The Trading Terminal ← Back to The Trading Terminal
Terms and Conditions Privacy Policy
1. Introduction 2. Who This Policy Applies To 3. Information We Collect 4. Cookies, Local Storage and Session Storage 5. Analytics and Your Consent 6. How We Use Your Information 7. Who We Share Your Information With 8. Overseas Disclosure 9. Marketing Communications 10. How We Protect Your Information 11. How Long We Keep Your Information 12. Children 13. Your Rights and Choices 14. Data Breaches 15. Changes to This Policy 16. Contact Us and How to Complain

Privacy Policy

Last updated: 3 September 2026

Document: Privacy Policy
Version: 1.1
Effective date: 3 September 2026
Operator: Harrison Weaver, sole trader
ABN: 56 118 164 232
Jurisdiction: South Australia, Australia
Service: thetradingterminal.com
Contact: support.thetradingterminal@gmail.com
1. Introduction

1.1 This Privacy Policy explains how Harrison Weaver (ABN 56 118 164 232), a sole trader carrying on business as The Trading Terminal (we, us, our), collects, uses, stores, discloses and protects personal information when you use the website and application at thetradingterminal.com (the Platform).

1.2 The Trading Terminal is a trading journal and analytics tool. We hold detailed records of how you trade. We treat that as sensitive commercial information belonging to you, and this policy sets out exactly what we do with it.

1.3 We handle personal information in accordance with the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth), as a matter of policy and as a commitment to our users.

1.4 This policy forms part of our Terms and Conditions. Capitalised terms not defined here have the meaning given in those Terms.

1.5 This policy is published at thetradingterminal.com and applies from the effective date on the cover page.

2. Who This Policy Applies To

2.1 This policy applies to everyone who visits the Platform, creates an account, subscribes to a paid plan, submits a support ticket, or participates in our affiliate programme.

The Platform is not offered to residents of the European Economic Area, the United Kingdom or Switzerland. We do not target, market to, or knowingly accept users from those regions, and our Terms prohibit registration from them. We do not rely on the EU or UK General Data Protection Regulation as our compliance framework and we have not appointed a representative under Article 27 of either regulation. If we identify an account held by a resident of a restricted region, we will close it and delete the associated data.

2.2 The Platform is not available to anyone under 18 years of age. See clause 12.

2.3 We do not sell personal information, and we do not share it for cross-context behavioural advertising.

3. Information We Collect
3.1 Information you give us when you register
InformationRequired?Why We Collect It
Email addressRequiredTo create and identify your account, authenticate you, and send service communications.
PasswordRequiredTo authenticate you. Passwords are hashed by Supabase Auth using bcrypt and are never visible to us in plain text.
Google account (OAuth)Alternative to passwordIf you sign in with Google, Google shares your email address, name and profile picture with us via OAuth 2.0. We use this only to create or identify your account. We do not access your Google Drive, contacts or any other Google data.
Full nameRequiredTo personalise the application and to identify you in support and billing.
Date of birthRequiredTo verify that you meet the minimum age of 18.
Country of residenceRequiredTo apply the regional restrictions in our Terms, and to monitor our tax registration obligations.
Terms and age confirmationRequiredA record that you accepted our Terms and confirmed your age, with the date and time.
Marketing opt-inOptionalA record of whether you consented to marketing emails, with the date and time.
Referral codeIf applicableTo attribute your signup to an affiliate, where you arrived through a referral link.
3.2 Information in your profile and settings

Once your account exists, we hold: your user ID; account creation date; subscription tier, status and billing period; Stripe customer and subscription identifiers; trial status and expiry; complimentary access status and expiry; analytics consent status and timestamp; timezone preference; favourite trading pairs; your custom playbook lists (setups, confluences, entry signals and mistake tags); quick links configuration; dashboard and analytics layout preferences; auto-group and auto-merge sync preferences; your webhook API key; affiliate referral source; and internal administrative flags including administrator status, account freeze status and any notes we record about your account.

