Pre-release edition: the operator, public privacy contact, target countries, and final processing map are not yet confirmed. Real personal data and exchange keys must not be accepted.
This document explains TradeStat rules and practices. Its contents identify the document type and any action that applies; informational notices do not themselves constitute user consent.
Document status and operator
This policy is an informational notice, not blanket consent to data processing. If a particular operation requires consent, TradeStat will request it separately before that operation begins, without a pre-selected box and with the relevant version recorded.
As of this edition, the site is a preview using de-identified trading fixtures, a text editorial backend, and transitional sign-in for existing central AuthServer accounts. The legal entity or sole proprietor operating TradeStat, registration details, address, applicable jurisdiction, and public privacy contact have not yet been confirmed. Mass registration, exchange-key connections, and full production processing of personal data must not begin until they are published.
Scope and service roles
This policy covers the public TradeStat site, future dashboard, admin area, statistics, strategy marketplace, blog, and integrations. It does not replace the separate notices of the central AuthServer, exchanges, CopyTrader, or other external services.
Before launch, each party’s role must be formally determined: independent controller, joint controller, or processor acting on instructions. Even if one organization owns the products, the policy must still explain which information moves between them and why.
Categories, sources, purposes, and legal bases
The information involved depends on the selected feature. TradeStat applies data minimization: it does not collect information merely for possible future use and maps each category to a specific purpose. The table separates current operations from the planned production environment.
| Operation | Data and source | Purpose | Basis / status |
|---|---|---|---|
| Language and privacy settings | ru/en and category choices; user or browser | Display the selected language and remember the decision | Necessary site function; active now |
| Optional analytics | IP, browser, device, referrer, pathname, interactions; browser and Yandex Metrica | Traffic measurement and interface improvement | Separate consent; active only after choice |
| Transitional unified account | Login and password in request memory; central AuthServer. TradeStat keeps only a pseudonymous identity HMAC, keyed session HMAC, expiry, and local roles | Sign-in verification, short session, security, and role-based access | Technical preview for existing accounts; active without registration or seamless SSO |
| Trading statistics | Accounts, trades, positions, fees, source identifiers; exchange or CopyTrader connected by the user | Synchronization, metric calculation, and reports | Performance of selected feature; not connected yet |
| Support and security | Message, contact, IP, time, technical and audit context; user and systems | Answer requests, prevent abuse, and investigate | Contract, obligation, or legitimate interest; process not live yet |
Required data and consequences of refusal
Necessary settings can be cleared through browser controls, but the site will then determine language again and ask about optional technologies. Refusing analytics or Session Replay does not restrict the public site and must not restrict the future dashboard.
Sign-in requires the login and password of an existing central account. They are used only for one server-to-server AuthServer request and are not stored by TradeStat; without them, sign-in cannot work. Connecting an exchange is voluntary: without a key, TradeStat cannot automatically retrieve that account’s history, while other features remain available.
Recipients, vendors, and countries
The current demonstration web environment uses Zomro infrastructure in Germany and Cloudflare as an external network layer. After consent, analytics data is sent to Yandex Metrica; the applicable contracting entity, subprocessors, and countries depend on the tag owner’s account and must be confirmed before production.
The central AuthServer already receives the login and password solely to verify an existing account; its token remains a server-side proof and is not stored by TradeStat. CopyTrader, exchanges, object storage, email/support, and future vendors receive information only after the relevant integration and only to perform their function. A current list of recipients, countries, roles, and contractual safeguards will be published before full launch. TradeStat does not sell personal data.
Localization and international transfers
A German VDS is not automatically a lawful sole location for primary storage for every audience. Before launch, target countries and localization duties must be determined. If Russian Federal Law 152-FZ Article 18(5) applies to Russian citizens’ data, primary collection, recording, organization, accumulation, storage, alteration, and retrieval must be architected to meet Russian requirements; any later transfer is assessed separately.
If the GDPR applies, transfer outside the EEA requires an appropriate mechanism and country-risk assessment, not a sentence in a policy. For every actual flow, TradeStat must record the source, recipient, country, purpose, volume, and safeguard before enabling it.
Retention, deletion, and backups
Information is kept only while required for the stated purpose, a mandatory period, or the protection of legal rights. Before production, every category receives a specific period or testable criterion, process owner, and automated deletion job; saying “as long as necessary” without an internal rule is insufficient.
After account closure, active data is erased or de-identified on the approved schedule, except where law or a substantiated dispute requires retention. Deleted data may remain for a limited period in protected backups and expires through their rotation cycle; restoring a backup must not silently return previously deleted records to production.
User rights
Subject to applicable law, a user may request confirmation of processing, access and a copy, correction, deletion, restriction, portability, objection, and withdrawal of consent for the future. The user may also complain to a competent supervisory authority. Available rights and response periods depend on jurisdiction and processing basis.
A public request channel, identity-verification method that avoids excess collection, and response procedure will be published before real accounts are processed. A request must not require sign-in when the person cannot sign in. TradeStat will not ask for a password or complete exchange key to verify identity.
Security and incidents
The live preview uses protected transport, restricted administrative access, data minimization, and a prohibition on secrets in the repository, URLs, and product analytics. Encryption of future exchange keys under a separate master key, full production/staging separation, off-site backups, and restoration testing remain production launch requirements and are not represented as completed controls.
Production launch requires an approved incident-response process, named responders, and notification channels. During an incident, data is protected and restored, the cause is investigated, and users and authorities are notified to the extent and within the periods required by applicable law. No control eliminates risk completely.
Scores, profiling, and children
Current strategy scores and insights use demonstration data and do not make decisions with legal or similarly significant effects on a person. Personalized restrictions, automated moderation, or access decisions would require a separate assessment, an explanation of logic, and accessible human review before launch.
The service is not intended for children. A specific minimum age and enforcement approach must be approved together with the jurisdiction before registration. Until then, TradeStat must not knowingly collect minors’ data or market trading features to them.
Cookies, analytics, and updates
The detailed register of cookies, localStorage, sessionStorage, providers, retention, and the permanent control button is in the Cookie Policy. Ordinary analytics and Session Replay are requested separately; without the relevant permission, that Metrica feature is not enabled.
A material change to purposes, recipients, or user rights creates a new document version. Where processing relies on consent, old permission does not automatically extend to a new purpose. Prior editions and evidence of the text shown should remain in an archive.