Privacy Policy
Last updated: 18 August 2026
This policy explains what personal information TradingSocial collects, how we collect it, why, who we share it with, which countries it goes to, how long we keep it, and what you can do about it. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Read section 4 first if you read nothing else. TradingSocial is a social platform, and a lot of what you create on it is public by default — visible to anyone on the internet, including people without an account.
1. Information we collect
- Account and sign-in: your email address and password. Your password is hashed by our authentication provider; we never see or store it in readable form. If you sign in with Google, we receive your name, email address, profile photo and Google account identifier.
- Profile: username, display name, avatar and cover images, bio, tagline, experience level, the markets and trading styles you select, your account type, your stated goal, your profile colour and any link you add to your card, your XP and level, your profile visibility and leaderboard preference, and the account balance and currency you enter (used to size your risk and to show your results in money).
- Trading journal: the trades you log — instrument, entries and exits, profit/loss, risk multiples, position size, your notes, how you tagged the trade (emotion, confidence, mistakes, strategy), and any chart screenshot you attach.
- Connected trading accounts: if you connect MetaTrader 5, your MT5 login number, broker server and the read-only investor password you supply. If you connect a crypto exchange, the read-only API key and secret you supply. In both cases we then receive your closed trade history from that service. See section 8.
- Payments: your subscription and trial status, your plan and billing period, and a customer reference from our payment provider. We never receive or store your card number. See section 7.
- Social activity: posts and post images, comments, likes, the accounts you follow and who follows you, poll votes, the traders you save, and feature requests, comments and votes on our public roadmap.
- Direct messages: the messages and images you send to other members.
- Reports and moderation: reports you make about another member or a trade, and reports other members make about you.
- Referrals: your referral code, and a record of clicks on your referral link.
- Learning (withdrawn): which lessons you marked complete and any XP awarded for them. Quiz answers were never recorded — quizzes were marked in your browser and the answers were never sent to us. The learning hub is no longer available and no new records are created; the existing records are retained, are included in your data export, and are removed when you delete your account.
- Support and feedback: the message you send, the page you were on, your browser's user-agent string, your screen size, a device class, and the most recent error your browser had logged — the last of these so that we can reproduce the bug you are reporting.
- Technical and usage: your IP address and browser user-agent are recorded against your sign-in sessions. As you use the site we record page views against a random identifier stored in your browser, together with the page path, the referring page, a device class and the campaign source you arrived from.
2. How we collect it
Most of it you give us directly, through forms and uploads. Some is collected automatically as you use the site — the pages you visit, your IP address, your browser and how you arrived. Some comes from other services: your name, email address and photo from Google if you sign in with Google; your closed trade history from MetaApi or your exchange if you connect an account; and your payment status and billing email from Stripe.
3. Why we collect it
To operate the platform and its social and leaderboard features; to authenticate you and keep your account secure; to take payment and work out what your plan includes; to send you account, trial and billing emails and a weekly review of your own trading; to answer support requests; to detect fraud, abuse and manipulation of the leaderboards; to understand how the product is used so we can improve it; to attribute referrals; and to measure and target our advertising. That last purpose is separate from analytics and is described in section 10.
4. What other people can see
Some of what you create is public — visible to anyone on the internet, including people without an account, and to search engines:
- Your profile, if you have it set to public: your display name, username, avatar and cover image, bio, tagline, experience level, markets and trading styles, account type, badge, profile link, XP and level.
- Any trade you mark as public, including its notes and any screenshot attached to it.
- Your posts and post images, your comments, your likes, and the accounts you follow.
Poll votes are private. Only the totals for each option are shown. Nobody — not other members, not anonymous visitors — can see which option you chose. This changed in August 2026; before that, how you voted was readable by anyone.
Visible to other signed-in members: anything you post to the public roadmap.
Private to you: the lessons you completed while the learning hub existed. This also changed in August 2026; before that, any signed-in member could read them.
Private to you and the other participant: your direct messages and their attachments.
Private to you: journal entries you have not marked public, your trading rules, process goals and templates, the traders you save, your notifications, your feedback, your billing details, the credentials for any account you connect, and the account balance you enter. Your stated balance and your payment-provider reference are withheld at the database level from every other user, including signed-in ones.
You can make your profile private, or opt out of the leaderboards, under Settings → Privacy, and each journal entry has its own visibility setting.