3.3 Trading account records

For each trading account you create in the Platform: account name; broker name; account type (live, evaluation, prop or backtest); currency; starting balance; profit goal; maximum drawdown; your risk desk configuration, including trailing drawdown type, daily loss limit and lock settings; your cash adjustment ledger of deposits and withdrawals, with dates and notes; and any notes you add.

3.4 Trade records

For each trade you log or import: symbol; direction; entry and exit dates and prices; stop loss and take profit levels; risk percentage; risk-to-reward ratio; gross profit or loss, fees and net result; outcome; your own grade; setup, confluence and mistake tags; emotion and discipline ratings; free-text notes; trade session, timeframe, bias, market conditions, news impact, order type, and stop and target management notes; the source of the record (manual entry, cTrader sync or MetaTrader Expert Advisor); the provider trade identifier for synced trades; the sync timestamp; and the storage path of any screenshots you upload.

Screenshots you upload are stored in private storage with per-user folder isolation and are not publicly accessible.

3.5 Broker connection data

If you connect a cTrader account: the OAuth provider; your provider user identifier and account identifier; your broker account number and broker name; the OAuth access token and refresh token; the token expiry; sync status and any error messages; the cluster your account sits on (live or demo); and the Trading Terminal account it is linked to.

OAuth tokens are encrypted at rest using AES-256-GCM. They permit read-only retrieval of your closed trade history. They do not permit us to trade, transfer funds, or alter your broker account.

3.6 Support tickets

When you submit a support ticket we collect: the ticket number and category; your first and last name; your email address; your phone number if you choose to provide it (optional); the content of your message; any screenshots you attach; ticket status and timestamps; and the full reply thread, including replies you send by email.

If you reply to a ticket notification email, your reply is ingested through a Gmail mailbox we operate and added to the ticket. Emails sent to us outside a ticket thread are received in that mailbox and retained as ordinary correspondence.

3.7 Affiliate data

If you participate in the affiliate programme we collect: your affiliate code; your name and email address; your referral source or channel; the version of the affiliate agreement you accepted and the date you accepted it; your commission rate and duration; commission records including amounts and invoice references; and payout records including the payment details you supply.

3.8 Payment data

Payments are processed by Stripe. Card numbers, security codes and bank details are collected directly by Stripe and are never received or stored by us. From Stripe we receive and store your Stripe customer and subscription identifiers, your subscription status and plan, billing period and renewal dates, and payment success and failure events. Your Trading Terminal user identifier is passed to Stripe as metadata so that payments can be matched to your account.

3.9 Information collected automatically

When you use the Platform we automatically collect: your IP address, which is visible to us through Cloudflare in the CF-Connecting-IP header and is used for security, rate limiting and abuse prevention; standard request data such as browser type, operating system, device type and referring page; and application error logs and diagnostic data.

Where you have consented to analytics, we also collect the product analytics events described in clause 5. Where you have not consented, no analytics data is collected.

3.10 Information we do not collect

We do not collect sensitive information as defined in the Privacy Act — we do not ask for information about your health, race, ethnicity, political opinions, religious beliefs, sexual orientation, criminal record or union membership. We do not collect government identifiers such as tax file numbers, passport numbers or driver licence numbers. We do not verify your identity against documents, and we do not perform credit checks. Please do not include information of this kind in trade notes, support tickets or screenshots.

4. Cookies, Local Storage and Session Storage

4.1 We use a small number of cookies, together with browser local storage and session storage. Local storage and session storage are not cookies but they store data on your device, so we disclose them here in full.

