Last updated: 3 September 2026
1.1 This Privacy Policy explains how Harrison Weaver (ABN 56 118 164 232), a sole trader carrying on business as The Trading Terminal (we, us, our), collects, uses, stores, discloses and protects personal information when you use the website and application at thetradingterminal.com (the Platform).
1.2 The Trading Terminal is a trading journal and analytics tool. We hold detailed records of how you trade. We treat that as sensitive commercial information belonging to you, and this policy sets out exactly what we do with it.
1.3 We handle personal information in accordance with the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth), as a matter of policy and as a commitment to our users.
1.4 This policy forms part of our Terms and Conditions. Capitalised terms not defined here have the meaning given in those Terms.
1.5 This policy is published at thetradingterminal.com and applies from the effective date on the cover page.
2.1 This policy applies to everyone who visits the Platform, creates an account, subscribes to a paid plan, submits a support ticket, or participates in our affiliate programme.
The Platform is not offered to residents of the European Economic Area, the United Kingdom or Switzerland. We do not target, market to, or knowingly accept users from those regions, and our Terms prohibit registration from them. We do not rely on the EU or UK General Data Protection Regulation as our compliance framework and we have not appointed a representative under Article 27 of either regulation. If we identify an account held by a resident of a restricted region, we will close it and delete the associated data.
2.2 The Platform is not available to anyone under 18 years of age. See clause 12.
2.3 We do not sell personal information, and we do not share it for cross-context behavioural advertising.
| Information | Required? | Why We Collect It |
|---|---|---|
| Email address | Required | To create and identify your account, authenticate you, and send service communications. |
| Password | Required | To authenticate you. Passwords are hashed by Supabase Auth using bcrypt and are never visible to us in plain text. |
| Google account (OAuth) | Alternative to password | If you sign in with Google, Google shares your email address, name and profile picture with us via OAuth 2.0. We use this only to create or identify your account. We do not access your Google Drive, contacts or any other Google data. |
| Full name | Required | To personalise the application and to identify you in support and billing. |
| Date of birth | Required | To verify that you meet the minimum age of 18. |
| Country of residence | Required | To apply the regional restrictions in our Terms, and to monitor our tax registration obligations. |
| Terms and age confirmation | Required | A record that you accepted our Terms and confirmed your age, with the date and time. |
| Marketing opt-in | Optional | A record of whether you consented to marketing emails, with the date and time. |
| Referral code | If applicable | To attribute your signup to an affiliate, where you arrived through a referral link. |
Once your account exists, we hold: your user ID; account creation date; subscription tier, status and billing period; Stripe customer and subscription identifiers; trial status and expiry; complimentary access status and expiry; analytics consent status and timestamp; timezone preference; favourite trading pairs; your custom playbook lists (setups, confluences, entry signals and mistake tags); quick links configuration; dashboard and analytics layout preferences; auto-group and auto-merge sync preferences; your webhook API key; affiliate referral source; and internal administrative flags including administrator status, account freeze status and any notes we record about your account.
For each trading account you create in the Platform: account name; broker name; account type (live, evaluation, prop or backtest); currency; starting balance; profit goal; maximum drawdown; your risk desk configuration, including trailing drawdown type, daily loss limit and lock settings; your cash adjustment ledger of deposits and withdrawals, with dates and notes; and any notes you add.
For each trade you log or import: symbol; direction; entry and exit dates and prices; stop loss and take profit levels; risk percentage; risk-to-reward ratio; gross profit or loss, fees and net result; outcome; your own grade; setup, confluence and mistake tags; emotion and discipline ratings; free-text notes; trade session, timeframe, bias, market conditions, news impact, order type, and stop and target management notes; the source of the record (manual entry, cTrader sync or MetaTrader Expert Advisor); the provider trade identifier for synced trades; the sync timestamp; and the storage path of any screenshots you upload.
Screenshots you upload are stored in private storage with per-user folder isolation and are not publicly accessible.
If you connect a cTrader account: the OAuth provider; your provider user identifier and account identifier; your broker account number and broker name; the OAuth access token and refresh token; the token expiry; sync status and any error messages; the cluster your account sits on (live or demo); and the Trading Terminal account it is linked to.
