Privacy Policy
Last updated: 7 September 2026 · Trades Replay · Bhopal, Madhya Pradesh, India
Trades Replay (the “Company”, “we”, “us” or “our”), an entity operating out of Bhopal, Madhya Pradesh, India, operates the Trades Replay backtesting and market-replay software at https://tradesreplay.com (the “Service”). This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, where we keep it, how long we keep it, and what rights you have over it.
It applies to everyone who signs up for an Account, everyone who visits the Service's public pages, and everyone who contacts our support address. It forms part of, and should be read with, our Terms of Service.
1. Our Role, and the Law That Applies
For all personal data described in this Policy we act as the data fiduciary under India's Digital Personal Data Protection Act 2023 (the “DPDP Act”) and as the data controller under the EU and UK General Data Protection Regulation (“GDPR”) — that is, we decide why and how the data is processed. Where we process data strictly on your documented instruction, we act as a processor for that purpose.
Because our infrastructure sits in the European Union and we serve customers worldwide, we apply the DPDP Act, the GDPR and the California Consumer Privacy Act (as amended by the CPRA, “CCPA”) together, and give every user the benefit of the strongest applicable standard.
2. Personal Data We Collect
2.1 Data you give us when you create an Account
- Email address — your login identifier and the only channel we use for account, security and billing notices.
- Username and, if you set one, a separate display name.
- Password — stored only as a salted one-way hash (scrypt). We never store, log or have any means of reading your plaintext password. Nobody at Trades Replay can tell you what your password is.
- Profile picture, if you upload one — held as an image file on our server and served from your Account.
- Timezone, so that dates and session times display correctly for you.
- Pending email address and a one-time verification token, held only while an email change is in flight (the token expires after 24 hours).
2.2 Billing data — handled by Paddle, not by us
All payments are processed by our Merchant of Record, Paddle.com Market Limited. Paddle collects your card or payment-method details, billing address, billing country and any tax identifier directly from you at its own checkout. We never receive, see, process or store your full card number, CVC, bank details or payment credentials. What we receive back from Paddle is limited to the subscription record we need to give you the plan you bought: a Paddle customer and subscription identifier, the plan and billing cycle, the subscription status, the renewal date and the billing country. Paddle's own Privacy Notice governs everything Paddle does with your data as its own controller.
2.3 The content you create inside the Service
- Sessions — the name you give a backtest, the instrument, the start and end dates, the starting balance, and your spread and commission settings.
- Backtest state — your replay position, indicator configurations, price alerts, chart drawings and layout, saved as one record per Session so your work survives a browser change or a new device. One previous copy is kept as a safety net against a bad write.
- Simulated trades — side, entry, exit, stop-loss, take-profit, R multiple, simulated profit or loss, result, timestamps, and any free-text note you write on a trade. Trade notes are free text; please do not put anything sensitive, or anyone else's personal data, in them.
- Time invested — while a chart page is actually open and in use it records one heartbeat a minute, aggregated to one row per day, per Session, per instrument. This is what the dashboard's “Time Invested” figures are computed from. It records elapsed time, not what you looked at.
- Deleted-session summaries — when you delete a Session we destroy its state and its trades, and keep only a short summary line so the Deleted Sessions list can still show what it was.
2.4 Data collected automatically
- IP address — present in web-server logs and used for rate limiting and abuse prevention. Failed login attempts are counted in memory against both the IP address and the email address, to slow down brute-force attacks; those counters are not written to disk and are lost on restart.
- User-agent string and standard request metadata, in web-server access logs.
- Application logs — errors, warnings and an application diagnostic log which records the account identifier alongside the event, so that a fault reported by one user can be traced. It is capped and rotates automatically.
- Account activity — the date your Account was created, plan changes, email changes and session deletions, kept as an audit trail for security and dispute resolution. Individual sign-in events are not kept as account records; they appear only in the web-server logs described above, under the retention in Section 11.
2.5 Diagnostic screen captures — only when you ask for them
The Service contains a diagnostic function which sends rendered frames of your own chart canvas from your browser to our server so that a visual fault you are reporting can be inspected exactly as you see it. It runs only when a capture is triggered from your session, it captures the chart canvas and not your desktop or any other tab, and only the most recent capture is retained — starting a new one deletes the previous one.
2.6 Support communications
Emails, attachments and any information you send to our support address are retained so we can answer you, prove what was agreed, and resolve disputes.
2.7 Data we deliberately do not collect
- No advertising identifiers, no device fingerprinting, no cross-site tracking.
- No third-party analytics — no Google Analytics, no Meta Pixel, no LinkedIn Insight Tag, no session-replay or heatmap tool.