5. Who we share your information with
We use the service providers below to run TradingSocial. Each receives only what its job requires.
| Provider | What it receives | Why | Where it is processed |
|---|---|---|---|
| Supabase | Your account, profile, trades, messages, uploaded files and session records | Database, authentication and file storage | Australia — Sydney. Supabase Inc. is a United States company, and its support and platform logs are held there |
| Vercel | Every request you make: IP address, browser, page address and cookies | Hosting for the website and the app | United States |
| Stripe | Your email address and account identifier; and, entered by you directly on Stripe's own page, your name, billing address and card details | Subscription payments. We never receive or store your card number | United States, European Union and India |
| Resend | Your email address and the content of the emails we send you — the weekly review email contains your own trading statistics | Sending account, billing and summary emails | United States |
| MetaApi (Agilium Labs LLC) | If you connect MT5: your MT5 login number, broker server and investor password, and your closed trade history | Automatic MT5 trade sync. We never store your investor password | United States (Wyoming); the connected account is hosted on a node that defaults to the United Kingdom |
| Binance | If you connect an exchange: the read-only API key and secret you supply, and your fill history | Automatic crypto trade sync | Lithuania and globally; our sync runs from Singapore |
| Your IP address, browser, the pages you view and an analytics identifier; and, if you sign in with Google, your name, email address and profile photo | Product analytics and Google sign-in | United States and globally | |
| Meta (Facebook) | Your IP address, browser and the pages you view on our marketing site; and, when you complete signup or subscribe, a one-way hash of your email address and account identifier | Advertising measurement and matching | United States and Ireland. Meta also routes pixel events through a forwarding endpoint it operates in Oregon, United States |
| The same as Meta. Our servers also send Reddit a signup or purchase event directly, but only if you turned on Advertising in section 10. That event no longer contains your IP address | Advertising measurement and matching | United States | |
| Twelve Data | The instrument names you search for. Nothing that identifies you is sent — the request comes from our server, not your browser | Symbol search and live prices | Singapore |
Meta, Google and Reddit use what they receive for their own advertising purposes as well as ours.
On "selling" your information. We have never sold your personal information and we receive no money for it. Rather than rely on the word, here is what we actually do: if you turn on Advertising in section 10, we send Meta and Reddit a one-way hash of your email address so that they can match you to an advertising audience. Under some overseas privacy laws that counts as "selling" or "sharing". It does not happen unless you turn it on, and section 10 tells you how to turn it back off.
We also disclose personal information where we are required or permitted to by law, and to other members and the public as described in section 4.
6. Where your information goes
Your account and everything in it is stored in Australia, in a database hosted in Sydney. The providers in section 5 are, or may be, located in the United States, the United Kingdom, Ireland, Singapore, Lithuania and India, and Google processes data globally. The most sensitive single transfer we make is the MT5 investor password described in section 8, which leaves Australia.
We rely on each provider's published privacy terms and security commitments. We have not separately negotiated a data-processing agreement with every provider on that list. Under Australian Privacy Principle 8.1 we remain accountable to you for how an overseas recipient handles information we disclose to it, and you can complain to us about that under section 16.
7. Payments
Subscriptions are billed through Stripe. When you start a checkout we send Stripe your email address and your account identifier. You then enter your card number, name and billing address on a page hosted by Stripe. Those details never pass through our servers and we never store them. What we keep is your plan, your subscription status and period dates, and a customer reference. Prices, renewal, cancellation and refunds are covered by our subscription terms.
If you have ever paid us, Stripe keeps your invoices and charge history after you delete your account — see section 13.
8. Connected trading and exchange accounts
MetaTrader 5. To sync your trades automatically we ask for your MT5 account number, your broker's server, and your read-only investor password, which can view an account but cannot place trades or move funds. We pass it once to MetaApi (Agilium Labs LLC, a United States company), the service that runs the sync for us and which holds it to keep the connection alive. We do not store it ourselves — it is never written to our database. MetaApi hosts the connected account on a node that defaults to the United Kingdom, so your broker login is held outside Australia. We were not able to locate a privacy policy published by MetaApi at a public address; if that matters to you, do not connect an MT5 account. Disconnecting the broker in Settings removes the account and the password from MetaApi, and so does deleting your TradingSocial account.
Crypto exchanges. If you connect an exchange we ask for a read-only API key. We encrypt the key and secret with AES-256-GCM before storing them; the encryption key is held in our server environment and never in the database, so a copy of the database on its own cannot read them. They are never displayed back to you, and the columns holding them are readable by no user account of any kind. We use them from a server in Singapore to read your fills. Only you can revoke a key at the exchange — if you delete your account we delete our encrypted copy, but you should revoke the key at the exchange as well.
9. Direct messages
Direct messages are readable by you and the person you are talking to. The database enforces that: a request for a conversation you are not part of is refused. Images you attach are stored in a private, non-public store and are served only through a route that re-checks you are a participant and then issues a short-lived link. Messages are not end-to-end encrypted — we can access them where we need to in order to investigate abuse or to comply with the law.
One consequence you should know about: deleting your account deletes your conversations, including the messages the other person sent in them.
