Privacy Policy
1. Who is responsible for your data
(company number , ) is the data controller for Precedent. Contact: . We are registered with the Information Commissioner's Office, registration number .
2. What we collect and why
| Data | Why | Lawful basis (UK GDPR) |
|---|---|---|
| Email address and a salted hash of your password (we never store the password itself) | To create your account and let you sign in | Contract |
| Plan, subscription status and dates; Stripe customer and subscription IDs | To give you the access you paid for and manage billing | Contract |
| Record of when you accepted the Terms and requested immediate access | To show we met consumer-law requirements | Legal obligation / legitimate interests |
| Daily count of data requests, last-seen time, account events (e.g. subscription granted, account deleted) | Fair-use limits, security, preventing abuse, support | Legitimate interests |
| Your demo (paper) trades: market, direction, prices, result | To show your trade history and results, and anonymous community statistics. Other visitors see you only as "Trader #1234" (or a nickname you choose); you can hide yourself from community stats at any time | Contract / legitimate interests |
| Desk (yearly plan) — only if you use it: your trading accounts (name, broker, server, account number, currency, balance/equity), the trades the MT5 EA or you send (symbol, direction, size, prices, times, profit, stop/target), your risk rules and journal entries (notes, feelings, tags, screenshot links, day notes). Never your broker password — the EA works inside MetaTrader and only reads account data | To run your journal, calendar, statistics and rule checks, and to send the notifications you switch on | Contract |
| Telegram chat ID — only if you connect Telegram alerts | To send you alerts | Contract |
A session cookie (sid) | Keeps you signed in. Strictly necessary, so no consent banner is required | Legitimate interests |
Card details are entered on Stripe's secure checkout and are never sent to or stored by us.
Your app settings, paper trades and "this browser" alerts are stored only in your own browser (local storage) and never reach our servers.
3. Who we share it with
We don't sell your data or share it for marketing. We use these service providers (processors), under contracts that protect your data:
- Cloudflare — hosting and database for the app.
- Stripe — payments, invoices, the billing portal and fraud prevention. Stripe is also an independent controller for payment data (see stripe.com/privacy).
- Telegram — only if you choose to connect it, to deliver alert messages.
Market-data providers (Twelve Data for spot gold and FX) receive no personal data: those requests are made by our server. The free-tier crypto and PAX Gold charts load public market data from Binance's public API directly from your browser, so Binance can see your IP address like any website you visit.
4. International transfers
Some providers (for example Cloudflare and Stripe) may process data outside the UK, including in the USA. Where they do, transfers are covered by UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework) or the ICO's International Data Transfer Agreement/Addendum.
5. How long we keep it
- Account data: until you delete your account.
- Sign-in sessions: 30 days, or until you log out.
- Payment and transaction records, and records of your Terms acceptance: up to 6 years, to meet tax and legal obligations (Stripe keeps its own records under its policy).
6. Your rights
You can: access your data; correct it; have it erased; restrict or object to processing; and receive it in a portable format. Two of these are self-service in the app: Account → Export my data (download everything we hold about you, as a file) and Account → Delete account (erases your account and cancels any subscription). For anything else, email — we'll respond within one month.
If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113). We'd appreciate the chance to put things right first.
7. Children
Precedent is for adults (18+). We don't knowingly collect data from children.
8. Security
Passwords are hashed with PBKDF2 and a unique salt; sessions use secure, HTTP-only cookies; data-provider keys stay on our server; all traffic is encrypted (HTTPS).
9. Changes
We'll post any update here with a new date, and tell you about material changes by email or in the app.