← Back to TradinZ · Terms of Use · Disclaimer
Privacy Policy
Draft pending legal review — [Legal Entity] (the data controller), [address], and the contact details below must be completed and reviewed by licensed counsel before commercial launch.
Last updated: September 2026
1. The short version
TradinZ is built to know as little about you as possible. There are no user accounts, no advertising, no analytics trackers, and no sale or sharing of personal data. What the Service processes, it processes to show you financial data you asked for.
2. What we process, and why
- Brokerage API credentials (if you connect an account). A read-only API key you supply is stored in the Service's server configuration and used solely to fetch your positions from your broker so they can be displayed and analysed for you. Legal basis: performance of the service you requested. The connection cannot trade or move money. You can revoke the key at your broker at any time.
- Portfolio and research data you enter. Manual portfolios, theses, saved screens, logged predictions, and preferences are stored so the Service can show them back to you — on the server for portfolio-type data, and in your own browser's local storage for view preferences. Legal basis: performance of the service.
- Technical logs. Standard, short-lived server logs (timestamps, requested endpoints, error messages) used to keep the Service running. Legal basis: legitimate interest in operating and securing the Service.
We do not process special categories of personal data, we do not profile you, and we make no automated decisions with legal or similarly significant effect.
3. What we do not do
- No advertising, ad networks, or cross-site tracking.
- No sale, rental, or sharing of personal data with third parties for their own purposes.
- No third-party analytics scripts.
- No marketing emails — we don't collect your email address.
4. Third-party data sources
To display market information, the Service's server requests data from third-party providers (market-data APIs, regulatory-filing systems, public financial websites and feeds). These requests are made by the server on its own behalf and do not include your identity, your portfolio contents, or any personal data of yours. Your brokerage credentials are only ever sent to your own broker.
5. Cookies and local storage
The Service does not use tracking cookies. It uses your browser's local storage for functional preferences only (for example: the active screen, saved comparison tickers, builder settings). These values stay on your device and can be cleared at any time via your browser settings.
6. Retention
Portfolio and research data you enter is kept until you delete it in the Service or ask us to remove it. Brokerage credentials are kept until you replace or revoke them. Technical logs are retained briefly and rotated automatically.
7. Security
We apply reasonable technical measures appropriate to the data held — restricted file permissions for credentials, read-only broker scopes, and no storage of passwords or payment details. No system is perfectly secure; do not reuse sensitive credentials, and prefer read-only API keys wherever your broker offers them.
8. Your rights (GDPR)
If you are in the EU/EEA, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, the right to data portability, and the right to lodge a complaint with a supervisory authority (in Croatia: AZOP, azop.hr). To exercise any right, contact [contact email]. We will respond within the statutory deadlines.
9. Children
The Service is not directed at children under 16 and does not knowingly process their data.
10. International transfers
Third-party market-data providers the server queries may be located outside the EU/EEA (notably in the United States). Those requests do not contain your personal data. If future features require transferring personal data outside the EU/EEA, we will put appropriate safeguards (such as standard contractual clauses) in place and update this policy.
11. Changes
We may update this policy; the "Last updated" date reflects the current version. Material changes will be signposted on the Service.
12. Contact
Data controller: [Legal Entity], [address], Croatia. Contact: [contact email].