Account and activity information
An account uses your name, email address, phone number and a password hash. The service stores account identifiers, profile updates, virtual cash records, paper orders, positions, completed trades, replay state, competition activity, referrals, notifications and support tickets or replies where you use those features. Do not put passwords, OTPs or brokerage credentials in support messages.
Why the information is used
Information is used to authenticate accounts, operate the simulator, keep account and order records consistent, administer competitions and referrals, deliver service messages, respond to support requests and investigate misuse or technical problems. Administrators can access information needed to operate these features.
Cookies and browser storage
The app uses an HTTP-only session cookie with a configured maximum lifetime of seven days. Session storage remembers navigation for a signed-in account. Local browser storage can hold chart drawings, preferences, cached interface data and promotion display state. Browser storage may remain on the device after logout or account removal until you clear it.
Service providers and external links
Hosting, database, security and email services process information needed to run TradeLab. The code supports Resend for service emails and Upstash for request-rate controls when configured. Requests can involve IP addresses and operational logs. Market-data requests use configured market-data providers. External links take you to services with their own privacy notices; do not share private account information in those URLs.
Promotions and competitions
The platform can display promotions created by its operator. Competition display names, rankings and results can be visible to other participants according to the competition view. Avoid putting sensitive information in your display name. The current public-page package does not add advertising-network scripts or third-party tracking analytics.
Retention and account deletion
Account and practice records are kept while needed to provide and administer the service, resolve issues and maintain operational records. A fixed retention schedule has not yet been published. The current account-removal process retains a limited deletion audit record, which can include the former account ID, name, email, phone and deletion details. Removing an account therefore does not automatically erase every record or data already stored in your browser.
Your requests and questions
You can update supported profile fields through your account. Use the contact page or in-app Support to request help with access, correction, account deletion or privacy concerns. Identity verification may be needed before changing or disclosing account information. Do not send a password as proof of identity.
Changes to this notice
This page should be updated when the product’s data practices change. The review date is shown below. Any future marketing analytics, paid services or new data uses need a corresponding policy review.