4.2 Cookies
CookiePurposeLifetimeConsent
tt_ctrader_stateCross-site request forgery protection during the cTrader authorisation flow. HttpOnly, Secure, SameSite=Lax.10 minutesStrictly necessary — set only when you start a cTrader connection
Supabase authentication cookiesMaintains your logged-in session.Session / until sign-outStrictly necessary
PostHog cookies (ph_ prefix)Product analytics. Identifies your session for analytics purposes only.Up to 12 monthsOnly set if you select "Accept" on the consent banner
4.3 Local storage

We store the following in your browser's local storage: your authentication session token; display preferences (currency format, date format, theme and timezone); your remembered email address if you selected "remember me"; any referral code you arrived with; the last page you viewed; an auto-saved draft of any unsaved trade; cached application data for performance; your dashboard and analytics layout selections; your journal filter state; banner dismissal flags; and login lockout counters used for security. If you have consented to analytics, PostHog also stores keys here.

4.4 Session storage

We store a session-only authentication flag. If you have consented to analytics, PostHog also stores session data here.

4.5 Clearing this data

4.5.1 You can clear cookies, local storage and session storage through your browser settings at any time. Doing so will sign you out and reset your preferences, including any unsaved trade draft.

4.5.2 If you withdraw analytics consent, we purge all PostHog cookies, local storage keys and session storage keys from your browser and record the withdrawal on your profile.

5. Analytics and Your Consent

5.1 We use PostHog for product analytics. PostHog is opt-in only. It does not load, set any cookie, or collect anything at all unless you actively select "Accept" on our consent banner. Declining costs you no functionality.

5.2 The banner presents "Accept" and "Reject" with equal prominence. Closing or ignoring it is treated as a rejection.

5.3 Where you consent, PostHog is configured to identify known users only, with automatic pageview capture disabled and autocapture disabled. It does not record your screen, keystrokes or trade data.

5.4 The events we currently track are limited to signup completion, including your email address and whether you opted in to marketing. The user properties we send are your user identifier, email address and subscription tier.

5.5 Your consent decision is recorded on your profile with a timestamp, so that it persists across devices and sessions.

5.6 You can withdraw consent at any time from within the Platform. Withdrawal stops all future collection and purges local analytics data as described in clause 4.5.2. Data already sent to PostHog before withdrawal is held by PostHog under its own retention arrangements; contact us if you want us to request its deletion.

5.7 PostHog processes this data in the United States.

6. How We Use Your Information
PurposeInformation Used
Providing the PlatformAccount data, profile, trading accounts, trades, screenshots, playbook lists, layouts and preferences — used to authenticate you, store your records, generate analytics, run the Risk Desk and Position Sizer, and restore your settings.
Broker synchronisationOAuth tokens, provider identifiers and trade data — used only to import your closed trades and keep your journal current.
Billing and subscription managementEmail address, Stripe identifiers, subscription status and plan — used to take payment, apply your tier, manage trials and complimentary access, and issue refunds.
Transactional emailEmail address and name — used for verification codes, password resets, receipts, trial reminders, support notifications and important service notices. You cannot opt out of these while you hold an account.
SupportTicket content, contact details, attachments and, where necessary, your account and trade records — used to investigate and resolve your issue.
Security, fraud prevention and abuse controlIP address, request data, login attempt counters, rate limit identifiers and administrative flags — used to protect the Platform and other users.
Affiliate programme administrationAffiliate details, referral codes, commission and payout records — used to attribute referrals, calculate commission, apply clawbacks and make payments.
Product analyticsConsented analytics events only — used to understand how the Platform is used and where it fails.
MarketingEmail address and name, only where you have opted in — used to send product news and offers.
Legal and regulatory complianceAny relevant information — used to meet tax, record-keeping and legal obligations, and to establish, exercise or defend legal claims.
Operational monitoringAggregated metrics and support ticket alerts sent to the operator through Telegram. No end-user personal information is disclosed to any third party through this channel beyond the ticket excerpt necessary to alert the operator.

6.1 We do not use your trade data for advertising, we do not sell it, and we do not use it to train machine-learning or artificial-intelligence models. There are currently no artificial-intelligence features in the Platform. If we introduce one, we will update this policy and name the provider before the feature becomes available to you.

