Privacy Policy
Last updated: 15 July 2026 - Version 5.0
1. Data Controller
SYNDICATES TRADING LTD is the data controller for personal data processed through the Syndicates platform, unless we state otherwise in a separate written agreement.
Company number: 17252162
Registered office: 128 City Road, London, United Kingdom, EC1V 2NX
Privacy contact: [email protected]
Data protection contact: [email protected]
This Privacy Policy is issued under the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 ("PECR") where applicable.
2. Personal Data We Collect
We collect and process the following categories of personal data:
2.1 Account and Profile Data
- Name and email address;
- Password hash, account role, account status, and registration timestamps;
- Avatar image where you upload one;
- Referral code, referrer information, and related attribution fields where provided.
2.2 Authentication and Security Data
- Two-factor authentication secrets, encrypted at rest;
- Failed login attempts, lockout timestamps, refresh token hashes, and token revocation records;
- IP addresses, user agents, request metadata, and security event logs.
2.3 Payment and Membership Data
- Stripe customer, payment, subscription, invoice, and portal identifiers;
- Membership status, plan type, access start and end dates, and billing events;
- Refund, chargeback, and support records relating to payments;
- Checkout legal acknowledgements (terms acceptance, immediate digital access request, and cancellation-rights acknowledgement).
We do not store full card numbers, CVV codes, or bank account details. Payment details are processed by Stripe.
2.4 Product, Community and Education Data
- Course progress, lesson completion, watched seconds, playback-start events, and content access logs;
- Discord ID, Discord username, encrypted Discord OAuth refresh token, and role-management events;
- TradingView username claims for indicator access;
- Support messages, admin notes, and related communication history.
2.5 Trading Journal and Backtesting Data
- Journal names, settings (for example starting balance, risk percentage, commission, timezone);
- Trade log entries (instrument/pair, session, date/time, risk-reward, notes, chart links);
- Optional share tokens and share-enabled status for read-only shared journal links;
- Admin or reviewer marks where a journal is reviewed inside the platform;
- Local browser storage used as a temporary draft/cache for journal workflows on your device.
If you enable journal sharing, anyone with the share link may view the shared journal content. Treat share links as confidential and disable sharing when no longer needed.
2.6 Cookies, Analytics, Device and Referral Data
- Authentication cookies, consent cookies, referral cookies, and Discord OAuth state cookies;
- Optional Google Analytics cookies and usage data where you accept analytics cookies;
- Timezone preference, news-filter preference, and temporary news calendar cache in browser storage;
- Affiliate click records, conversion attribution, IP address, and timestamps;
- Affiliate payout request records (amount, method, status) where the affiliate programme is used.
Full cookie details are in our Cookie Policy.
3. Lawful Bases
We process personal data only where a lawful basis applies:
- Contract: to create accounts, provide free and paid features, process memberships, host journals you create, provide support, and deliver the Services you request.
- Legal obligation: to keep accounting records, comply with tax, company, consumer, fraud-prevention, and lawful authority requirements.
- Legitimate interests: to secure the platform, prevent abuse, enforce terms, log paid content access for refund and chargeback evidence, improve the Services, and operate referral tracking where those interests are not overridden by your rights.
- Consent: for optional non-essential cookies (including Google Analytics and affiliate referral cookies), optional integrations where consent is required, and marketing communications if we ever send them on a consent basis. You can withdraw consent at any time.
4. How We Use Personal Data
- To operate, secure, and improve the Services;
- To authenticate users, maintain sessions, and provide account security features;
- To process payments, memberships, invoices, refunds, and chargeback evidence;
- To track paid content access, course progress, and refund eligibility;
- To provide trading journal, backtesting, and optional share-link features;
- To manage Discord roles, TradingView indicator claims, and support requests;
- To measure site usage with Google Analytics where you have accepted analytics cookies;
- To detect fraud, misuse, security incidents, and policy violations;
- To comply with legal obligations and respond to lawful requests;
- To send service emails such as welcome, reset-password, and security notices.
We do not currently operate a marketing newsletter. Service emails are sent as needed to provide the account and security features you request.
