Edgetrail

Privacy Policy

1. Controller

LudusNovus LLC
1209 Mountain Road Pl NE, Ste N
Albuquerque, NM 87110
United States

Represented by Marian van der Elst (Managing Member). Contact for all privacy matters: support@edgetrail.app or info@ludusnovus.com.

This policy applies to the Edgetrail website and web app (edgetrail.app). It fulfils the information duties under the EU General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (FADP) and the UK GDPR.

2. What data we process and why

a) Visiting the website. To deliver the page, the server technically processes your IP address as well as the date, time and requested address. Our server does not write access logs for this. Our hosting provider Infomaniak may keep short-term technical logs to fend off attacks. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, working service).

b) Account. Email address, an optional username, your password only as a salted hash (PBKDF2 – nobody can read it, not even us), language and time of registration. Sign-in sessions (tokens) are stored only as a hash and expire after 60 days. For each signed-in session we also store a rough device hint from your browser (brand and operating system, e.g. “Chrome · macOS”), the time of last activity and a short id. This lets you see your signed-in devices in settings and sign them out individually or all at once; when a new device signs in we also email you a notice. We use this only for your account security, not to re-identify a person. Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(f) GDPR (security of your account).

c) Your content. What you record in Edgetrail: trades, trading systems, journal entries (e.g. MMA, EODR, weekly reviews), goals and checklists, settings and uploaded chart images. This content may include information about your trading and finances. We do not analyse it and only look at it if you ask us to in support, if necessary to fend off an attack, or if required by law. Legal basis: Art. 6(1)(b) GDPR.

d) Emails about your account. We only send emails about your account and contract: welcome and confirmation, password reset link, notices when your password or email changes, a notice when a new device signs in, confirmation of your purchase, a confirmation link to delete your account, confirmations of cancellations and – only if you switch it on – your automatic backup (see i2). No marketing, no newsletter. Links in these emails work once and expire (confirmation after 7 days, reset and delete confirmation after 60 minutes); only a hash of them is stored. Sent via Infomaniak mail servers in Switzerland. Legal basis: Art. 6(1)(b) GDPR.

e) Abuse protection. When you sign in, register, use “Forgot password” or cancel, we store a hash of your IP address (not the address itself) and the username or email as counters to slow down automated attacks. The counters are valid for at most 24 hours and are then deleted automatically. Against bots, your browser invisibly solves a small computation; no data about you is collected and no third-party service is involved. When you register or change your password, we check whether it appears in known data breaches: only the first 5 characters of a SHA-1 hash are sent to the “Pwned Passwords” service (k-anonymity) – the password itself and the full hash never leave the server. Legal basis: Art. 6(1)(f) GDPR (security of your account and our service).

f) Record of your consent. At registration we store which version of the Terms and the Privacy Policy you accepted or acknowledged, and when. Legal basis: Art. 6(1)(c) and (f) GDPR (proof). Deleted with the account.

f2) One trial per person. For each account we store an irreversible checksum (SHA-256) of the normalised email address (case, dots in Gmail and “+tags” do not count). If you delete your account or change your email, the checksum of the previous address is kept – not the address itself – so the same person does not get a second trial. We reject disposable addresses at registration. Legal basis: Art. 6(1)(f) GDPR (protection against abuse of the free trial). The checksum of a previous address is deleted after 12 months.

f3) Deletion and data export. To protect your account, deletion takes two steps: your password and then a click on a confirmation link we email to your account address (valid 60 minutes). Only on that click is anything deleted; a running subscription is cancelled with Paddle immediately. If you chose “get your data by email”, the server compiles your data into a file and sends it via Infomaniak to your account address. If your account has no email address, the password alone is enough. Legal basis: Art. 6(1)(b) and Art. 20 GDPR.

g) Payment. When you buy a plan, the Paddle checkout opens. Paddle collects your name, payment and billing details there under its own responsibility as seller (Merchant of Record) and processes them according to its own privacy policy (paddle.com/legal/privacy). We never see card details. We pass your email address and an internal account number to Paddle so the purchase can be matched to your account. From Paddle we receive the plan, status, term and customer and subscription IDs and store them with your account. The checkout (Paddle.js) is only loaded once you choose a plan. Legal basis: Art. 6(1)(b) GDPR.

h) Cancellations. If you cancel via “Cancel contracts here”, we store the receipt (date, time), email, name (if given), type, reason, requested date and outcome. Legal basis: Art. 6(1)(b), (c) and (f) GDPR (contract handling and proof). We keep this for 3 years, also after the account is deleted, and then delete it automatically.