- No brokerage credentials, no API keys to any exchange or broker, no bank details, no financial-account access of any kind — the Service has no facility to connect to one (see Section 2.2 of the Terms).
- No government identity documents, no biometric data, and no special-category / sensitive personal data. Please do not send us any.
- No data about children (see Section 17).
3. Cookies and Local Storage
We use a deliberately minimal set of browser storage, all of it strictly necessary to operate the Service. We serve no advertising or analytics cookies, so we do not present a cookie consent banner — there is nothing to consent to beyond what the Service needs to work.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
session | Cookie — HTTP-only, Secure, SameSite=Lax | Keeps you signed in. Signed server-side; it holds your account identifier, nothing else. | Browser session, cleared on logout |
tr-locale | Cookie — SameSite=Lax | Remembers the interface language you picked, so the first paint of a page is already in it. | 1 year |
tr-locale | Local storage | The same language choice, which is what the in-page picker reads. | Until cleared |
tr-theme | Local storage | Remembers light or dark mode, so navigating in dark never flashes a white page. | Until cleared |
Paddle sets its own cookies inside its checkout when you make a purchase; those are governed by Paddle's Privacy Notice. Clearing the two local-storage keys or the locale cookie is harmless — the Service simply falls back to its defaults. Clearing the session cookie logs you out.
4. Why We Process Your Data (Lawful Basis)
| Purpose | Lawful basis (GDPR) | Basis (DPDP Act) |
|---|---|---|
| Creating and running your Account; storing and serving your Sessions, trades and settings; giving you the plan you bought | Performance of a contract (Art. 6(1)(b)) | For the specified purpose of providing the Service you signed up for |
| Billing, invoicing, subscription management and enforcing non-payment | Performance of a contract; legal obligation (Art. 6(1)(b), 6(1)(c)) | Contractual and statutory |
| Transactional email — verification links, password and security notices, billing and renewal notices | Performance of a contract; legitimate interests (Art. 6(1)(b), 6(1)(f)) | Specified purpose |
| Security, rate limiting, fraud and abuse prevention, enforcing the Terms, investigating incidents | Legitimate interests (Art. 6(1)(f)) | Legitimate use — security and prevention of fraud |
| Diagnosing faults, maintaining and improving the Service, aggregated usage statistics | Legitimate interests (Art. 6(1)(f)) | Legitimate use |
| Keeping tax, accounting and transaction records | Legal obligation (Art. 6(1)(c)) | Statutory obligation |
| Establishing, exercising or defending legal claims | Legitimate interests (Art. 6(1)(f)) | Legitimate use — enforcement of legal rights |
| Optional product or marketing email, if you opt in | Consent (Art. 6(1)(a)) — withdrawable at any time | Consent |
5. How We Use Your Data
- To run the Service: authenticate you, load and save your Sessions, compute your statistics and reports, serve historical Market Data to your chart, and honour your plan's limits.
- To bill you: pass your subscription request to Paddle, read back the resulting subscription status, and apply the correct plan to your Account.
- To communicate with you: email-change verification links, account and security notices, billing receipts and renewal reminders, and answers to your support requests. A password is changed from inside your Account using your current password; if you have lost access to your Account, write to support@tradesreplay.com.
- To keep the platform safe: rate-limit logins, detect and block abuse and multi-account evasion, investigate incidents, and enforce the Terms.
- To maintain and improve the product: reproduce and fix faults, and analyse aggregated, de-identified usage patterns.
- To comply with law and to establish, exercise or defend legal claims.
- Marketing, only if you opt in. We do not add you to a marketing list merely because you signed up. Where you do opt in, every message carries an unsubscribe link and you may opt out at any time by writing to support@tradesreplay.com.
6. What We Never Do With Your Data
- We do not sell your personal data — not to advertisers, not to data brokers, not to anyone, in any form, for any consideration. We do not rent, trade or barter it. We do not share it for cross-context behavioural advertising.
- We do not train AI or machine-learning models on your data. Your Sessions, simulated trades, trade notes and statistics are never used to train, fine-tune or evaluate any model, ours or a third party's.
- We do not share, publish, syndicate or resell your trading ideas or results. Your backtests are visible to you and to nobody else, except the strictly limited administrative access described in Section 8.
- We do not send your data to an advertising network, because we run no advertising anywhere in the Service.
7. Automated Decision-Making
We do not carry out automated decision-making producing legal or similarly significant effects about you within the meaning of GDPR Article 22. Automated rules exist only for security — for example, temporarily rate-limiting an IP address or email address after repeated failed logins. Any decision to suspend or terminate an Account for breach of the Terms is taken by a human, and you may contest it by writing to support@tradesreplay.com.