5. Sharing and Service Providers
We do not sell personal data. We share data with service providers only where needed to provide, secure, bill for, measure, or support the Services.
| Provider | Purpose | Typical location |
|---|---|---|
| Stripe | Payments, billing, invoicing, fraud prevention | UK, EU, United States |
| Discord | OAuth identity, community access, role management | United States and other regions |
| Google (Google Analytics) | Optional website analytics after cookie consent | United States and other regions |
| Cloudflare | DNS, security, CDN/proxy, TLS, abuse protection | Global |
| Proton Mail / SMTP provider | Transactional emails and support email handling | Switzerland / EU |
| Economic calendar feed provider | Server-side fetch of public market calendar data for the news widget | As operated by the feed host |
| Server hosting provider | Application hosting, file storage, database storage | As configured for the production server |
We may also disclose data to professional advisers, payment dispute handlers, insurers, regulators, law enforcement, courts, or other parties where required by law or necessary to establish, exercise, or defend legal claims.
If you enable a shared trading journal link, the journal content is intentionally available to anyone who has the link. That is a user-initiated disclosure, not a sale of data.
6. International Transfers
Some providers process personal data outside the United Kingdom, including providers in the United States (for example Stripe, Discord, and Google Analytics where used). Where this happens, we use appropriate safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, supplementary technical and organisational measures, or the UK Extension to the EU-US Data Privacy Framework where applicable.
For Google Analytics, processing is also subject to Google's terms and data protection terms applicable to that product. You may request information about relevant transfer safeguards by contacting us.
7. Retention
We keep personal data only for as long as needed for the purposes described in this Policy, including legal, accounting, tax, fraud-prevention, dispute-handling, and security purposes. Automated cleanup jobs enforce shorter technical retention for some logs.
- Account, profile, avatar, journal, and progress data: for the life of the account. After account deletion, we remove or anonymise personal data except where retention is required (for example tax, fraud, chargeback, or security records).
- Payment and invoice data: normally 6 years after the relevant transaction for accounting and tax records. Stripe may retain payment records under its own obligations.
- Content access events (video play / stream evidence): normally up to 2 years, then deleted automatically.
- Support messages: normally up to 1 year, unless longer retention is needed for disputes or legal compliance.
- Activity / security logs: normally up to 90 days, unless needed for investigation or legal claims. On account deletion, remaining activity log rows are detached from your user ID where retained for platform auditing.
- Affiliate click data: normally up to 90 days, then deleted.
- Refresh tokens, rate limits, password-reset tokens, and similar temporary security records: deleted or expired automatically according to their technical lifetime.
- Google Analytics data:retained according to the retention settings configured in our Google Analytics property and Google's product rules, and only collected after analytics cookie consent.
8. Your UK GDPR Rights
Subject to legal conditions and exemptions, you may have the right to:
- access a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion of your data;
- restrict or object to processing;
- receive certain data in a portable format;
- withdraw consent where processing is based on consent;
- complain to the Information Commissioner's Office.
Signed-in users can download much of their account data and request account deletion from account settings. You can also contact [email protected]. We may need to verify your identity. We aim to respond within one month unless the request is complex or an extension is permitted by law.
You can complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint. We ask that you contact us first so we can try to resolve the issue.
9. Security
We use technical and organisational measures designed to protect personal data, including password hashing, encryption of sensitive secrets, HTTPS, secure cookies, rate limiting, account lockout, token expiry, role-based access controls, audit logs, and administrative access controls.
No online service is completely secure. You are responsible for using a strong password, keeping credentials confidential, enabling two-factor authentication where available, and managing any journal share links you create.
10. Personal Data Breaches
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Where required by law, we will also notify affected users without undue delay.
11. Cookies and Similar Technologies
We use cookies and similar technologies to operate and secure the Services. Optional analytics and affiliate cookies require your consent. For details and preference controls, see our Cookie Policy.
12. Children
The Services are for users aged 18 or over. We do not knowingly provide accounts to children. If we learn that an account was created by a person under 18, we may close the account and delete or restrict related data in line with our legal obligations.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in our Services, providers, law, or processing activities. Material changes will be posted on this page and, where appropriate, notified by email or in-app notice. The version and date at the top of this page identify the current text.
14. Contact
Questions, requests, or complaints about privacy should be sent to:
SYNDICATES TRADING LTD
Company number: 17252162
Registered office: 128 City Road, London, United Kingdom, EC1V 2NX
Privacy contact: [email protected]
Data protection contact: [email protected]