Privacy Policy

Last updated: June 17, 2026
Counsel review draft

These documents are working drafts prepared for beta access and lawyer review. They should be reviewed and finalized by qualified counsel before public launch, paid rollout, regulatory submission, or reliance in a dispute.

1. Beta and Counsel Review Status

This Privacy Policy is a working beta and counsel-review draft for LoopTrading. It is written to explain the data practices of the current application and to give privacy counsel a concrete document to review before public launch, LLC formation, paid billing expansion, and any broader state, federal, or international rollout.

LoopTrading is operated in the United States. The final launch policy should be updated with the legal entity name, business address, privacy contact, data protection contacts if needed, and any jurisdiction-specific notices required by counsel.

2. Short Version

We collect the information needed to provide automated trading software: account information, encrypted exchange API credentials, exchange account and trading data, bot configurations, billing records, support messages, security logs, and optional analytics. We do not sell your personal data. We do not share your trading activity, balances, API credentials, or bot configurations for advertising.

3. Information We Collect

3.1 Account and identity information

  • Email address, name, profile image, and account identifiers;
  • Hashed password if you use email and password sign-in;
  • OAuth profile data, such as Google email, name, and profile image, if you sign in with Google;
  • Beta access status, agreement version, acceptance timestamps, and account settings.

3.2 Authentication and security information

  • Login events, failed login events, IP address, approximate device/browser information, and user agent;
  • Rate-limit records, session data, security alerts, and operational audit logs;
  • Bug reports, screenshots, page URLs, and diagnostic data you choose to submit.

3.3 Exchange integration information

  • Exchange name, account label, and public API key identifier;
  • API secrets encrypted at rest using a key stored separately from the database;
  • Account balances, order status, fills, fees, symbols, and trade history fetched from connected exchanges;
  • Exchange errors, rejected orders, rate-limit events, and reconciliation data needed to keep bots accurate.

3.4 Bot, trading, and performance information

  • Bot names, symbols, strategy choices, offsets, order sizes, capital caps, safety settings, and runtime state;
  • Orders placed through the Service and their results, including fill price, quantity, fees, realized P&L, cycle count, and status;
  • Price candles, sandbox runs, backtest inputs, analytics views, and billing calculations;
  • Optional leaderboard opt-in data, such as anonymous or pseudonymous performance metrics.

3.5 Billing and payment information

  • Billing plan, trial status, subscription status, payment-method-on-file status, and billing cycle dates;
  • Stripe customer, checkout, subscription, invoice, setup intent, and payment identifiers;
  • Performance-fee calculation records, including billing windows, net realized profit, fee amount, carry-forward amounts, and charge status.

Payment cards are processed by Stripe. We do not store full card numbers, CVV codes, or complete card credentials.

3.6 Communications and support

  • Emails, support requests, bug reports, feedback, waitlist entries, notification preferences, and unsubscribe records;
  • Transactional email delivery metadata, such as whether a message was sent or failed.

3.7 Cookies, analytics, and device data

  • Essential cookies and local storage used for login, security, preferences, and consent choices;
  • Google Analytics page-view and navigation data when analytics is enabled and you grant analytics consent;
  • Sentry or similar error diagnostics when enabled, redacted where feasible;
  • Server logs such as request paths, response codes, timestamps, IP addresses, and error traces.

4. Sources of Information

We collect information from:

  • You, when you create an account, configure bots, connect exchanges, choose settings, contact support, or submit feedback;
  • Your connected exchanges, when you authorize us to read balances, orders, fills, fees, and market data through API keys;
  • Stripe, Google, Resend, Sentry, hosting providers, and other service providers used to operate the Service;
  • Your browser or device through cookies, local storage, headers, logs, and consent preferences.

5. How We Use Information

  • Operate the Service. Authenticate users, run bots, process exchange API instructions, reconcile state, display dashboards, and send notifications.
  • Protect users and the platform. Detect fraud, abuse, unauthorized access, suspicious activity, and technical failures.
  • Process billing. Manage trials, subscriptions, performance-fee calculations, invoices, payment method setup, and billing support.
  • Improve the product. Debug errors, monitor uptime, plan capacity, evaluate feature quality, and understand aggregate usage.
  • Communicate with you. Send transactional messages, security notices, product updates, support replies, billing notices, and optional summaries.
  • Comply with law. Respond to lawful requests, enforce terms, maintain tax/accounting records, and protect legal rights.