8. Who Can See Your Data
8.1 Inside Trades Replay. Access to production systems and to the database is limited to the operator of the Service, on a least-privilege basis, for the purposes of running, supporting and securing the platform. The Service contains an administrative view which lists accounts, their plan and aggregate counts, and an impersonation facility used to reproduce a fault an account has reported; both are restricted to administrator accounts and their use is logged. We do not browse customer backtests for interest, for research, or for any commercial purpose.
8.2 Other users. No part of your Account, your Sessions, your simulated trades or your statistics is visible to any other user. There is no public profile, no leaderboard, no sharing feature and no social feed in the Service.
8.3 Legal disclosure. We may disclose personal data where required by valid legal process — a court order, a subpoena, a warrant or a lawful regulatory demand — or where necessary to protect our rights, comply with a legal obligation, or investigate suspected fraud, a security breach or a violation of our Terms. We review each request for validity and will resist an overbroad request where it is lawful to do so.
8.4 Business transfer. If we are involved in a merger, acquisition, reorganisation or sale of all or part of our business, personal data may be transferred as part of that transaction. We will give notice before your data becomes subject to a materially different privacy policy.
9. Processors and Sub-Processors
We use the following third-party providers. Each receives only the minimum data needed for its specific function, and each is bound by a data-processing agreement or equivalent contractual terms.
| Provider | Location | What it does, and what it sees |
|---|---|---|
| Amazon Web Services, Inc. | European Union — Stockholm (eu-north-1) | Hosts our production server, application database and backups. All Account data and Backtest Data live here. AWS is ISO 27001 and SOC 2 certified and has no routine human access to our data. |
| Paddle.com Market Limited | United Kingdom | Merchant of Record. Runs the checkout and takes payment; sees your billing email, country, tax identifier and payment method. PCI-DSS compliant. We never see your card number. |
| Resend, Inc. | United States | Delivers our transactional email (verification links, notices). Sees the recipient address and the message content. |
| Dukascopy Bank SA | Switzerland | Source of historical market data. Data is fetched by our server; no personal data of yours is sent to them and they receive nothing about you. |
| Google LLC (Google Fonts) | United States / global CDN | Serves the web fonts some pages use. Your browser requests them directly, so Google receives your IP address and user-agent as part of that request. No account data is involved. |
| Video hosts (e.g. YouTube / Arcade) | United States | Only where a tutorial in the education library is an embedded video, and only when you open it. The host then sees your IP address and sets its own cookies under its own policy. |
| Let's Encrypt (ISRG) | United States | Issues our TLS certificates. Receives no application data. |
| Domain registrar and DNS provider | — | Resolves our domain name. Receives no application data. |
We will update this table before adding a new processor that handles personal data. Material additions are notified under Section 18.
10. Where Your Data Is Held, and International Transfers
Your Account data and every backtest you create are stored on servers in the European Union (Amazon Web Services, Stockholm). Backups are held in the same region.
Some of our processors are established outside India and the EEA — principally Paddle (United Kingdom, which benefits from a European Commission adequacy decision) and Resend and Google (United States). Where personal data is transferred outside the EEA or the UK, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (Decision 2021/914) and the UK International Data Transfer Addendum, together with the provider's own certifications (ISO 27001, SOC 2 Type II). Under the DPDP Act, cross-border transfer is permitted to any country not restricted by notification of the Central Government; as at the “Last updated” date no such restriction applies to the countries above.
11. How Long We Keep Data
| Data | Retention |
|---|---|
| Account record (email, username, display name, password hash, timezone, avatar, plan) | For the life of the Account. If you close it, deleted after a 30-day grace period. |
| Sessions, backtest state, simulated trades, notes, drawings | For the life of the Account, subject to your plan's retention span. Deleting a Session destroys them immediately and irreversibly — only a short summary line survives, until you remove that too. |
| Time-invested activity rows | For the life of the Account. |
| Billing, invoice and tax records | Held by Paddle as Merchant of Record under its own retention schedule; our own copy of the subscription record is kept up to 7 years to meet Indian tax and accounting requirements. |
| Web-server access logs | Up to 90 days. |
| Application diagnostic log | Rotates automatically at a fixed size; two generations at most. |
| Security event records (failed logins, rate-limit hits) | In-memory only, lost on restart; where written to a log, up to 180 days. |
| Diagnostic screen captures | Only the most recent capture is kept; a new capture deletes the previous one. |
| Support email | Up to 3 years. |
| Operational backups | Rolling cycle. Deleted data may persist in a backup for a short period after deletion from production before it is overwritten. |
After the relevant period we delete or irreversibly anonymise the data. We may retain what we need to comply with a legal obligation, to enforce our agreements, or to establish, exercise or defend a legal claim, for as long as that need lasts.
12. Security
We apply reasonable technical and organisational measures to protect personal data, including:
- TLS 1.2+ for all data in transit; HTTPS enforced across the Service.
