Last updated: this page is versioned with the site. The controller of your personal data is data broker s.r.o., Prague, Czech Republic. Privacy questions go to [email protected] and are answered by a person within one working day.
What we collect, and why
We collect as little as the site can function on. Everything below is listed with the reason and the legal basis under the GDPR.
- Nothing at all if you only read the site. No account, no profile, no tracking across other sites.
- Email address and password hash when you create an account. Basis: performance of a contract. Without them there is no account.
- Display name, country, bio and trading style if you choose to fill them in. Basis: consent. All optional, all editable, all deletable.
- Your favourites, challenge entries and points balance. Basis: performance of a contract — these are the account's function.
- Reviews you write. Basis: consent, given when you submit one.
- Purchase and payout proof documents. Basis: consent. See the retention section — these are deleted after verification.
- Newsletter email if you subscribe. Basis: consent, withdrawable from any email in one click.
- Server logs including IP address, for security and abuse prevention. Basis: legitimate interest. Retained 30 days.
What we never collect
We do not ask for and cannot see: your trading account credentials, your broker or firm login, your bank details, your card details, or your trading positions. Nothing on this site requires them, and any page asking you for them is not ours.
Proof documents
Verifying a review or a payout requires a document. We only ever need three things from it: the firm, the product or amount, and the date. You may blur everything else, and we would rather you did.
One person on our team checks the document and then deletes the file. We do not keep proofs after verification, we do not store them in a backup that outlives that deletion beyond our standard 30-day backup cycle, and we never pass them to the firm being reviewed. What remains is a flag on the review saying it was verified.
How long we keep things
- Account data: until you delete the account.
- Proof documents: until verification, typically under 48 hours. Then deleted.
- Published reviews: indefinitely, because other readers rely on them. On account deletion they become anonymous unless you ask us to remove them too.
- Newsletter subscription: until you unsubscribe, then a suppression record so we do not email you again.
- Server logs: 30 days.
- Backups: rolling 30 days, after which deleted data is gone from backups as well.
Cookies and analytics
Three categories, and only the first is set without asking.
- Strictly necessary: the session cookie that keeps you signed in and the CSRF token that stops form forgery. Without these the site cannot work, so they are set without consent, as the law permits.
- Analytics: aggregate page-view measurement with no cross-site tracking and no advertising profile. Declining it changes nothing about how the site behaves.
- Affiliate attribution: when you click through to a firm, that firm may set an identifier so it can attribute the sale. That cookie is set on the firm's domain under the firm's own policy, not ours. Declining it costs you nothing except the points you would have earned.
You can decline everything except the strictly necessary category and the site keeps working in full.
Who we share data with
We do not sell personal data. We have never sold personal data and the business model does not require it.
We share the minimum with processors who run parts of the service: hosting, transactional email, and the translation provider that processes editorial content — not personal data — for the multilingual versions of this site. Each is bound by a data processing agreement.
Firms listed on this site never receive your email address, your identity, or the documents you upload. When you click an affiliate link the firm learns that a visitor arrived from us, which is how attribution works everywhere on the web; it does not learn who you are from us.
International transfers
Some processors operate outside the EEA. Where they do, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision. We will name the specific processors on request.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your data, and to object to processing based on legitimate interest. You also have the right to withdraw consent at any time without affecting processing that already happened.
Most of this you can do yourself from your account settings without emailing anyone — export everything we hold, edit anything, or delete the account outright. For anything else, write to [email protected]. We answer within one working day and always within the statutory month.
If you believe we have handled your data badly, you may complain to your national data protection authority. We would prefer you told us first, but that right does not depend on it.
Children
This site is not for anyone under 18, and accounts require confirmation that you are over 18. If we learn that an account belongs to a minor we delete it.
Security
Passwords are stored as salted hashes and are never recoverable in plain text — not even by us. Traffic is encrypted in transit. Proof documents are stored outside the public web root and deleted after verification. Access to production data is limited to the people who need it.
No system is perfect. If we suffer a breach affecting your data we will tell you and the relevant authority within 72 hours of becoming aware, and we will tell you what actually happened rather than what sounds best.
Changes to this policy
If we change anything material we will say so on this page and, for changes that affect how we use your data, by email to account holders. We do not make material changes quietly — that would be a strange position for a site whose entire product is logging when other companies do exactly that.