OAuth tokens are encrypted at rest using AES-256-GCM. They permit read-only retrieval of your closed trade history. They do not permit us to trade, transfer funds, or alter your broker account.
When you submit a support ticket we collect: the ticket number and category; your first and last name; your email address; your phone number if you choose to provide it (optional); the content of your message; any screenshots you attach; ticket status and timestamps; and the full reply thread, including replies you send by email.
If you reply to a ticket notification email, your reply is ingested through a Gmail mailbox we operate and added to the ticket. Emails sent to us outside a ticket thread are received in that mailbox and retained as ordinary correspondence.
If you participate in the affiliate programme we collect: your affiliate code; your name and email address; your referral source or channel; the version of the affiliate agreement you accepted and the date you accepted it; your commission rate and duration; commission records including amounts and invoice references; and payout records including the payment details you supply.
Payments are processed by Stripe. Card numbers, security codes and bank details are collected directly by Stripe and are never received or stored by us. From Stripe we receive and store your Stripe customer and subscription identifiers, your subscription status and plan, billing period and renewal dates, and payment success and failure events. Your Trading Terminal user identifier is passed to Stripe as metadata so that payments can be matched to your account.
When you use the Platform we automatically collect: your IP address, which is visible to us through Cloudflare in the CF-Connecting-IP header and is used for security, rate limiting and abuse prevention; standard request data such as browser type, operating system, device type and referring page; and application error logs and diagnostic data.
Where you have consented to analytics, we also collect the product analytics events described in clause 5. Where you have not consented, no analytics data is collected.
We do not collect sensitive information as defined in the Privacy Act — we do not ask for information about your health, race, ethnicity, political opinions, religious beliefs, sexual orientation, criminal record or union membership. We do not collect government identifiers such as tax file numbers, passport numbers or driver licence numbers. We do not verify your identity against documents, and we do not perform credit checks. Please do not include information of this kind in trade notes, support tickets or screenshots.
4.1 We use a small number of cookies, together with browser local storage and session storage. Local storage and session storage are not cookies but they store data on your device, so we disclose them here in full.
| Cookie | Purpose | Lifetime | Consent |
|---|---|---|---|
| tt_ctrader_state | Cross-site request forgery protection during the cTrader authorisation flow. HttpOnly, Secure, SameSite=Lax. | 10 minutes | Strictly necessary — set only when you start a cTrader connection |
| Supabase authentication cookies | Maintains your logged-in session. | Session / until sign-out | Strictly necessary |
| PostHog cookies (ph_ prefix) | Product analytics. Identifies your session for analytics purposes only. | Up to 12 months | Only set if you select "Accept" on the consent banner |
We store the following in your browser's local storage: your authentication session token; display preferences (currency format, date format, theme and timezone); your remembered email address if you selected "remember me"; any referral code you arrived with; the last page you viewed; an auto-saved draft of any unsaved trade; cached application data for performance; your dashboard and analytics layout selections; your journal filter state; banner dismissal flags; and login lockout counters used for security. If you have consented to analytics, PostHog also stores keys here.
We store a session-only authentication flag. If you have consented to analytics, PostHog also stores session data here.
4.5.1 You can clear cookies, local storage and session storage through your browser settings at any time. Doing so will sign you out and reset your preferences, including any unsaved trade draft.
4.5.2 If you withdraw analytics consent, we purge all PostHog cookies, local storage keys and session storage keys from your browser and record the withdrawal on your profile.
5.1 We use PostHog for product analytics. PostHog is opt-in only. It does not load, set any cookie, or collect anything at all unless you actively select "Accept" on our consent banner. Declining costs you no functionality.
5.2 The banner presents "Accept" and "Reject" with equal prominence. Closing or ignoring it is treated as a rejection.
5.3 Where you consent, PostHog is configured to identify known users only, with automatic pageview capture disabled and autocapture disabled. It does not record your screen, keystrokes or trade data.
5.4 The events we currently track are limited to signup completion, including your email address and whether you opted in to marketing. The user properties we send are your user identifier, email address and subscription tier.
