Privacy Policy
How we collect, use, and protect your information.
Information we collect
Account information
We collect email addresses and hashed passwords during registration. Google OAuth sign-ins provide name and email directly from Google.
Usage data
Anonymized usage data including pages visited, features used, and session duration is collected through Google Analytics and Yandex Metrica to enhance the service.
Paper trading data
Your paper trading positions, orders, and history are stored on our servers to deliver the simulation experience without involving real money.
Affiliate and referral data
If you participate in the Affiliate Program, we store referral attribution data (who referred whom), aggregated daily click counts, commission ledger entries, payout requests, and — for Ambassadors — content portfolio submissions. IP addresses associated with referral clicks are stored as irreversible SHA-256 hashes for fraud detection and are never stored in plaintext.
How information is used
We use collected information to:
- Deliver and maintain the service
- Send transactional communications (verification, password resets, alerts)
- Refine features through aggregated usage analysis
- Detect fraudulent activity (including affiliate fraud via churn rate monitoring and IP deduplication)
- Calculate and process affiliate commissions
- Meet regulatory requirements
We do not sell personal information to third parties.
Data storage and security
Infrastructure is located in the Asia-Pacific region. Passwords are hashed using bcrypt, API credentials use AES-256-GCM encryption, and transmission relies on TLS.
Cookies
We use the following cookies:
- tw_access, tw_refresh — authentication tokens (HttpOnly, Secure, session-scoped). Required for the service to function.
- tw_ref — affiliate referral attribution (first-party, 90-day duration, SameSite=Lax, Secure). Set when you arrive via a referral link. Stores the referrer code only, no personal data.
- NEXT_LOCALE — language preference (first-party, persistent).
- Analytics cookies from Google Analytics and Yandex Metrica. These can be disabled through browser settings.
Third-party services
We share data with: Google Analytics (usage analytics), Yandex Metrica (usage analytics), Stripe (card payment processing), and NOWPayments (cryptocurrency payment processing). Each operates under its own privacy framework. Market data is received from Binance, Bybit, OKX, and Dukascopy. These providers do not receive your personal data.
User rights
You may access, export, or delete your data. Account deletion requests are processed within 30 days. You may withdraw marketing consent anytime by contacting [email protected].
Data retention
Active accounts maintain their data indefinitely. Deleted accounts are soft-deleted and purged within 30 days. Server logs persist for 90 days. Affiliate commission records are retained for tax compliance purposes for 7 years after payout.
Children
The Service is not directed at individuals under 18. Minor data is promptly removed if discovered.
Policy updates
Significant modifications are communicated via email, with the header date reflecting the latest revision.