keeping it is our legal obligation to be able to evidence the acknowledgement, and our legitimate interest in being able to answer a payment dispute fairly.

Platform connections and credentials — stated exactly

Different trading platforms offer different sign-in methods, and we use the most protective one each platform supports. Where a platform offers OAuth, you sign in on the platform's own site and we never see your password — we hold only the access and refresh tokens it issues, encrypted at rest. Where a platform supports only credential login, the credentials you give us are encrypted at rest and used solely to maintain your connection and place the trades your configuration calls for. For MetaTrader accounts, the password you enter is passed to our execution provider to open the connection and is not stored in our own database. Where a venue is connected by API key, the key and secret are encrypted at rest in the same way.

What we do not do with it

We do not sell your personal data. We do not share your trading data with other members. We do not use your journal entries, your trades or your account balances to train a model, and we do not send them to an AI provider except where a feature you have used says plainly that it does so.

Why we are allowed to process it

Account, subscription and connection data is processed because it is necessary to perform our contract with you. Security records, error logs and fraud prevention are processed on the basis of our legitimate interest in keeping the Platform safe and working. Marketing email is processed on the basis of your consent, which you can withdraw at any time from the unsubscribe link in any such email. Where the law requires us to keep a record — a tax record in particular — the basis is our legal obligation.

What we use it for

Running the web application and your member account; opening and maintaining your platform connections and running the background workers that execute and reconcile copied trades; taking payment and managing your subscription; answering support tickets; keeping the Platform secure and diagnosing faults; and, if you have opted in, telling you about product updates and launches.

Who else processes it

Stripe, our payment processor, which handles payment and the billing portal. An execution provider, which opens and maintains broker connections and executes trades. Our hosting, database and background-processing providers, which run the application, store its data and run the workers behind it. Email providers, which deliver transactional email and, separately, opt-in product email. An AI provider, for the features that state they use one. Each acts on our instructions under a data-processing agreement. The identity of the execution and AI providers is available on request.

Transfers outside the EEA

Some of these processors are established outside the European Economic Area, or process data there. Where that happens and the law requires a safeguard, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism, together with encryption in transit and at rest.

How long we keep it

Your account content stays while your account is open. When you close your account, live activity stops at once and your journal, rulebook and goals are erased after a thirty-day grace window, which exists so an accidental or coerced closure can be reversed. Connection credentials and tokens are deleted when you disconnect the account they belong to. Invoices and other financial records are kept for the period Dutch tax and accounting law requires business records to be kept. The checkout acknowledgement described above is kept for as long as a claim about that purchase could still be brought, because it exists to answer exactly such a claim, and it survives the closure of your account for that reason. Support messages are kept for as long as is reasonably needed to resolve and evidence the request.

Security

Access tokens, API secrets and stored platform credentials are encrypted at rest with authenticated encryption, traffic is encrypted in transit, and administrative access is restricted to the accounts that need it. No system is perfectly secure, and we will tell you and the supervisory authority about a breach affecting your data where the law requires it.

Children

The Platform is not for anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us personal data, tell us and we will delete it.

Cookies

The cookies the Platform sets, and what each one is for, are described in the Cookie Policy.

Your rights

You can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, object to processing based on our legitimate interest, withdraw a consent you have given, and ask for a portable copy of the data you provided to us. Data Requests explains how, and what we need from you. You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the supervisory authority where you live.

Changes

If this policy changes materially we will update the date above and tell active members by email.

← REFUND & CANCELLATION POLICYCOOKIE POLICY →