chartping
This is an archived version. It is the text of the Privacy Notice exactly as published under version 2026-06 (effective 27 July 2026), kept unchanged so that anyone who accepted it can read what they accepted. It is not the current version — read the current Privacy Notice, and see every archived version.

Privacy Notice

Effective 27 July 2026 · Version 2026-06

This notice explains what personal data Chartping collects, why, the legal bases we rely on, who receives it, where it is processed, how long we keep it, how it is deleted, and your rights. It covers the marketing website (chartping.com), the account system, the cloud API, the web and mobile portals, and the Chartping desktop agent.

Chartping is a read-only monitoring and alerting tool. It does not place, modify or close orders, does not connect to your broker or exchange to trade, and does not hold or have withdrawal rights over your funds — which limits the personal data we handle by design. We run no advertising trackers and no ad network anywhere, and no third-party analytics service inside the product. We do keep one first-party measurement of our own, described under “How we use it”: it never leaves our database. On this marketing website we use Google Analytics, and only if you consent to it — see Cookie Policy.

Who we are

TrendSoft Ltd, a company registered in England and Wales, Company No. 16144241, registered office Aa House 54, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom, is the data controller for the processing described here. Privacy contact: [email protected] (general: [email protected]).

We have not appointed a Data Protection Officer: none of the conditions that make one mandatory applies to our processing at this scale. The privacy contact above is the route for all data-protection questions.

Controller or processor — which we are

For your account, your billing, and the monitoring of your own accounts, we are the controller. For Trader personal data processed as part of a Developer's licensing product — the subject attributes used to issue a licence, and Developer-to-Trader log and alert content we transport — the Developer is the controller and we act as their processor under a Data Processing Agreement, which forms a mandatory part of every Developer agreement. Direct requests about that data to the Developer; we will assist them and forward anything we receive.

Data you provide about other people. Content you publish through flows, inbound sources, webhooks or alert channels, and accounts you connect, may include other people's personal data. You must have the right to provide it. For such content we act on your instructions as an intermediary and are not responsible for your decision to collect or share it.

What we collect

We practise data minimisation. From your trading accounts we read read-only data only; connected API credentials must be read-only, are stored encrypted (AES-256-GCM) and are never returned in any API response or export.

  • Account and identity — email address, username, password (stored only as a salted hash), Google or Apple sign-in identifier, two-factor enrolment and recovery codes.
  • Security and sign-in records — sign-in and security events (type, outcome, IP address, browser user-agent), recognised login devices, and a device-recognition cookie identifier, so we can alert you to access from a new device.
  • Monitoring data — account equity, balance, margin, open positions (including stop-loss and take-profit levels), pending orders, closed trades, drawdown, per-minute equity points and a per-day equity summary. Stored in our cloud, keyed to your account and the trading-account identity (broker server and login number). Demo and live accounts are treated the same.
  • Device and agent— agent device identifier and public key, hostname, operating system, agent version, a hashed hardware-anchor identifier (a SHA-256 digest derived from the machine's firmware identifier — never the raw identifier), and device re-bind or clone lineage timestamps.
  • Alerts and notifications — verified phone number, email addresses you add, mobile push tokens, webhook URLs you configure, alert content and delivery status, escalation and acknowledgement records, and your notification preferences.
  • Flows and inbound sources — flow configuration, message bodies you or your systems publish, and delivery and audit records including publisher IP addresses.
  • Licensing subject data (processor role) — Developer-defined subject attributes stored as the Developer provides them, typically a trading-account number, plus a derived pseudonymous fingerprint and licence metadata.
  • Billing — subscription tier and status, and store or provider references. Full card details never reach us; payment happens on Apple, Google, RevenueCat or Stripe-hosted surfaces.
  • Consent records — which document versions you accepted and when; for SMS consent, the exact text shown, the timestamp, and the IP address and user-agent, kept as legal evidence.
  • Support and correspondence — messages you send us.
  • Marketing website and waitlist — waitlist email, optional context, your IP address for abuse prevention, referral source, and a record of your email confirmation; plus an anti-bot check on the form.
  • Website analytics (only with your consent) — if you accept analytics cookies on this website, Google Analytics records how you moved through the site: pages viewed, referring source, approximate location derived from a truncated IP address, and device and browser characteristics, tied to a randomly generated identifier stored in a cookie. If you decline, none of this is collected.

We do not intentionally collect special category data and ask that you do not provide it. We run no session recording and no advertising identifiers anywhere, and no analytics inside the product — the portal, the mobile apps and the desktop agent carry no measurement service.

Do you have to provide it? You are under no statutory obligation to give us personal data. Some is contractually necessary: without an email address we cannot create or run your account. The rest is optional and needed only for the feature it enables — a verified phone number only for SMS alerts, read-only API credentials only to connect an exchange account, a push token only for mobile push. Decline any of it and that feature is simply unavailable.