6. How We Share Information

We share information only as needed to provide, secure, bill, support, and improve the Service, or when required by law. Current provider categories include:

  • Hosting and infrastructure: Railway, Neon/Postgres, Upstash/Redis, and related infrastructure providers;
  • Authentication: Google OAuth if you choose Google sign-in;
  • Payments: Stripe for checkout, subscriptions, invoices, setup intents, and payment-method handling;
  • Email: Resend or other transactional email providers;
  • Error monitoring: Sentry or similar diagnostics providers when enabled;
  • Analytics: Google Analytics when enabled and allowed by consent settings;
  • Exchanges: Binance.US, Coinbase, or Kraken — whichever you connect. Additional exchanges (such as Binance global where legally available) may be supported later and will be listed here before they launch;
  • Professional advisers: lawyers, accountants, auditors, insurance providers, or compliance advisers under appropriate confidentiality expectations;
  • Legal and safety recipients: courts, regulators, law enforcement, or counterparties when required or appropriate to protect rights, safety, security, or legal compliance.

We do not sell personal data. We do not share personal data for cross-context behavioral advertising. If that changes, this policy and the app must be updated with any required opt-out mechanisms before the change occurs.

7. Sensitive and Financial Information

Exchange API credentials, exchange account data, balances, trading history, billing records, and financial account-related information can be sensitive. We use this information to provide the Service, secure accounts, process billing, comply with law, and support users. We do not use this information for advertising.

Depending on counsel's regulatory analysis, some LoopTrading data practices may need to be mapped against the Gramm-Leach-Bliley Act, the FTC Safeguards Rule, Regulation P-style privacy notices, state privacy laws, or other financial-data obligations. The current policy is drafted to make that review easier but is not a substitute for counsel's final determination.

8. Cookies and Consent

Essential cookies and local storage support login, security, preferences, theme settings, and consent choices. Analytics cookies are optional. When Google Analytics is enabled, the app defaults analytics consent to denied until you accept analytics cookies in the banner. You can decline analytics without losing access to core Service features.

9. Data Retention

We keep information for as long as reasonably needed to provide the Service, maintain security, meet legal and tax obligations, resolve disputes, and enforce agreements. Current expected retention includes:

  • Account data: for the life of the account, then deleted or anonymized after account closure unless retention is legally or operationally required;
  • Encrypted API secrets: deleted when you remove the exchange key or close the connected account, subject to backup and operational limits;
  • Trading, billing, and invoice records: retained as needed for accounting, tax, dispute, fraud-prevention, and audit purposes;
  • Server and security logs: usually about 30 days, unless needed longer for security, debugging, legal, or abuse-prevention reasons;
  • Backups: retained on provider backup cycles and deleted according to normal backup rotation;
  • Aggregated or anonymized data: may be retained indefinitely if it no longer identifies you.

10. Security

We use administrative, technical, and operational safeguards designed for the sensitivity of the information we handle. Current safeguards include TLS in transit, encrypted API secrets at rest, bcrypt password hashing, same-origin checks on mutating routes, rate limiting, logging, limited access to production systems, and monitoring for operational failures.

Before public launch, counsel and security reviewers should confirm the written security program, vendor oversight, incident response plan, breach notification obligations, access review process, MFA/admin controls, vulnerability testing cadence, secure disposal, and disaster recovery plan.

11. Your Choices and Rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to certain processing, withdraw consent, opt out of sale or sharing, limit use of sensitive personal information, or appeal a privacy request decision.

To make a request, contact [email protected]. If that mailbox has not yet been configured during beta, use the operator contact from your beta invitation. We may need to verify your identity before fulfilling certain requests. Some data may be retained where needed for security, legal, tax, billing, dispute, or operational reasons.

We will not discriminate against you for exercising privacy rights. Some requests, such as deletion of account or exchange data, may make it impossible to continue providing the Service.

12. State Privacy Notices

For U.S. state privacy-law review, the categories of personal information collected include identifiers; account credentials; commercial and billing information; internet, device, and network activity; geolocation inferred from IP address; financial and trading information; support communications; and inferences or analytics derived from use of the Service. We use and disclose these categories for the purposes described in this policy.

We do not currently sell personal information or share it for cross-context behavioral advertising. We do not knowingly collect personal information from anyone under 18.

13. International Users

The Service is operated from the United States. If you access it from outside the United States, your information may be processed in the United States and other locations where our service providers operate. Do not use the Service if doing so would violate laws applicable to you.

14. Children

LoopTrading is not directed to children or anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us so we can address it.

15. Changes to This Policy

We may update this Privacy Policy as the beta progresses, service providers change, or counsel completes review. Material changes may be announced by email, in-app notice, or renewed acceptance flow where appropriate.

16. Contact

Privacy questions can be sent to [email protected]. If that mailbox has not yet been configured during beta, use the operator contact from your beta invitation.