6.2 We may create aggregated, de-identified statistics from Platform usage. Aggregated statistics do not identify you and cannot reasonably be re-identified.

7. Who We Share Your Information With

7.1 We disclose personal information only to the service providers listed below, who process it on our behalf and under contract, and only to the extent needed for the purpose stated.

ProviderWhat It DoesWhat It ReceivesWhere
Supabase, Inc.Database, authentication and private file storage — the core of the Platform.All account, profile, trading account, trade and support data; authentication credentials; uploaded screenshots.AWS Sydney (ap-southeast-2), Australia
Google LLC (OAuth)Third-party sign-in — only if you choose to sign in with Google.Authentication is handled by Google's OAuth 2.0 service. Google shares your email address, name and profile picture with us. We do not access any other Google data.United States and globally
Stripe, Inc.Payment processing, subscription management and the billing portal.Your email address, name, card details (collected directly by Stripe), subscription data and your Trading Terminal user identifier.United States and globally
Cloudflare, Inc.Hosting, content delivery, edge compute, TLS and denial-of-service protection.All HTTP traffic to the Platform, including your IP address and request metadata.Global edge network
Spotware Systems Ltd (cTrader)Broker authorisation and trade history retrieval — only if you connect a cTrader account.Authorisation requests and token exchanges; your trading account identifiers.European Union (Cyprus)
Resend, Inc.Delivery of transactional and, where opted in, marketing email.Your email address, name and the content of the message.United States
Upstash, Inc.API rate limiting.A hashed identifier derived from your IP address and the endpoint called, held very briefly.Global
PostHog, Inc.Product analytics — only if you consent.Your user identifier, email address, subscription tier and the events in clause 5.4.United States
Google LLC (Gmail)The support mailbox used to receive ticket replies and correspondence.Email content and the sender address.United States and globally
Telegram FZ-LLCOperator alerts for new support tickets and business metrics.A short excerpt of ticket information, sent only to the operator. Not used to communicate with users.Global
Fair Economy, Inc. (Forex Factory)Economic calendar data.Nothing. The feed is fetched server-side and no user information is sent.United States
ipapi.coCountry detection for affiliate link routing.Your IP address, and only where you have consented to analytics.Global
Google LLC (Fonts)Delivery of the web fonts used by the interface.Standard request data including your IP address and user agent.Global
Cloudflare (cdnjs) and jsDelivrDelivery of the charting library and database client library.Standard request data including your IP address and user agent.Global
Trustpilot A/SReview collection. Only engaged if you choose to click through and leave a review.Nothing unless you submit a review, in which case Trustpilot's own policy applies.European Union (Denmark)

7.2 Affiliate links

The Platform contains outbound affiliate links to TradingView, FundingPips, FTMO, Alpha Futures and similar providers. Clicking one takes you to that provider's own website, where their privacy policy applies. We do not send them your personal information. We may receive a commission if you sign up, and we disclose that on the pages where those links appear.

7.3 We may also disclose personal information where we are required or permitted to do so by law, by a court order or a valid request from a regulator or law enforcement agency; where it is reasonably necessary to investigate suspected unlawful activity or a serious threat to a person's life, health or safety; to establish, exercise or defend a legal claim; or to our professional advisers under a duty of confidence.

7.4 If our business is sold or transferred, personal information may be transferred as part of that transaction. We would notify you and require the acquirer to be bound by obligations no less protective than those in this policy.

8. Overseas Disclosure

8.1 Your account and trade data is stored in Australia, in Supabase's Sydney region (ap-southeast-2).

8.2 Some of the providers in clause 7 are located, or process data, outside Australia — principally in the United States, the European Union and through global content delivery networks. By using the Platform you acknowledge that your information may be disclosed to those providers in those locations.

