1. Information We Collect
Account information: Name, email address, and authentication credentials (via Supabase Auth with Google OAuth or email/password).
Brokerage account identifiers: Rithmic account IDs and provider names (Apex, Lucid, etc.) that you link to the Platform. We do not store your brokerage passwords. Credentials are used only during the validation step and are not persisted on our servers.
Trading activity: Signals generated, trades executed via copy trading, performance metrics, and strategy preferences. This data is used to operate the copy trading service and display your dashboard.
Payment information: Processed entirely by Stripe. We store only your Stripe customer ID and subscription status. We never see or store your credit card number.
Usage data: Pages visited, features used, timestamps, and device/browser information for analytics and service improvement.
2. How We Use Your Information
We use collected information to: (a) operate and maintain the Platform, (b) process subscriptions and payments, (c) execute copy trading assignments, (d) send trade alerts and service notifications, (e) improve the Platform and develop new features, (f) prevent fraud and enforce our Terms of Service, and (g) comply with legal obligations.
3. Information Sharing
We do not sell your personal information. We share data only in these cases:
Service providers: Stripe (payments), Supabase (authentication and database), Vercel (hosting), Cloudflare (DNS and security). Each provider processes data under their own privacy policies.
Strategy publishers: Publishers can see aggregate subscriber counts and anonymized performance metrics. They cannot see your identity, brokerage account, or personal details.
Legal requirements: We may disclose information when required by law, subpoena, or to protect the rights, property, or safety of TradeVibe, our users, or the public.
4. Data Storage and Security
Your data is stored in Supabase (hosted on AWS) with Row Level Security (RLS) policies that ensure you can only access your own data. All connections use TLS encryption. Brokerage connections use Rithmic's encrypted protocol. We implement access controls, audit logging, and regular security reviews. No system is 100% secure; we cannot guarantee absolute security.
5. Data Retention
We retain your account data for as long as your account is active. Trading history is retained for 24 months for performance analytics. If you delete your account, we will remove your personal data within 30 days, except where required by law (e.g., payment records for tax compliance).
6. Your Rights
You have the right to: (a) access your personal data via your dashboard and settings, (b) correct inaccurate information, (c) delete your account and associated data, (d) export your trading data, (e) opt out of marketing communications, and (f) withdraw consent for data processing. To exercise these rights, contact us at admin@tradevibe.co.
7. Cookies and Tracking
We use essential cookies for authentication (Supabase session tokens). We do not use third-party tracking cookies or advertising pixels. Analytics are limited to server-side page view counts.
8. International Transfers
Your data may be processed in the United States regardless of your location. By using the Platform, you consent to the transfer and processing of your data in the US.
9. Children
The Platform is not intended for users under 18. We do not knowingly collect data from minors. If we discover we have collected data from a user under 18, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. The "Effective" date at the top indicates the latest revision.