Why we use it, and our legal bases

  • Performance of a contract — creating and running your account; monitoring and alerting; issuing and validating licences; providing the portals and the agent; billing and entitlements.
  • Legal obligation — financial and tax record-keeping; answering data-subject requests.
  • Legitimate interests — securing the service (fraud and abuse prevention, rate limiting, sign-in auditing, new-device alerts, tenant-isolation auditing); staff-action accountability; preventing and investigating payment fraud and responding to chargebacks; improving and troubleshooting the service; and defending legal claims. We have assessed each of these against your rights and interests and record those assessments internally.
  • Consent — SMS alert delivery to your verified number (separate opt-in; withdraw any time by replying STOP or in settings); the waitlist launch email, which you confirm by email before we add you and which carries an unsubscribe link in every message; and website analytics, which is off until you accept in the cookie banner and can be switched off again at any time on the Cookie Policy page. We do not currently send any other marketing; if we introduce it, it will be opt-in only and off by default.

We may create aggregated or anonymised data that does not identify you and use it for lawful purposes including operating, measuring and improving the service.

Automated decision-making. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Automated security mechanisms such as temporary sign-in lockout and rate limiting protect your account and do not have such effects; you can contact us to have any security block reviewed by a person.

Who receives your data

Our processors, each under written terms:

  • Hetzner Online GmbH (Germany, with a standby site in Finland) — our platform: the dedicated servers we rent, and the databases holding all server-side data.
  • Microsoft Azure Key Vault (United Kingdom) — secrets management only: the keys and credentials the service needs. It holds no account or monitoring data.
  • Telnyx (United States) — SMS delivery, phone verification and STOP handling: your verified phone number and the alert text.
  • Brevo (European Union) — transactional and alert email: your email address and the message content.
  • RevenueCat (United States) — subscription management: an internal user identifier and subscription events.
  • Stripe (United States) — Developer-licensing billing: a customer identifier and subscription state; card data stays with Stripe.
  • Google (Firebase Cloud Messaging) — mobile push: the push token and the notification title and body.
  • Cloudflare (global edge) — the network edge for our hostnames and the anti-bot check on the waitlist form. All traffic transits and is decrypted at Cloudflare's edge, so its content passes through it; at rest, traffic metadata such as IP addresses.
  • Google (Google Analytics) (United States) — website analytics, and only where you have consented: the analytics identifier stored in your browser, pages viewed, referring source, truncated IP address and device characteristics. Advertising features and Google Signals are off, and we do not use analytics data for advertising.
  • Google Workspace (United States and global) — our own mailboxes: everything you send to support@, privacy@, security@ or legal@ and everything we reply, including data-request correspondence and any identity evidence you attach to it.

Recipients you choose, which are not our processors: notification endpoints you configure (webhook URLs, Discord, Slack, Telegram, Microsoft Teams, ntfy or any custom endpoint); your own broker or exchange, when you add a read-only API connection; Apple and Google, if you sign in with them or purchase through their stores; and your Developer, if you activate their product.

Others — professional advisers; authorities where the law requires; payment providers, app stores, card networks and banks where needed to resolve a payment dispute or investigate payment fraud; and, if we are ever involved in a merger, acquisition, financing, reorganisation, insolvency or sale of assets, the parties involved under confidentiality, with any successor required to honour this notice or give you notice of changes. We do not sell personal data and do not share it with data brokers or advertisers.

Where your data is processed

Our platform runs on dedicated servers we rent from Hetzner Online GmbH, in Germany, with a second site in Finland that takes over if the first becomes unavailable. Both are in the European Economic Area. Our secrets — the keys and credentials the service needs — are held separately in Microsoft Azure Key Vault in the United Kingdom. Data reaching the other providers listed above is processed in their locations. Agent-side data stays on your own device; the agent transmits monitoring telemetry to our cloud as described above.

We are a UK company, so sending your data to our servers in Germany and Finland is a transfer out of the UK. It needs no special safeguard: the UK recognises the EEA as providing an adequate level of protection, and that is what this transfer relies on. If you are in the EEA, your data stays within it apart from the specific providers named above.

Where personal data of someone in the UK or EU is transferred to a country without an adequacy decision, we rely on appropriate safeguards under Article 46 — the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses — as incorporated in the relevant provider agreement, together with contractual necessity for the underlying processing. Transfers to EU providers rely on UK-to-EU adequacy. You can request a copy of the relevant safeguard, redacted where necessary for commercial confidentiality, by writing to [email protected].

We do not rely on your consent for these transfers. A transfer that is unavoidable to provide the service cannot be freely consented to, so it is not bundled with any consent checkbox: it is disclosed here and made lawful by the safeguards above.