8.3 Before engaging a provider we take reasonable steps to satisfy ourselves that it has appropriate security and privacy practices. However, overseas providers are subject to the laws of the countries in which they operate, and those laws may differ from Australian privacy law. Where we disclose information overseas, we may not be able to control or ensure that the recipient will not breach the Australian Privacy Principles, and you may not be able to seek redress under the Privacy Act in respect of that provider.

9. Marketing Communications

9.1 We send marketing email only where you have opted in. Opting in is never a condition of using the Platform.

9.2 Every marketing message identifies us and includes a functional unsubscribe facility. Unsubscribe requests are actioned within 5 business days, in accordance with the Spam Act 2003 (Cth).

9.3 Unsubscribing from marketing does not stop transactional and service messages, such as verification codes, receipts, trial reminders, security notices and support replies. Those are necessary to operate your account and cannot be switched off while you hold one.

9.4 You can change your marketing preference at any time in the Platform or by contacting us.

10. How We Protect Your Information

The security measures we apply include:

  • all traffic encrypted in transit over HTTPS, with HTTP Strict Transport Security enabled (two-year max-age, preload);
  • row-level security enforced at the database on every table, so a user can only ever read or write their own records;
  • privileged profile fields — subscription tier, administrator status and Stripe identifiers — protected by database triggers so they cannot be altered by a client request;
  • cTrader OAuth tokens encrypted at rest using AES-256-GCM;
  • passwords hashed by Supabase Auth using bcrypt; we never see or store them in plain text;
  • cross-site request forgery protection on authorisation flows, using a state parameter and an HttpOnly cookie;
  • rate limiting on all API endpoints, and account lockout after repeated failed logins;
  • administrative elevation protected by a separate password, with a full audit log of every administrative action;
  • security headers including X-Frame-Options, X-Content-Type-Options, a strict referrer policy, a content security policy, and a permissions policy that disables camera, microphone and geolocation access;
  • private storage buckets with per-user folder isolation for uploaded screenshots; and
  • no card data held on our systems at any time.

10.1 Access to production data is limited to the operator, on a need-to-know basis, for support, fault diagnosis, security investigation and legal compliance. That access is logged.

10.2 No system is completely secure. While we take the measures above, we cannot guarantee absolute security, and you are responsible for keeping your own password and webhook API key confidential.

11. How Long We Keep Your Information
InformationRetention Period
Account, profile, trading account and trade dataKept while your account is open. Deleted when you delete your account.
Uploaded screenshotsKept while your account is open. Deleted when you delete your account.
cTrader tokens and connection recordsDeleted when you disconnect the integration or delete your account.
Automated database backupsDaily snapshots retained for 7 days on a rolling basis. Deleted data may persist in a backup for up to 7 days after deletion before it is overwritten.
Support ticketsRetained for 12 months after the ticket is resolved, then deleted. On account deletion, tickets are immediately de-identified by removing the link to your user record; the remaining ticket content is deleted at the end of the 12-month period.
Payment and transaction recordsRetained for 5 years from the end of the financial year to which they relate, as required by Australian tax law. This applies even after account deletion.
Affiliate commission and payout recordsRetained for 5 years, as financial records.
Marketing consent and unsubscribe recordsRetained for 5 years, to demonstrate compliance with the Spam Act 2003 (Cth).
Terms acceptance and age confirmation recordsRetained for the life of the account and for 5 years after closure, as evidence of the contract.
Administrative audit logRetained for 2 years.
Application error and diagnostic logsRetained for up to 30 days.
Edge and security logs (Cloudflare)Retained transiently by Cloudflare, generally no more than 30 days, under Cloudflare's own arrangements.
Rate limiting dataEphemeral — held for minutes.
OAuth state tokensEphemeral — 10 minutes.
Analytics data (if consented)Held by PostHog under its own retention arrangements. We do not control this. Contact us if you want us to request deletion.
11.1 What happens when you delete your account

11.1.1 You can delete your account from within the Platform. Deletion cancels any Stripe subscription and then deletes your trades, trading accounts, uploaded screenshots, broker connections, saved layouts, playbook lists, profile record and authentication record.

