Privacy Policy
Last updated: 4 August 2026
This Privacy Policy explains how MrTrades (“MrTrades”, “we”, “us”) collects, uses, and shares information when you use mrtrades.com and related domains, APIs, and products (the “Service”). By using the Service you acknowledge this Policy. For how you may use the Service, see our Terms of Service.
1. Who we are
MrTrades operates the Service. For privacy requests, use Portal Support.
2. Information we collect
Depending on how you use the Service, we may process:
- Account & identity — username, email, display name, profile fields, authentication records, MFA/passkey metadata, linked social login identifiers, and session/token data (via MrTrades Auth / Keycloak and related providers)
- Wallets — wallet addresses you link after Auth for HL builder / journal sync; we do not ask for private keys or seed phrases
- Billing — plan tier, invoices, promo/referral codes, payment status, and payment references needed to confirm a purchase. We do not store full card numbers for card processors we do not operate
- Product data — journal trades/notes, preferences, screener/terminal settings, Nexus configs, webhook URLs and delivery metadata, API keys (hashed or prefixed), device/ticker keys and layouts, support messages
- Usage & technical — API usage, IP address, user agent, approximate location from IP, logs, error reports, and performance metrics
- Cookies & local storage — session cookies, auth/PKCE state, and client-side preferences needed to run the Service
Public market data we ingest from venues is not “your” personal data, but may be associated with your account when you save symbols, journals, or alerts.
3. How we use information
We use information to:
- Provide, secure, and improve the Service
- Authenticate users, link wallets, and manage subscriptions and credits
- Operate APIs, webhooks, tape products, and device feeds you enable
- Prevent abuse, debug issues, and monitor reliability
- Communicate about the Service (including support replies and material policy updates)
- Comply with law and enforce our Terms
4. Legal bases (where applicable)
Where privacy laws require a legal basis (e.g. GDPR), we typically rely on: performance of a contract (providing the Service you request); legitimate interests (security, product improvement, fraud prevention); consent where we ask for it; and legal obligation where applicable.
5. Sharing
We may share information with:
- Service providers — hosting, databases, identity (Keycloak/OIDC), email or OAuth providers you choose (e.g. Google, Microsoft, X, Discord), analytics/ops tooling we use to run the Service
- Destinations you configure — webhook endpoints, Discord channels, or devices you connect; those parties process what you send them under their own terms
- Legal / safety — when required by law, or to protect rights, security, or users
- Business transfers — in connection with a merger, acquisition, or asset sale, subject to appropriate safeguards
We do not sell your personal information.
6. Retention
We retain account, billing, journal, and log data for as long as needed to operate the Service, meet legal/accounting needs, resolve disputes, and enforce agreements. You may request deletion of account data via Portal Support; some records (e.g. payment history, security logs) may be retained where required or for legitimate interests.
7. Security
We use technical and organizational measures appropriate to the Service (including access controls, hashed secrets where applicable, and transport encryption). No method of transmission or storage is completely secure.
8. International transfers
The Service may be hosted or accessed from multiple countries. Where we transfer personal data internationally, we take steps intended to provide an appropriate level of protection consistent with applicable law.
9. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to / restrict certain processing. You can update profile fields in the Portal, revoke API/device keys, unlink wallets, and manage Auth account settings at auth.mrtrades.com. To exercise other rights, contact us via Portal Support. You may also have the right to lodge a complaint with a supervisory authority.
10. Children
The Service is not directed to children under 16 (or the higher age required in your jurisdiction). We do not knowingly collect personal data from children.
11. Changes
We may update this Policy by posting a revised version with a new “Last updated” date. Material changes may also be noted in the Portal where practical. Continued use after the effective date means you acknowledge the updated Policy.
12. Contact
Privacy requests: Portal Support.