- Passwords stored only as salted scrypt hashes; plaintext passwords are never stored or logged.
- Session cookies set HTTP-only, Secure and SameSite=Lax; the signing secret is generated per deployment and never committed to source control.
- Rate limiting and progressive blocking on the login endpoint against brute-force and credential-stuffing attacks.
- Every data-bearing endpoint scoped to the authenticated account, so one account cannot read another's Sessions or trades.
- Least-privilege server access restricted to the operator; administrative actions inside the Service restricted to administrator accounts.
- Regular operating-system and dependency security updates; firewalling at the cloud provider level.
- Automated hourly database snapshots, and a per-Session previous-state copy that protects a backtest against a bad write.
No system is completely secure. If a personal-data breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India without undue delay and, in any event, within seventy-two (72) hours of becoming aware of it, in line with the DPDP Act and GDPR Articles 33 and 34, and we will act promptly to contain and remediate it.
13. Your Rights Under the DPDP Act 2023 (India)
If you are in India, you have the right to:
- Access — obtain a summary of the personal data we process about you and of our processing activities;
- Correction and erasure — have inaccurate or incomplete data corrected, completed or updated, and have data erased where it is no longer needed for the purpose it was collected for;
- Nominate — nominate another person to exercise your rights in the event of your death or incapacity;
- Withdraw consent — where processing rests on consent, withdraw it at any time, with effect for the future;
- Grievance redressal — raise a complaint with our Grievance Officer (Section 16) before approaching the Data Protection Board of India.
14. Your Rights Under the GDPR (EU, EEA, UK, Switzerland)
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure, the “right to be forgotten” (Art. 17), subject to our legal retention obligations
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20) — we will provide your Account data and backtests in a structured, machine-readable JSON export
- Right to object to processing based on legitimate interests (Art. 21)
- Right not to be subject to solely automated decision-making (Art. 22) — see Section 7
- Right to withdraw consent at any time, where consent is the basis
- Right to lodge a complaint with your national supervisory authority
15. Your Rights Under the CCPA / CPRA (California)
California residents have the right to know what personal information is collected, used and disclosed; the right to delete; the right to correct; the right to opt out of the sale or sharing of personal information; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising any of them. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of; we collect no sensitive personal information as that term is defined. To exercise a right, write to support@tradesreplay.com. You may use an authorised agent, and we may ask you to verify the request.
16. How to Exercise Your Rights, and Our Grievance Officer
To exercise any right in Sections 13 to 15, email support@tradesreplay.com from the email address on your Account, stating what you want. We may ask for additional verification before acting, to prevent someone else obtaining or destroying your data.
- Acknowledgement: within 48 hours.
- Substantive response: within 30 days of a valid request (extendable by a further 30 days for a complex request, with notice to you). There is no charge, unless a request is manifestly unfounded or excessive.
Under the DPDP Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, we designate a Grievance Officer for all data-protection concerns:
- Grievance Officer, Trades Replay
- Email: support@tradesreplay.com (subject line: “Data protection — grievance”)
- Location: Bhopal, Madhya Pradesh, India
If you are not satisfied with our response you may escalate to the Data Protection Board of India under the DPDP Act; if you are in the EEA or the UK you may complain to your local supervisory authority; and if you are in California you may contact the California Privacy Protection Agency. We would ask you to come to us first so we can put things right.
17. Children
The Service is not intended for, and is not offered to, anyone under eighteen (18). We do not knowingly collect personal data from a child. If you believe a child has given us personal data, write to support@tradesreplay.com and we will delete it and close the account promptly.
18. Changes to This Policy
We may update this Policy from time to time. When we do, we update the “Last updated” date at the top of this page. For a material change — one that substantially affects your rights or how we handle your data — we will give at least fourteen (14) days' advance notice by email to the address on your Account and/or by a notice inside the Service. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy. The current version is always at https://tradesreplay.com/legal/privacy.
19. Governing Law for Privacy Disputes
This Policy is governed by the laws of the Republic of India, without regard to conflict-of-laws principles, and the courts at Bhopal, Madhya Pradesh, India have exclusive jurisdiction over any dispute arising out of it — subject always to your non-waivable statutory right to complain to a regulator, including the Data Protection Board of India, an EEA or UK supervisory authority, or the California Privacy Protection Agency.
20. Contact Us
- Company: Trades Replay
- Product: Trades Replay — https://tradesreplay.com
- Email (also the Grievance Officer): support@tradesreplay.com
- Business location: Bhopal, Madhya Pradesh, India
Questions about this document? Email support@tradesreplay.com. These documents are published in English. Any translation is provided for convenience only; in the event of a conflict, the English version governs.