11.1.2 Deletion is permanent and cannot be reversed. Export your trade journal to CSV before deleting anything you want to keep.

11.1.3 The following is not deleted at the same time, for the reasons given:

  • database backup snapshots, for up to 7 days, before they are overwritten in the ordinary rotation;
  • payment and transaction records, which we are legally required to retain for 5 years;
  • your customer record held by Stripe, which Stripe retains under its own policy after we cancel the subscription; that record is outside our control;
  • support tickets, which are immediately de-identified and then deleted 12 months after resolution; and
  • analytics data already sent to PostHog, if you consented to analytics; that data is held by PostHog and we can request but not guarantee its deletion.

11.1.4 If you want deletion actioned on your behalf rather than through the Platform, contact us and we will process it within 30 days.

12. Children

12.1 The Platform is not directed at, and must not be used by, anyone under 18. We require a date of birth and an age confirmation at registration.

12.2 We do not knowingly collect personal information from a person under 18. If we become aware that we have, we will close the account and delete the information promptly.

12.3 If you believe a person under 18 has provided us with personal information, contact us immediately at support.thetradingterminal@gmail.com.

13. Your Rights and Choices
RightHow to Exercise It
Access your informationMost of your information is visible in the Platform. For anything else, contact us and we will provide it, ordinarily within 30 days.
Correct your informationEdit your profile, trades and settings directly in the Platform, or contact us to correct anything you cannot change yourself.
Export your dataExport your full trade journal to CSV at any time from within the Platform.
Delete your account and dataDelete your account from within the Platform, or contact us. See clause 11.1.
Withdraw analytics consentChange your consent setting in the Platform at any time. See clause 5.6.
Opt out of marketingUse the unsubscribe link in any marketing email, or change your preference in the Platform.
Complain about our handling of your informationContact us first — see clause 16. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner.

13.1 We do not charge for access or correction requests. We may ask you to verify your identity before we act on a request, to make sure we are not disclosing your information to someone else.

13.2 In limited circumstances we may decline a request — for example, where giving access would unreasonably affect another person's privacy, where the request is frivolous or vexatious, or where we are required by law to retain the information. If we decline, we will tell you why in writing and explain how to complain.

14. Data Breaches

14.1 We maintain a process for identifying, containing and assessing suspected data breaches.

14.2 If a breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner as soon as practicable, in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). Our notification will describe what happened, what information was involved, and what you should do in response.

14.3 Where a breach originates with one of our service providers, we will act on the information they give us and pass on what is relevant to you.

15. Changes to This Policy

15.1 We may update this policy as the Platform changes. The version number and effective date on the cover page always identify the current version.

15.2 Where a change materially affects how we handle your personal information, we will notify you by email or in-app notification at least 14 days before it takes effect. Minor changes and clarifications take effect on publication.

15.3 We will always update this policy before introducing a new category of processing, a new service provider that receives your personal information, or any artificial-intelligence feature.

16. Contact Us and How to Complain

16.1 For any privacy question, access or correction request, or complaint, contact us:

The Trading Terminal

Harrison Weaver, sole trader — ABN 56 118 164 232

Adelaide, South Australia, Australia

Support tickets: available in the Platform under Profile → Support

Email: support.thetradingterminal@gmail.com

16.2 We will acknowledge a privacy complaint within 5 business days and give you a written response within 30 days. If we need longer, we will tell you why and when to expect an answer.

16.3 If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:

Office of the Australian Information Commissioner

GPO Box 5218, Sydney NSW 2001

Telephone 1300 363 992 · oaic.gov.au

End of Privacy Policy — Version 1.1, effective 3 September 2026.