Privacy Policy

This policy explains what personal information TradingSocial collects, how we collect it, why, who we share it with, which countries it goes to, how long we keep it, and what you can do about it. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Read section 4 first if you read nothing else. TradingSocial is a social platform, and a lot of what you create on it is public by default — visible to anyone on the internet, including people without an account.

1. Information we collect

2. How we collect it

Most of it you give us directly, through forms and uploads. Some is collected automatically as you use the site — the pages you visit, your IP address, your browser and how you arrived. Some comes from other services: your name, email address and photo from Google if you sign in with Google; your closed trade history from MetaApi or your exchange if you connect an account; and your payment status and billing email from Stripe.

3. Why we collect it

To operate the platform and its social and leaderboard features; to authenticate you and keep your account secure; to take payment and work out what your plan includes; to send you account, trial and billing emails and a weekly review of your own trading; to answer support requests; to detect fraud, abuse and manipulation of the leaderboards; to understand how the product is used so we can improve it; to attribute referrals; and to measure and target our advertising. That last purpose is separate from analytics and is described in section 10.

4. What other people can see

Some of what you create is public — visible to anyone on the internet, including people without an account, and to search engines:

Poll votes are private. Only the totals for each option are shown. Nobody — not other members, not anonymous visitors — can see which option you chose. This changed in August 2026; before that, how you voted was readable by anyone.

Visible to other signed-in members: anything you post to the public roadmap.

Private to you: the lessons you completed while the learning hub existed. This also changed in August 2026; before that, any signed-in member could read them.

Private to you and the other participant: your direct messages and their attachments.

Private to you: journal entries you have not marked public, your trading rules, process goals and templates, the traders you save, your notifications, your feedback, your billing details, the credentials for any account you connect, and the account balance you enter. Your stated balance and your payment-provider reference are withheld at the database level from every other user, including signed-in ones.

You can make your profile private, or opt out of the leaderboards, under Settings → Privacy, and each journal entry has its own visibility setting.

5. Who we share your information with

We use the service providers below to run TradingSocial. Each receives only what its job requires.

Meta, Google and Reddit use what they receive for their own advertising purposes as well as ours.

On "selling" your information. We have never sold your personal information and we receive no money for it. Rather than rely on the word, here is what we actually do: if you turn on Advertising in section 10, we send Meta and Reddit a one-way hash of your email address so that they can match you to an advertising audience. Under some overseas privacy laws that counts as "selling" or "sharing". It does not happen unless you turn it on, and section 10 tells you how to turn it back off.

We also disclose personal information where we are required or permitted to by law, and to other members and the public as described in section 4.

6. Where your information goes

Your account and everything in it is stored in Australia, in a database hosted in Sydney. The providers in section 5 are, or may be, located in the United States, the United Kingdom, Ireland, Singapore, Lithuania and India, and Google processes data globally. The most sensitive single transfer we make is the MT5 investor password described in section 8, which leaves Australia.

We rely on each provider's published privacy terms and security commitments. We have not separately negotiated a data-processing agreement with every provider on that list. Under Australian Privacy Principle 8.1 we remain accountable to you for how an overseas recipient handles information we disclose to it, and you can complain to us about that under section 16.

7. Payments

Subscriptions are billed through Stripe. When you start a checkout we send Stripe your email address and your account identifier. You then enter your card number, name and billing address on a page hosted by Stripe. Those details never pass through our servers and we never store them. What we keep is your plan, your subscription status and period dates, and a customer reference. Prices, renewal, cancellation and refunds are covered by our subscription terms.

If you have ever paid us, Stripe keeps your invoices and charge history after you delete your account — see section 13.

8. Connected trading and exchange accounts

MetaTrader 5. To sync your trades automatically we ask for your MT5 account number, your broker's server, and your read-only investor password, which can view an account but cannot place trades or move funds. We pass it once to MetaApi (Agilium Labs LLC, a United States company), the service that runs the sync for us and which holds it to keep the connection alive. We do not store it ourselves — it is never written to our database. MetaApi hosts the connected account on a node that defaults to the United Kingdom, so your broker login is held outside Australia. We were not able to locate a privacy policy published by MetaApi at a public address; if that matters to you, do not connect an MT5 account. Disconnecting the broker in Settings removes the account and the password from MetaApi, and so does deleting your TradingSocial account.

Crypto exchanges. If you connect an exchange we ask for a read-only API key. We encrypt the key and secret with AES-256-GCM before storing them; the encryption key is held in our server environment and never in the database, so a copy of the database on its own cannot read them. They are never displayed back to you, and the columns holding them are readable by no user account of any kind. We use them from a server in Singapore to read your fills. Only you can revoke a key at the exchange — if you delete your account we delete our encrypted copy, but you should revoke the key at the exchange as well.

9. Direct messages

Direct messages are readable by you and the person you are talking to. The database enforces that: a request for a conversation you are not part of is refused. Images you attach are stored in a private, non-public store and are served only through a route that re-checks you are a participant and then issues a short-lived link. Messages are not end-to-end encrypted — we can access them where we need to in order to investigate abuse or to comply with the law.