10. Cookies, analytics and advertising
| Cookie or identifier | Set by | Purpose | Expiry |
|---|---|---|---|
sb-* | TradingSocial | Keeps you signed in. Essential | Session |
ts_ref | TradingSocial | Remembers who referred you | 30 days |
ts_consent | TradingSocial | Remembers your choice below. Essential — without it we would have to ask you on every page | 180 days |
ts_anon_id (browser storage) | TradingSocial | Links your visits before and after you sign up | 180 days, then a new one is generated |
ts_internal (browser storage) | TradingSocial | Marks a browser as ours, so our own visits are excluded from analytics | Until you clear site data |
_ga, _ga_* | Google Analytics | How the site is used | 13 months |
_fbp, _fbc | Meta | Advertising measurement | Up to 90 days |
rdt_cid, _rdt_uuid, _rdt_em | Advertising measurement | 90 days |
Your choice, and what it actually does. On your first visit we show a notice at the bottom of the page with three buttons. You can change your mind at any time using the Cookie settings link in the footer of any page. There are two groups:
- Analytics — Google Analytics and our own usage counts. On unless you turn it off. This tells us which pages people use. If you turn it off, Google Analytics is never loaded, we stop recording your visits entirely, and the identifiers above are deleted from your browser.
- Advertising — the Meta and Reddit pixels. Off unless you turn it on. We changed this: these used to load on every visit. They now do not load at all unless you choose them, because they send identifiers to advertising companies that let those companies recognise you across other sites.
Declining is not cosmetic. The scripts are not loaded, no request is made to Google, Meta or Reddit, and any identifiers they had already set are deleted. You can also block or delete cookies in your browser settings, and Google, Meta and Reddit each offer their own opt-outs.
The part your browser cannot control, and what we did about it. When you complete signup or subscribe, our servers — not your browser — can send Reddit a record of that event. Because it is sent server-to-server, no cookie setting, ad blocker or browser control can prevent it. Two things follow from that:
- We only send it if you turned Advertising on. Your choice above governs this server-side event as well, which is the only way it can be governed at all.
- We no longer send Reddit your IP address. We previously sent it unmodified. We stopped. If we ever re-enable it for advertising measurement it will be sent only as a one-way hash, never in a readable form.
What that event contains when it is sent: a one-way hash of your email address, a one-way hash of your account identifier, and the amount if it was a purchase. If you would rather be excluded from it entirely regardless of the setting, email us at onetradingsocial@gmail.com and we will exclude your account.
Meta's conversions gateway. When the Meta pixel is loaded, Meta's own script also sends event data to a forwarding endpoint Meta operates on Amazon Web Services in Oregon, United States (with a backup on Google Cloud in Iowa). This is configured by Meta on their side, not by us. It is included in what turning Advertising off prevents.
11. Security
What we actually do:
- Your data is stored in Australia and encrypted in transit.
- Every table in our database has row-level security, so the database itself refuses a request for another person's records rather than relying on the application to remember.
- Only the fields needed to render a public profile are readable by other users. Your account balance, payment reference and notification settings are readable by you alone.
- Trade screenshots and message attachments are held in a private store that is not reachable from the internet, and are served only through a route that re-checks permission and issues a short-lived link.
- Exchange API keys are encrypted with AES-256-GCM using a key held outside the database.
- Your MT5 investor password is never stored by us at all.
- Passwords are hashed by our authentication provider and are never stored in readable form.
- Staff access to account records is restricted; email addresses are masked by default, and every time one is revealed it is written to an audit log that cannot be edited or deleted.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. If something goes wrong
If a data breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner, as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). We will tell you what happened, what information was involved, and what you should do about it.
13. How long we keep your information
| Information | How long we keep it |
|---|---|
| Your account, profile, trades, posts, comments, direct messages and uploaded images | Until you delete your account. We do not delete inactive accounts |
| Feature requests and comments you post to the public roadmap | Kept after you delete your account, with your name removed, so the roadmap stays readable |
| Moderation reports made about your account | 3 years from the report, or until the matter is resolved, whichever is longer. After you delete your account these are kept against a one-way salted hash of your email address rather than your name — see below |
| Usage and analytics records | 12 months. If you never created an account, these records are deleted outright at 12 months. If you have an account, the browser identifier is removed from them at 12 months and what remains — an event name, a device class, a campaign source and a date — is no longer linked to you or to your other visits, and we keep that indefinitely as a count. The identifiers are also removed immediately if you delete your account, and the identifier in your browser is replaced with a new one every 180 days |
| Billing records | Held by Stripe. Australian record-keeping law requires records explaining a transaction to be kept for five years |
| Administrator access records | 24 months. The database refuses to alter or delete one inside that window |
| Emails we have sent you | Held in our email provider's sending logs, on their retention schedule |
Why we keep moderation reports. If a member is reported for suspicious or abusive behaviour, deleting the account should not erase the report — otherwise the way to clear a record would be to delete the account and sign up again. So when an account is deleted we keep the report's reason, detail, status and date, and replace the identity with a one-way salted hash of the email address. We cannot turn that hash back into an email address, no member can read these records, and we use them only to prevent fraud and abuse. Our lawful basis is our legitimate interest in preventing fraud and abuse on the platform.
