Privacy Policy
Last updated 17 August 2026
This policy explains what personal data ForexPro Terminal collects, why, who it reaches, and what you can require us to do about it. The data controller is {{LEGAL_ENTITY}}, {{REGISTERED_ADDRESS}}. Contact: reejan@reejangopan.me.
The short version. There are no advertising trackers, no third-party analytics, no session recording and no data sold to anyone. We never ask for and never hold your brokerage or exchange credentials. Your trade journal notes never leave your browser. What we do hold is the account you use to log in, the trading configuration and records you create, and ordinary server logs.
1. Who we are
{{LEGAL_ENTITY}} operates ForexPro Terminal, a rules-based signal and decision-support service for Gold (XAUUSD) and Bitcoin (BTCUSD). We are the controller of the personal data described below.
2. What we collect, and why
| Data | Why we hold it | Legal basis (UK/EU GDPR) |
|---|---|---|
| Access credentials — your username and a one-way cryptographic hash of your password (PBKDF2). We never store the password itself and cannot recover it. | To let you in, and to keep everyone else out. | Performance of our contract with you |
| Subscription and billing records — your email address, what you bought, when, and the amount. Card details are entered with our payment provider and never reach our servers. | To take payment, issue receipts, and meet tax and accounting obligations. | Contract; legal obligation |
| Trading configuration — risk percentages, daily and weekly loss limits, session filters, spread and news thresholds, the emergency-stop flag, and (if you choose to enter it) your account balance. | To run the risk calculations and limit checks you asked for. The balance figure is optional; without it the position-size and loss-limit features simply do not activate. | Contract |
| Trade and signal records — signals published to you, trades you record (symbol, direction, entry, stop, target, size, outcome, P&L), order intents, and periodic snapshots of equity, balance and daily P&L. | To show your open and closed positions, performance analytics and the P&L calendar. | Contract |
| Backtest runs — the parameters you chose and the simulated results. | So a run you started stays available after you navigate away. | Contract |
| Push notification subscriptions — the endpoint URL and encryption keys your browser generates when you enable alerts. Also, if you configure it, your Telegram chat identifier. | To deliver the alerts you switched on. Switching them off deletes the record. | Consent |
| Server and security logs — IP address, request path, timestamp, user agent and error details. | To keep the service running, diagnose faults, enforce rate limits and detect abuse. | Legitimate interests (security and service integrity) |
| Support correspondence — what you write to us and our replies. | To answer you and keep a record of what was agreed. | Contract; legitimate interests |
3. What we deliberately do not collect
- Your brokerage or exchange credentials. The Service has no order-execution capability, so it never needs them and never asks. If anything claiming to be us asks for them, it is not us.
- Advertising or cross-site tracking data. There are no ad pixels, no remarketing tags, no third-party analytics scripts and no session-replay tools anywhere in the product or on the marketing site.
- Your journal notes. Notes you attach to trades in the Journal are stored in your own browser's local storage and are never transmitted to our servers. They stay on that device, and clearing your browser data deletes them permanently — we hold no copy and cannot restore them.
- Special category data. We do not seek or want data about health, beliefs, biometrics or anything similar. Please do not put it in journal notes or support emails.
4. Cookies and local storage
We use no advertising or analytics cookies, so there is no consent banner to click through. What the site does store on your device is limited to:
- a session token held in your browser, which keeps you logged in and expires on its own — strictly necessary for the Service to work;
- one first-party functional cookie recording whether you left the sidebar open or collapsed;
- local storage for your journal notes and interface preferences, as described above.
All of these are first-party and strictly necessary or functional. None is shared with anyone.
5. Who your data reaches
We do not sell personal data, and we do not share it for advertising. It reaches only the service providers we need to run the product:
- Hosting and database — our application server and PostgreSQL database run on a managed cloud platform.
- Front-end hosting and CDN — serves the web interface.
- Payment provider — processes your subscription and holds the card details we never see. They are an independent controller for their own compliance purposes, under their own privacy policy.
- Push and messaging delivery — your browser vendor's push service, and Telegram if and only if you have configured Telegram alerts.
- Professional advisers and authorities — where we are legally required to disclose, or need advice on a dispute.
Market data providers are a different matter and worth being precise about: we fetch price data from them. We send them nothing about you. There is no outbound flow of your personal data to any market data source.
If the business is ever sold or merged, personal data may transfer to the buyer, who would be bound by terms no less protective than these; we would tell you first.
6. International transfers
Our providers may process data outside {{JURISDICTION}}, including in the United States and the European Union. Where data leaves the UK or EEA, transfers are made under an adequacy decision or the UK/EU Standard Contractual Clauses, with additional safeguards where needed. Ask us for details of the mechanism used for any specific provider.
7. How long we keep it
- Account and configuration data — for as long as your subscription is active, then up to 90 days, so a cancellation you regret can be undone.
- Trade, signal and backtest records — for as long as your account exists, since deleting them destroys the performance history the analytics are built on. You can delete them yourself at any time.
- Billing and tax records — for as long as tax law requires, typically six to seven years. This is a legal obligation and survives an erasure request.
- Server and security logs — normally 30 to 90 days, longer if needed to investigate a specific incident.
- Push subscriptions — until you disable alerts or the browser endpoint stops working, whichever comes first.
8. Your rights
Depending on where you live, you can require us to:
- give you a copy of the personal data we hold about you, in a portable format;
- correct anything inaccurate;
- delete your data, except where we must keep it (billing records, or an active legal claim);
- restrict or object to processing based on legitimate interests;
- withdraw consent for alerts at any time, without affecting what was done before you withdrew it.
Email reejan@reejangopan.me and we will respond within 30 days. There is no charge unless a request is manifestly excessive or repetitive. If you are unhappy with our answer you can complain to your national data protection authority — in the UK, the Information Commissioner's Office (ico.org.uk) — though we would rather you gave us the chance to fix it first.
If you are in California: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding twelve months. You have the right to know, delete, correct and to non-discrimination for exercising those rights; use the same email address.
9. Automated decision-making
The Service generates trading signals automatically. Those decisions are about the market, not about you: no profiling of you takes place, and no automated decision is made about you that produces a legal or similarly significant effect. Nothing you do in the product changes what a signal says.
10. Security
Traffic is encrypted in transit with TLS. Passwords are stored only as salted PBKDF2 hashes. Access to the production database is restricted, API access is authenticated and rate-limited, and secrets are held in environment configuration rather than in code. No system is perfectly secure; if a breach ever affects your personal data and is likely to present a risk to you, we will notify you and the relevant regulator as the law requires.
11. Children
The Service is not for anyone under 18 and we do not knowingly collect their data. If you believe a minor has given us personal data, tell us and we will delete it.
12. Changes to this policy
If we change how we handle personal data we will update this page and the date at the top, and for material changes we will notify you by email or in the product before they take effect.
13. Contact
{{LEGAL_ENTITY}}, {{REGISTERED_ADDRESS}}
Email: reejan@reejangopan.me