One consequence you should know about: deleting your account deletes your conversations, including the messages the other person sent in them.

10. Cookies, analytics and advertising

Your choice, and what it actually does. On your first visit we show a notice at the bottom of the page with three buttons. You can change your mind at any time using the Cookie settings link in the footer of any page. There are two groups:

Declining is not cosmetic. The scripts are not loaded, no request is made to Google, Meta or Reddit, and any identifiers they had already set are deleted. You can also block or delete cookies in your browser settings, and Google, Meta and Reddit each offer their own opt-outs.

The part your browser cannot control, and what we did about it. When you complete signup or subscribe, our servers — not your browser — can send Reddit a record of that event. Because it is sent server-to-server, no cookie setting, ad blocker or browser control can prevent it. Two things follow from that:

What that event contains when it is sent: a one-way hash of your email address, a one-way hash of your account identifier, and the amount if it was a purchase. If you would rather be excluded from it entirely regardless of the setting, email us at onetradingsocial@gmail.com and we will exclude your account.

Meta's conversions gateway. When the Meta pixel is loaded, Meta's own script also sends event data to a forwarding endpoint Meta operates on Amazon Web Services in Oregon, United States (with a backup on Google Cloud in Iowa). This is configured by Meta on their side, not by us. It is included in what turning Advertising off prevents.

11. Security

What we actually do:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. If something goes wrong

If a data breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner, as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). We will tell you what happened, what information was involved, and what you should do about it.

13. How long we keep your information

Why we keep moderation reports. If a member is reported for suspicious or abusive behaviour, deleting the account should not erase the report — otherwise the way to clear a record would be to delete the account and sign up again. So when an account is deleted we keep the report's reason, detail, status and date, and replace the identity with a one-way salted hash of the email address. We cannot turn that hash back into an email address, no member can read these records, and we use them only to prevent fraud and abuse. Our lawful basis is our legitimate interest in preventing fraud and abuse on the platform.

How these periods are enforced. Usage and analytics records, administrator access records and moderation reports are now deleted automatically by a job that runs every day. Billing records are held by our payment provider on their schedule, and sent email is held by our email provider on theirs. Everything in the first row of the table above is kept until you delete your account, and is removed by the deletion itself rather than by a timer.

One thing we should be straight about. A few smaller records — your in-app notifications, the click record on your referral link, and our own internal system alerts — have no stated period above and no automatic deletion. They are removed when you delete your account. We would rather say that than quietly set a period we had not told you about.

14. Deleting your account

You can delete your account yourself at any time under Settings → Your data. You will be asked to type your email address, and your password if your account has one. Deletion is immediate, there is no grace period, and it cannot be undone. Your email address is released, so you are free to sign up again later.

Deleting your account:

We send you a confirmation email listing what was removed and what was kept.

What we cannot delete for you. Some companies hold identifiers that we have no way to delete on your behalf. We would rather tell you than imply otherwise:

What we keep, and why, is in section 13.

15. Accessing, correcting and downloading your information

You can edit most of what we hold about you yourself, at any time, in Settings, and you can download a copy under Settings → Your data → Export my data. That export covers your profile, trades, posts, comments, likes, follows, feedback, trading rules, subscription record, lesson completions and connected broker.

The export does not yet cover everything we hold. Direct messages, notifications, usage records, poll votes, saved traders, process goals, trade templates and feature requests are not in it. If you want those, or anything else, ask us and we will provide it.

To request access to, or correction of, personal information you cannot reach yourself, email us at onetradingsocial@gmail.com. We will acknowledge your request within 5 business days and respond within 30 days, as Australian Privacy Principle 12 requires. There is no charge for making a request.

16. Complaints

If you think we have mishandled your personal information, email us at onetradingsocial@gmail.com with the word "privacy" in the subject line. We will acknowledge within 5 business days and give you a written answer within 30 days.

If you are not satisfied with our answer, you can take the complaint to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

17. Children

TradingSocial is not directed at people under 18, our Terms require you to be at least 18, and we do not knowingly collect the personal information of anyone younger. We do not verify age at signup, so this depends on the account holder being honest with us. If you believe someone under 18 has an account, tell us and we will close it and delete their information.

18. Changes to this policy

We may update this policy from time to time. The "last updated" date at the top reflects the latest version. If a change materially affects how we handle information we already hold about you, we will tell you by email.

August 2026 update: this policy was rewritten end to end. It now names every service provider that receives personal information and the country each one processes it in; describes payments, connected broker and exchange accounts, direct messages, and what is public by default; states our retention periods per category and the records we keep after account deletion; describes what deleting your account actually does, and what we cannot delete for you; adds a Notifiable Data Breaches clause and response timeframes for access, correction and complaints; and corrects two earlier statements — that browser settings control all of our tracking, and that deleting your account required contacting us.