5.5 Your consent decision is recorded on your profile with a timestamp, so that it persists across devices and sessions.
5.6 You can withdraw consent at any time from within the Platform. Withdrawal stops all future collection and purges local analytics data as described in clause 4.5.2. Data already sent to PostHog before withdrawal is held by PostHog under its own retention arrangements; contact us if you want us to request its deletion.
5.7 PostHog processes this data in the United States.
| Purpose | Information Used |
|---|---|
| Providing the Platform | Account data, profile, trading accounts, trades, screenshots, playbook lists, layouts and preferences — used to authenticate you, store your records, generate analytics, run the Risk Desk and Position Sizer, and restore your settings. |
| Broker synchronisation | OAuth tokens, provider identifiers and trade data — used only to import your closed trades and keep your journal current. |
| Billing and subscription management | Email address, Stripe identifiers, subscription status and plan — used to take payment, apply your tier, manage trials and complimentary access, and issue refunds. |
| Transactional email | Email address and name — used for verification codes, password resets, receipts, trial reminders, support notifications and important service notices. You cannot opt out of these while you hold an account. |
| Support | Ticket content, contact details, attachments and, where necessary, your account and trade records — used to investigate and resolve your issue. |
| Security, fraud prevention and abuse control | IP address, request data, login attempt counters, rate limit identifiers and administrative flags — used to protect the Platform and other users. |
| Affiliate programme administration | Affiliate details, referral codes, commission and payout records — used to attribute referrals, calculate commission, apply clawbacks and make payments. |
| Product analytics | Consented analytics events only — used to understand how the Platform is used and where it fails. |
| Marketing | Email address and name, only where you have opted in — used to send product news and offers. |
| Legal and regulatory compliance | Any relevant information — used to meet tax, record-keeping and legal obligations, and to establish, exercise or defend legal claims. |
| Operational monitoring | Aggregated metrics and support ticket alerts sent to the operator through Telegram. No end-user personal information is disclosed to any third party through this channel beyond the ticket excerpt necessary to alert the operator. |
6.1 We do not use your trade data for advertising, we do not sell it, and we do not use it to train machine-learning or artificial-intelligence models. There are currently no artificial-intelligence features in the Platform. If we introduce one, we will update this policy and name the provider before the feature becomes available to you.
6.2 We may create aggregated, de-identified statistics from Platform usage. Aggregated statistics do not identify you and cannot reasonably be re-identified.
7.1 We disclose personal information only to the service providers listed below, who process it on our behalf and under contract, and only to the extent needed for the purpose stated.
| Provider | What It Does | What It Receives | Where |
|---|---|---|---|
| Supabase, Inc. | Database, authentication and private file storage — the core of the Platform. | All account, profile, trading account, trade and support data; authentication credentials; uploaded screenshots. | AWS Sydney (ap-southeast-2), Australia |
| Google LLC (OAuth) | Third-party sign-in — only if you choose to sign in with Google. | Authentication is handled by Google's OAuth 2.0 service. Google shares your email address, name and profile picture with us. We do not access any other Google data. | United States and globally |
| Stripe, Inc. | Payment processing, subscription management and the billing portal. | Your email address, name, card details (collected directly by Stripe), subscription data and your Trading Terminal user identifier. | United States and globally |
| Cloudflare, Inc. | Hosting, content delivery, edge compute, TLS and denial-of-service protection. | All HTTP traffic to the Platform, including your IP address and request metadata. | Global edge network |
| Spotware Systems Ltd (cTrader) | Broker authorisation and trade history retrieval — only if you connect a cTrader account. | Authorisation requests and token exchanges; your trading account identifiers. | European Union (Cyprus) |