How long we keep it

  • Account, identity, contacts, devices and configuration — life of your account.
  • Per-minute equity points — 30 days.
  • Cash movements on a trading account (deposits, withdrawals, credits) — life of your account.
  • Closed trades — 180 days. Connector equity — 30 days.
  • Live telemetry snapshot (positions and orders) — about 24 hours.
  • Per-day equity summary — life of your account.
  • Alert history — 90 days. Flow messages — 7 days; delivery logs — 30 days; dead letters — 30 days; publish and audit records including publisher IP — 90 days.
  • SMS delivery logs — 90 days.
  • Sign-in and security audit events — life of your account.
  • Legal consent records — current acceptance kept; superseded records 2 years.
  • SMS consent evidence (text shown, timestamp, IP, user-agent) — about 5 years from withdrawal, kept as legal evidence.
  • Erasure-request record (proof we deleted) — 2 years.
  • Staff-action audit records (who did what to which account, which can include a snapshot of the changed data) — 6 years from the action, for accountability and defence of legal claims.
  • Billing and financial records — as tax and company law requires, typically 6 years.
  • Waitlist data — if you never confirmed your address, 30 days. Once confirmed, until the launch invitation or your removal request, and in any case no more than 24 months from when you confirmed. If you unsubscribe we keep the entry itself, so that the same address is not added and mailed again, but we delete the optional context and the IP address 30 days later.
  • Website analytics — the analytics cookie lasts up to 2 years in your browser; Google retains the associated event data for 14 months.
  • Support correspondence — 2 years after the request is closed.
  • Push tokens — life of your account; stale tokens are deleted automatically.

Deleting your account

When you delete your account — self-service in the portal, or by written request — we run a reviewed erasure process that hard-deletes your personal data across our operational systems in one transaction: account and contact details, devices, monitoring data including equity history and closed trades, alert history, notification channels, push tokens, webhook configurations, flow data, and connector accounts with their encrypted credentials. We then delete your sign-in and security audit records and your identity record from our sign-in system; if that step fails we re-run it until it completes, and your operational data stays deleted in the meantime. We also instruct RevenueCat to delete its subscriber record and take steps to cancel any active Stripe developer subscription.

What we keep despite erasure, each with the reason recorded:

  • SMS consent evidence — the record proving you opted in or out. It necessarily keeps the identifying details its legal purpose requires — the phone number, the exact text shown, the timestamp and, where recorded, the IP address and user-agent — because messaging-compliance law requires us to prove consent for that specific number. It is no longer linked to a live account.
  • The erasure-request record — proof we deleted your data.
  • Billing and financial records — where tax and company law require retention.
  • Staff-action audit records — an append-only log of administrative actions, which can include copies of data as it stood before and after a staff action, kept for accountability and defence of legal claims.

Backups. Copies of the database taken for disaster recovery may still contain your data for a short period after erasure. Today those are manual snapshots taken before a deployment or database change and kept only until the next one; when our automated backup regime is in place, erased data will age out of backups within the backup retention period. Restored data is re-erased before a restore is considered complete.

We describe deletion honestly: erasure is hard deletion of the underlying records, not anonymisation or key destruction. Records we must keep may still contain data capable of identifying you; we use them only for the stated purpose, restrict access to them, and delete them when their retention period ends.

You can export your data at any time from the portal, in a structured, machine-readable format.

Your rights

You have the right to access your data and get a copy; to have inaccurate data corrected; to erasure, subject to the exceptions above; to restrict processing; to data portability; to object to processing based on legitimate interests and to direct marketing (we stop marketing on request); to withdraw consent at any time where we rely on it, without affecting prior processing; and to complain to a supervisory authority — in the UK, the Information Commissioner's Office.

Use the self-service controls in the portal — export, deletion, consent withdrawal, channel management — or email [email protected]. We will verify your identity and respond within one month, extendable by two further months for complex requests, with notice of the reasons. Where identity verification is genuinely required, that period runs from when we receive the verifying information.

Security

We protect personal data with measures appropriate to the risk: TLS in transit; OAuth2/OpenID Connect sign-in with optional two-factor authentication, breached-password screening and sign-in throttling; short-lived access tokens; encryption of connected broker API credentials with key rotation; proof-of-possession binding of the agent connection so a stolen token alone is not enough; secrets in a managed vault; separation between our identity store and operational data; per-user data scoping; rate limiting; audit logging of sign-in events, staff actions and cross-tenant access; and staff access restricted to an allow-list with mandatory two-factor authentication. Connected API keys are never returned by any API. No method of transmission or storage is completely secure, but we work to protect your data and to respond to incidents — including notifying the ICO within 72 hours where a breach is likely to result in a risk to individuals, and notifying you where the risk is high.

Cookies

Cookies and similar technologies are described in our Cookie Policy. In short: cookies needed to sign you in, protect your account and remember choices you make in the app are set without asking; Google Analytics on this website is set only if you consent, and you can change that choice at any time on the Cookie Policy page. No advertising cookies are used anywhere.

Children

The service is not directed to, or intended for, anyone under 18, and we do not knowingly collect personal data from children.

Changes to this notice

We may update this notice. Each version is recorded, and every published version stays available at its own permanent address in the archive. Where a change is material we will notify you — by a notice in Chartping that appears the next time you open it and stays until you dismiss it, and by email where we hold an address for the purpose — and, where consent is the basis, ask for renewed consent before the change takes effect.

Contact

TrendSoft Ltd, Aa House 54, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom. Company No. 16144241. Privacy contact: [email protected] (general: [email protected]).

Every version of this document stays available, unchanged, at its own address — see the archive. If your record of what you accepted names a version, you can read exactly that text there.