Privacy Policy
Last updated: 1 March 2026
1. Introduction
TheTradeHub ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and your rights when you use our Service at thetraders-hub.com and our associated mobile applications (together, the "Service").
For the purposes of UK data protection law (including the UK GDPR and the Data Protection Act 2018), TheTradeHub is the data controller for personal data processed in connection with the Service. You can contact us at tradershubsupport@gmail.com.
By using the Service, you agree to the collection and use of information as described in this Privacy Policy.
2. Information We Collect
2.1 Account Information
When you register, we collect your full name, email address, and password (stored as a secure hash — never in plaintext).
2.2 MT5 Account Credentials
To connect your MetaTrader 5 accounts, we collect your MT5 account number, password, and broker server name. These credentials are stored encrypted and transmitted securely to MetaAPI solely to establish and maintain your account connections.
2.3 Trading Data
To operate the Service, we access trading data from connected MT5 accounts including open positions, trade history, account balance, and equity. This data is used solely to provide the features you enable (trade copying, position display, analytics).
2.4 Billing Information
Payments are processed by Stripe. We do not store full card details. We receive from Stripe: subscription status, billing history, Stripe customer/subscription identifiers, and limited payment method details (e.g. last four digits).
2.5 Device and Usage Data
We may collect Expo push notification tokens (to send trade alerts if you opt in), IP addresses, and logs and usage data (pages/screens visited, error logs) to secure and improve the Service. We do not use tracking cookies for advertising.
3. Lawful Bases for Processing
We process your personal data on the following lawful bases under UK GDPR:
- Contract: to provide the Service you request (account access, trade copying, subscription management).
- Legitimate interests: to secure the Service, prevent fraud and abuse, and improve reliability.
- Legal obligation: to comply with applicable laws (e.g. billing records for tax compliance).
- Consent: where required, such as sending push notifications (you can withdraw by disabling notifications in your device settings at any time).
4. How We Use Your Information
We use the data we collect to:
- Provide, operate, and maintain the trade copying Service
- Authenticate you and manage your account
- Process payments and manage your subscription
- Send push notifications about trade activity (if enabled)
- Send transactional emails (confirmations, password resets, billing receipts)
- Respond to support requests
- Detect, prevent, and investigate fraud, abuse, and security incidents
- Comply with legal obligations
We do not sell your personal data. We do not use your trading data for advertising.
5. Data Sharing
We share your data only as strictly necessary with the following service providers:
- MetaAPI / CopyFactory — MT5 account connectivity and trade copying (MT5 credentials and trading data shared as required to operate the Service).
- Supabase — database hosting, authentication, and backend services.
- Stripe — payment processing and subscription management.
- Expo — delivery of mobile push notifications (push tokens shared with Expo's push service).
We may also disclose information if required by law or in response to valid requests by public authorities.
6. International Data Transfers
Some of our service providers (including MetaAPI, Stripe, Supabase, and Expo) may process data outside the United Kingdom. Where this occurs, we take steps to ensure an adequate level of protection through appropriate contractual safeguards (including standard contractual clauses where applicable).
7. Data Retention
We retain personal data for as long as necessary to provide the Service and meet our legal obligations. If you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law (e.g. billing records for tax compliance). MT5 credentials are removed from our infrastructure providers promptly upon account deletion.
8. Security
We implement industry-standard security measures including:
- Encryption of sensitive credentials at rest
- TLS encryption for all data in transit
- Row-level security (RLS) policies on our database
- Secure authentication via Supabase Auth
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
9. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
- Access — request a copy of data we hold about you.
- Rectification — request correction of inaccurate data.
- Erasure — request deletion of your data (subject to legal retention requirements).
- Restriction — request restriction of processing in certain circumstances.
- Portability — request a portable copy of certain data.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is consent-based (e.g. push notifications), withdraw at any time via your device settings.
To exercise any of these rights, contact us at tradershubsupport@gmail.com. We will respond within 30 days.
You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO).
10. Automated Processing
The trade copying feature automates the replication of trades based on settings you configure. This does not constitute automated decision-making under Article 22 UK GDPR — all decisions about which accounts to connect and what settings to apply are made by you.
11. Cookies
We use only essential cookies required to operate the Service (e.g. authentication and session cookies). We do not use advertising or tracking cookies.
12. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal data from children. Contact us at tradershubsupport@gmail.com if you believe a child has provided us with personal data.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the Service. Continued use after changes take effect constitutes acceptance of the updated policy.
14. Contact
Questions about this Privacy Policy or our data practices: tradershubsupport@gmail.com