Privacy Policy
This Privacy Policy explains how TailJournal (“TailJournal”, “we”, “us”, or “our”) collects, uses, discloses, and safeguards personal information when you use our trading-journal and analytics platform, our websites, and related services (collectively, the “Services”). TailJournal is built for active retail and proprietary traders who want a rigorous, auditable record of their trading. Because our core function is to import, store, and analyze your broker trade data, we treat that data and the credentials used to obtain it with particular care. This document describes what we hold, why we hold it, the legal grounds we rely on, who we share it with, how long we keep it, and the rights you can exercise. It is intended as a clear, accurate template reflecting common SaaS practice and applicable data-protection law, including the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). It is not a substitute for individualized legal advice. If you do not agree with this Policy, please do not use the Services.
011. Who We Are and Scope
TailJournal operates the Services described at our website and within the application. For personal information processed about users of the Services, TailJournal acts as the data controller, meaning we determine the purposes and means of processing. Where we process data strictly on behalf of a business customer under a separate agreement, we may act as a processor; in that case the business customer is the controller and their privacy notice governs.
This Policy applies to personal information we collect through the application, our marketing and documentation sites, email and support channels, and any integrations you choose to connect, such as broker accounts. It does not apply to third-party services we do not control, including your broker, exchange, or any external website we link to. Those services operate under their own privacy policies, which you should review.
022. Information We Collect
We collect information you provide directly, information generated as you use the Services, and information we receive from integrations you authorize. The categories below describe what we typically hold for an active account. We aim to collect only what is necessary to operate, secure, and improve the Services.
The single most sensitive category we handle is your trading data and the broker access credentials used to retrieve it. Broker access tokens and API keys are encrypted at rest using industry-standard encryption and are scoped, wherever the broker permits, to read-only access so that we can import history and positions without the ability to place, modify, or cancel orders on your behalf.
033. How and Why We Use Your Information
We use personal information to deliver the Services you ask for and to run our business responsibly. In practice this means importing and reconciling your broker history, computing analytics such as expectancy, win rate, average R-multiple, drawdown, and profit factor, and presenting your journal in a usable form. We also use data to keep accounts secure, prevent abuse, and meet our legal and financial obligations.
We do not use your individual trading data to make trading recommendations to other users, and we do not sell your personal information. Where we analyze data to improve the Services, we rely on aggregated or de-identified data wherever feasible so that outputs do not identify you.
044. Legal Bases for Processing (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process personal information only where we have a valid legal basis under Article 6 of the GDPR. The basis we rely on depends on the specific purpose of processing, as set out below. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
055. How We Share Information and Sub-Processors
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose information only to the service providers (sub-processors) that help us run the Services, to comply with law, or in connection with a corporate transaction, each as described below. Sub-processors are bound by contract to process data only on our instructions, to maintain appropriate security, and to use it solely to provide their service to us.
The categories of sub-processors we engage are listed below. The specific vendors within each category may change as our infrastructure evolves; we maintain reasonable safeguards across all of them and update our records accordingly.
066. Legal and Corporate Disclosures
We may disclose personal information when we believe in good faith that disclosure is necessary to comply with a law, regulation, legal process, or enforceable governmental request; to enforce our terms of service; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of TailJournal, our users, or the public.
If TailJournal is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will continue to protect it in accordance with this Policy and will notify affected users where required by law before their information becomes subject to a materially different privacy policy.
077. International Data Transfers
We operate globally and may process and store personal information in countries other than the one in which you reside, including the United States. These countries may have data-protection laws that differ from those in your jurisdiction. Wherever we transfer personal information across borders, we take steps to ensure it remains protected in line with this Policy and applicable law.
For transfers of personal information out of the EEA, the United Kingdom, or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards, principally the European Commission’s Standard Contractual Clauses (SCCs) and, for UK transfers, the UK International Data Transfer Addendum, supplemented by additional technical and organizational measures where needed. You may request more information about these safeguards using the contact details below.
088. Data Retention
We keep personal information only for as long as necessary to fulfill the purposes described in this Policy, including providing the Services, complying with legal, accounting, and tax obligations, resolving disputes, and enforcing our agreements. When data is no longer needed, we delete it or irreversibly de-identify it. The table below summarizes our typical retention periods; specific periods may vary where a longer term is required by law or a shorter term is appropriate.
099. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These include encryption of data in transit using TLS and encryption of sensitive data at rest, with broker access tokens and API keys encrypted using industry-standard algorithms and managed key material. We apply the principle of least privilege, role-based access controls, and audit logging to internal systems, and we scope broker connections to read-only access wherever the broker supports it.
Additional measures include network isolation, regular patching, dependency and vulnerability scanning, encrypted backups, and periodic review of our security posture. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security. You are responsible for keeping your password confidential, enabling available security features such as multi-factor authentication, and notifying us promptly if you suspect unauthorized access to your account. If we become aware of a personal data breach, we will notify affected users and regulators as required by applicable law.
1010. Your Rights Under GDPR
If you are in the EEA, the United Kingdom, or Switzerland, you have rights over your personal information, subject to certain conditions and exemptions. We will respond to verified requests within the time frames required by law, normally within one month. We will not discriminate against you for exercising these rights.
To exercise any right, contact us at privacy@tradrtrades.com. We may need to verify your identity before acting on a request. If you believe we have not handled your information lawfully, you have the right to lodge a complaint with your local supervisory authority, though we encourage you to contact us first so we can resolve the matter.
1111. Your Rights Under CCPA/CPRA
If you are a California resident, you have rights under the CCPA as amended by the CPRA. Over the preceding 12 months we have collected the categories of personal information described in the Information We Collect section, used them for the purposes described in this Policy, and disclosed them to the sub-processor categories listed above to operate the Services. We have not sold personal information and have not shared it for cross-context behavioral advertising.
Because we do not sell or share personal information as those terms are defined under the CPRA, there is no information to opt out of; we nonetheless honor a “Do Not Sell or Share My Personal Information” preference and recognized opt-out signals such as Global Privacy Control as a confirmation of that practice. We do not use or disclose sensitive personal information for purposes beyond those permitted under the CPRA, so no separate right to limit applies. You may exercise the rights below, and you may use an authorized agent to submit a request on your behalf.
1212. Cookies and Tracking Technologies
We use cookies, local storage, and similar technologies to keep you signed in, remember your preferences, secure the Services, and understand how the application is used. Strictly necessary cookies are required for the Services to function and cannot be switched off through our consent controls. Analytics and preference cookies are optional and, where required by law, are set only with your consent.
You can manage non-essential cookies through our cookie controls and through your browser settings, which let you block or delete cookies. We honor browser-level opt-out signals such as Global Privacy Control where applicable. Disabling some cookies may affect the functionality of the Services. We do not use cookies to serve cross-context behavioral advertising.
1313. Children’s Privacy
The Services are intended for adults and are not directed to children. You must be at least 18 years old to create an account and use TailJournal. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete that information and terminate any associated account. If you believe a minor has provided us with personal information, contact us at privacy@tradrtrades.com so we can take appropriate action.
1414. Changes to This Policy and Contact
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Services. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice such as an in-app message or email. We encourage you to review this Policy periodically. Your continued use of the Services after an update takes effect constitutes acceptance of the revised Policy to the extent permitted by law.
If you have questions, requests, or complaints about this Policy or our handling of your personal information, contact our privacy team at privacy@tradrtrades.com. We will work with you in good faith to resolve any concern and, where required, will respond within the time frames set by applicable law.