i) Reminders (optional). If you turn them on, we store the chosen times, your time zone and, per device, the subscription address of your browser’s push service (e.g. Google, Apple or Mozilla) with the related public keys. The content of every notification is end-to-end encrypted; the push service cannot read it. Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw it at any time by turning reminders off; the subscription is then removed – as it is when you sign out or delete your account.

i2) Automatic backup (optional). If you switch it on in settings, the server emails all your data as a JSON file to your account’s confirmed address at the interval you choose (weekly or monthly) – built the same way as the export on deletion. We store only the chosen interval, the language and the time of the last backup. Legal basis: Art. 6(1)(a) GDPR (consent); you can switch it off at any time in settings. Sent via Infomaniak mail servers in Switzerland.

j) Support. If you write to us, we process your message and contact details to reply. Legal basis: Art. 6(1)(b) or (f) GDPR. We delete the correspondence when it is no longer needed, at the latest 3 years after it is closed, unless a legal retention duty applies.

3. Storage in your browser

Edgetrail sets no cookies. Your browser’s local storage (localStorage) only holds what the app needs for the functions you ask for: sign-in token, language, appearance, currency and display settings, short interface notes, a postponed notice and – only if you use the exchange import – your API keys or wallet address for Bybit, Binance, OKX or Hyperliquid (they stay on your device only). This storage is strictly necessary to provide the service you explicitly requested (Art. 5(3) ePrivacy Directive; Section 25(2) no. 2 German TDDDG); no consent is needed. Account-related entries are removed when you sign out.

4. Direct requests from your browser to third parties

Some functions fetch data directly from your browser from other providers. The respective provider technically learns your IP address; we do not transmit trade or account data.

Legal basis: Art. 6(1)(b) GDPR (function you invoked). We serve fonts from our own server, not from Google. Links to other sites (e.g. TradingView) only open when clicked; the respective provider’s privacy policy applies there.

5. Recipients

We do not sell your data and do not pass it on for advertising. Under US law (e.g. the California CCPA/CPRA) we do not “sell” or “share” personal information.

6. Countries outside the EU and Switzerland

Your data is stored in Switzerland. The European Commission has recognised Switzerland and the United Kingdom as providing adequate protection; the Swiss Federal Council has done the same for the EEA and the United Kingdom. We ourselves are a company based in the USA. Where we access data from the USA for operation and support, or Paddle.com Inc. handles purchases from the USA, this is because it is necessary for the contract you requested (Art. 49(1)(b) GDPR; Art. 17(1)(b) FADP). According to Paddle, transfers are safeguarded by appropriate guarantees, in particular the European Commission’s Standard Contractual Clauses.

7. How long we keep data

We may delete free accounts that have not been used for 24 months. We announce this by email at least 30 days in advance.

8. Your rights

You have the right of access (Art. 15 GDPR, Art. 25 FADP), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR, Art. 28 FADP) and the right to withdraw consent at any time with effect for the future (Art. 7(3) GDPR).

Right to object (Art. 21 GDPR): where we process data based on our legitimate interest (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation.

Much of this you can do directly in the app: export data (JSON/CSV), change email and password, delete your account. For everything else write to support@edgetrail.app. We reply within one month, free of charge. To protect your data, please write from your account’s email address.

Complaints: you can lodge a complaint with a supervisory authority – in Switzerland the Federal Data Protection and Information Commissioner (FDPIC, Feldeggweg 1, 3003 Bern, edoeb.admin.ch), in the EU the authority of your place of residence or work, in the United Kingdom the Information Commissioner’s Office (ICO).

9. Required data and automated decisions

For an account we need an email address and a password; without them we cannot perform the contract. All other information is voluntary. There is no automated individual decision-making and no profiling within the meaning of Art. 22 GDPR or Art. 21 FADP. The analyses in Edgetrail are calculations for you, not decisions about you.

10. Security

Transmission only encrypted (HTTPS/TLS), passwords only as a salted hash, sessions and email links only as a hash, strict browser security policies (Content Security Policy), throttling of sign-in attempts, a notice when a new device signs in plus an overview and sign-out of your devices, sign-out of all devices on password change, and daily backups in Switzerland. No system is perfectly secure; should a personal data breach nevertheless occur, we will inform you and the competent authorities as required by law.

11. Minimum age

Edgetrail is intended for people aged 16 and over. We do not knowingly collect data from children under 16. If we learn of it, we delete the account.

12. Changes

We update this policy when Edgetrail or the law changes. We inform registered users of material changes by email or in the app.