| Resend, Inc. | Delivery of transactional and, where opted in, marketing email. | Your email address, name and the content of the message. | United States |
| Upstash, Inc. | API rate limiting. | A hashed identifier derived from your IP address and the endpoint called, held very briefly. | Global |
| PostHog, Inc. | Product analytics — only if you consent. | Your user identifier, email address, subscription tier and the events in clause 5.4. | United States |
| Google LLC (Gmail) | The support mailbox used to receive ticket replies and correspondence. | Email content and the sender address. | United States and globally |
| Telegram FZ-LLC | Operator alerts for new support tickets and business metrics. | A short excerpt of ticket information, sent only to the operator. Not used to communicate with users. | Global |
| Fair Economy, Inc. (Forex Factory) | Economic calendar data. | Nothing. The feed is fetched server-side and no user information is sent. | United States |
| ipapi.co | Country detection for affiliate link routing. | Your IP address, and only where you have consented to analytics. | Global |
| Google LLC (Fonts) | Delivery of the web fonts used by the interface. | Standard request data including your IP address and user agent. | Global |
| Cloudflare (cdnjs) and jsDelivr | Delivery of the charting library and database client library. | Standard request data including your IP address and user agent. | Global |
| Trustpilot A/S | Review collection. Only engaged if you choose to click through and leave a review. | Nothing unless you submit a review, in which case Trustpilot's own policy applies. | European Union (Denmark) |
7.2 Affiliate links
The Platform contains outbound affiliate links to TradingView, FundingPips, FTMO, Alpha Futures and similar providers. Clicking one takes you to that provider's own website, where their privacy policy applies. We do not send them your personal information. We may receive a commission if you sign up, and we disclose that on the pages where those links appear.
7.3 We may also disclose personal information where we are required or permitted to do so by law, by a court order or a valid request from a regulator or law enforcement agency; where it is reasonably necessary to investigate suspected unlawful activity or a serious threat to a person's life, health or safety; to establish, exercise or defend a legal claim; or to our professional advisers under a duty of confidence.
7.4 If our business is sold or transferred, personal information may be transferred as part of that transaction. We would notify you and require the acquirer to be bound by obligations no less protective than those in this policy.
8.1 Your account and trade data is stored in Australia, in Supabase's Sydney region (ap-southeast-2).
8.2 Some of the providers in clause 7 are located, or process data, outside Australia — principally in the United States, the European Union and through global content delivery networks. By using the Platform you acknowledge that your information may be disclosed to those providers in those locations.
8.3 Before engaging a provider we take reasonable steps to satisfy ourselves that it has appropriate security and privacy practices. However, overseas providers are subject to the laws of the countries in which they operate, and those laws may differ from Australian privacy law. Where we disclose information overseas, we may not be able to control or ensure that the recipient will not breach the Australian Privacy Principles, and you may not be able to seek redress under the Privacy Act in respect of that provider.
9.1 We send marketing email only where you have opted in. Opting in is never a condition of using the Platform.
9.2 Every marketing message identifies us and includes a functional unsubscribe facility. Unsubscribe requests are actioned within 5 business days, in accordance with the Spam Act 2003 (Cth).
9.3 Unsubscribing from marketing does not stop transactional and service messages, such as verification codes, receipts, trial reminders, security notices and support replies. Those are necessary to operate your account and cannot be switched off while you hold one.
9.4 You can change your marketing preference at any time in the Platform or by contacting us.
The security measures we apply include:
10.1 Access to production data is limited to the operator, on a need-to-know basis, for support, fault diagnosis, security investigation and legal compliance. That access is logged.
10.2 No system is completely secure. While we take the measures above, we cannot guarantee absolute security, and you are responsible for keeping your own password and webhook API key confidential.