How these periods are enforced. Usage and analytics records, administrator access records and moderation reports are now deleted automatically by a job that runs every day. Billing records are held by our payment provider on their schedule, and sent email is held by our email provider on theirs. Everything in the first row of the table above is kept until you delete your account, and is removed by the deletion itself rather than by a timer.
One thing we should be straight about. A few smaller records — your in-app notifications, the click record on your referral link, and our own internal system alerts — have no stated period above and no automatic deletion. They are removed when you delete your account. We would rather say that than quietly set a period we had not told you about.
14. Deleting your account
You can delete your account yourself at any time under Settings → Your data. You will be asked to type your email address, and your password if your account has one. Deletion is immediate, there is no grace period, and it cannot be undone. Your email address is released, so you are free to sign up again later.
Deleting your account:
- cancels an active subscription immediately and detaches your card, so nothing further can be charged. The unused part of a period you have already paid for is not refunded — see section 11 of the Terms. If you want the time you have paid for, cancel first and delete later;
- removes any connected MT5 account from MetaApi, together with the investor password it was holding;
- deletes every image you have uploaded — avatars, cover images, post images, trade screenshots and message attachments — from both of our storage locations;
- removes the identifiers from your usage records, including visits from before you signed up, so they can no longer be linked to you or to each other;
- deletes your login and, with it, your profile, trades, posts, comments, likes, follows, poll votes, saved traders, trading rules, goals, templates, notifications, subscription record and your conversations.
We send you a confirmation email listing what was removed and what was kept.
What we cannot delete for you. Some companies hold identifiers that we have no way to delete on your behalf. We would rather tell you than imply otherwise:
- Stripe keeps your invoices and charge history if you ever paid, because Australian tax law requires records explaining a transaction to be kept. Your subscription is cancelled and your card detached, so nothing further can be charged. If you never paid, your customer record is deleted outright.
- Meta holds browser-level advertising identifiers from pages you visited. There is no deletion request we can send for you; you can remove it yourself under Facebook Settings → Your activity off Meta technologies.
- Reddit holds a hashed version of your email address, if you had Advertising turned on. It no longer receives your IP address from us at all. Reddit provides no per-user deletion endpoint. Email us and we will pass the request on.
- Google Analytics holds browser-level analytics identifiers from the marketing site. Clearing cookies for tradingsocial.io stops any further association; email us if you want us to lodge a deletion request with Google.
- Resend holds copies of the emails we sent you, including your address, in its sending logs. These age out on its own schedule; email us if you want them removed sooner.
- If you connected a crypto exchange, we delete our encrypted copy of your API key, but only you can revoke the key at the exchange. Please do that too.
What we keep, and why, is in section 13.
15. Accessing, correcting and downloading your information
You can edit most of what we hold about you yourself, at any time, in Settings, and you can download a copy under Settings → Your data → Export my data. That export covers your profile, trades, posts, comments, likes, follows, feedback, trading rules, subscription record, lesson completions and connected broker.
The export does not yet cover everything we hold. Direct messages, notifications, usage records, poll votes, saved traders, process goals, trade templates and feature requests are not in it. If you want those, or anything else, ask us and we will provide it.
To request access to, or correction of, personal information you cannot reach yourself, email us at onetradingsocial@gmail.com. We will acknowledge your request within 5 business days and respond within 30 days, as Australian Privacy Principle 12 requires. There is no charge for making a request.
16. Complaints
If you think we have mishandled your personal information, email us at onetradingsocial@gmail.com with the word "privacy" in the subject line. We will acknowledge within 5 business days and give you a written answer within 30 days.
If you are not satisfied with our answer, you can take the complaint to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
17. Children
TradingSocial is not directed at people under 18, our Terms require you to be at least 18, and we do not knowingly collect the personal information of anyone younger. We do not verify age at signup, so this depends on the account holder being honest with us. If you believe someone under 18 has an account, tell us and we will close it and delete their information.
18. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top reflects the latest version. If a change materially affects how we handle information we already hold about you, we will tell you by email.
August 2026 update: this policy was rewritten end to end. It now names every service provider that receives personal information and the country each one processes it in; describes payments, connected broker and exchange accounts, direct messages, and what is public by default; states our retention periods per category and the records we keep after account deletion; describes what deleting your account actually does, and what we cannot delete for you; adds a Notifiable Data Breaches clause and response timeframes for access, correction and complaints; and corrects two earlier statements — that browser settings control all of our tracking, and that deleting your account required contacting us.
Privacy questions or requests? Contact us at onetradingsocial@gmail.com.