| Information | Retention Period |
|---|---|
| Account, profile, trading account and trade data | Kept while your account is open. Deleted when you delete your account. |
| Uploaded screenshots | Kept while your account is open. Deleted when you delete your account. |
| cTrader tokens and connection records | Deleted when you disconnect the integration or delete your account. |
| Automated database backups | Daily snapshots retained for 7 days on a rolling basis. Deleted data may persist in a backup for up to 7 days after deletion before it is overwritten. |
| Support tickets | Retained for 12 months after the ticket is resolved, then deleted. On account deletion, tickets are immediately de-identified by removing the link to your user record; the remaining ticket content is deleted at the end of the 12-month period. |
| Payment and transaction records | Retained for 5 years from the end of the financial year to which they relate, as required by Australian tax law. This applies even after account deletion. |
| Affiliate commission and payout records | Retained for 5 years, as financial records. |
| Marketing consent and unsubscribe records | Retained for 5 years, to demonstrate compliance with the Spam Act 2003 (Cth). |
| Terms acceptance and age confirmation records | Retained for the life of the account and for 5 years after closure, as evidence of the contract. |
| Administrative audit log | Retained for 2 years. |
| Application error and diagnostic logs | Retained for up to 30 days. |
| Edge and security logs (Cloudflare) | Retained transiently by Cloudflare, generally no more than 30 days, under Cloudflare's own arrangements. |
| Rate limiting data | Ephemeral — held for minutes. |
| OAuth state tokens | Ephemeral — 10 minutes. |
| Analytics data (if consented) | Held by PostHog under its own retention arrangements. We do not control this. Contact us if you want us to request deletion. |
11.1.1 You can delete your account from within the Platform. Deletion cancels any Stripe subscription and then deletes your trades, trading accounts, uploaded screenshots, broker connections, saved layouts, playbook lists, profile record and authentication record.
11.1.2 Deletion is permanent and cannot be reversed. Export your trade journal to CSV before deleting anything you want to keep.
11.1.3 The following is not deleted at the same time, for the reasons given:
11.1.4 If you want deletion actioned on your behalf rather than through the Platform, contact us and we will process it within 30 days.
12.1 The Platform is not directed at, and must not be used by, anyone under 18. We require a date of birth and an age confirmation at registration.
12.2 We do not knowingly collect personal information from a person under 18. If we become aware that we have, we will close the account and delete the information promptly.
12.3 If you believe a person under 18 has provided us with personal information, contact us immediately at support.thetradingterminal@gmail.com.
| Right | How to Exercise It |
|---|---|
| Access your information | Most of your information is visible in the Platform. For anything else, contact us and we will provide it, ordinarily within 30 days. |
| Correct your information | Edit your profile, trades and settings directly in the Platform, or contact us to correct anything you cannot change yourself. |
| Export your data | Export your full trade journal to CSV at any time from within the Platform. |
| Delete your account and data | Delete your account from within the Platform, or contact us. See clause 11.1. |
| Withdraw analytics consent | Change your consent setting in the Platform at any time. See clause 5.6. |
| Opt out of marketing | Use the unsubscribe link in any marketing email, or change your preference in the Platform. |
| Complain about our handling of your information | Contact us first — see clause 16. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner. |
13.1 We do not charge for access or correction requests. We may ask you to verify your identity before we act on a request, to make sure we are not disclosing your information to someone else.
13.2 In limited circumstances we may decline a request — for example, where giving access would unreasonably affect another person's privacy, where the request is frivolous or vexatious, or where we are required by law to retain the information. If we decline, we will tell you why in writing and explain how to complain.
14.1 We maintain a process for identifying, containing and assessing suspected data breaches.
14.2 If a breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner as soon as practicable, in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). Our notification will describe what happened, what information was involved, and what you should do in response.
14.3 Where a breach originates with one of our service providers, we will act on the information they give us and pass on what is relevant to you.
15.1 We may update this policy as the Platform changes. The version number and effective date on the cover page always identify the current version.
15.2 Where a change materially affects how we handle your personal information, we will notify you by email or in-app notification at least 14 days before it takes effect. Minor changes and clarifications take effect on publication.
15.3 We will always update this policy before introducing a new category of processing, a new service provider that receives your personal information, or any artificial-intelligence feature.
16.1 For any privacy question, access or correction request, or complaint, contact us:
The Trading Terminal
Harrison Weaver, sole trader — ABN 56 118 164 232
Adelaide, South Australia, Australia
Support tickets: available in the Platform under Profile → Support
Email: support.thetradingterminal@gmail.com
16.2 We will acknowledge a privacy complaint within 5 business days and give you a written response within 30 days. If we need longer, we will tell you why and when to expect an answer.
16.3 If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:
Office of the Australian Information Commissioner
GPO Box 5218, Sydney NSW 2001
Telephone 1300 363 992 · oaic.gov.au
End of Privacy Policy — Version 1.1, effective 3 September 2026.