Privacy Policy

Last updated: April 23, 2026

This Privacy Policy explains what data ApolloTrader ("we", "us") collects, how we use it, and the choices you have. ApolloTrader is operated from Alberta, Canada, and we design our practices to align with PIPEDA (Canada) and the GDPR (where applicable).

1. Information We Collect

Account information

  • Email address and a hashed password (we never store your password in plain text)
  • Optional profile fields you provide
  • When you sign in with Google, we receive your basic profile (email, name, profile image URL) — we do not receive your Google password

Trade data you upload

When you import a CSV from your broker, we store the executions contained in that file (symbol, side, quantity, price, timestamp, commissions, and similar fields), plus any notes or strategy tags you add. This is "Your Content" under our Terms.

Technical information

  • Browser type and general device information (collected automatically to ensure the service functions correctly across different devices)
  • A session cookie used to keep you signed in — this is strictly necessary for the service to function and is exempt from cookie-consent requirements under most frameworks
  • Basic usage analytics (pages visited, rough timing) collected through our hosting provider's built-in analytics — aggregated and not used to identify you personally

2. How We Use Your Information

  • To provide and operate the service — authenticate you, show your trade data, calculate metrics
  • To send transactional emails (account verification, password resets, important notices)
  • To detect and prevent abuse, fraud, or security incidents
  • To improve the product based on aggregated usage patterns
  • To comply with legal obligations

We do not sell your personal information, and we do not use your trade data to target you with advertising.

3. Sub-processors

We use the following third parties to operate the service. Each of them processes personal data on our behalf under their own security and privacy commitments:

  • Railway — application hosting and database (United States / global)
  • Vercel — frontend hosting and basic site analytics (United States / global)
  • Resend — transactional email delivery
  • Polygon.io — market data (no personal data is sent to Polygon; only public symbols)
  • Twelve Data — market data (no personal data is sent; only public symbols)
  • Google — OAuth sign-in (only when you choose to sign in with Google)

We will update this list when we add or remove sub-processors. If you'd like notice of changes, email us at support@apollotrader.app.

4. Cookies

We use a single session cookie to keep you authenticated. We do not use advertising or tracking cookies. Because our cookie is strictly necessary, we do not display a cookie consent banner.

5. Data Retention

We keep your account and trade data for as long as your account is active. When you delete your account, we remove your personal data and your trade data from our active systems within 30 days, except where retention is required by law (for example, tax or anti-fraud records).

6. Your Rights

Depending on where you live, you may have rights to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Export your trade data in a portable format
  • Object to or restrict certain processing, or withdraw consent where processing is based on consent
  • Lodge a complaint with a data protection authority (for example, the Office of the Privacy Commissioner of Canada)

To exercise any of these rights, email support@apollotrader.app. We respond within 30 days.

7. Security

We use industry-standard safeguards: encrypted connections (HTTPS), password hashing, access controls on our databases, and reputable hosting providers. No online service can guarantee absolute security, but we take the security of your trade data seriously. If you become aware of a vulnerability or incident, please report it to support@apollotrader.app.

8. International Transfers

Our sub-processors (including Railway, Vercel, Resend, and Google) operate servers outside of Canada, including in the United States and Europe. By using ApolloTrader, you understand that your data may be transferred to and processed in those jurisdictions under the safeguards those providers maintain.

9. Children's Privacy

ApolloTrader is not intended for anyone under 18. We do not knowingly collect data from children. If you believe we have, email us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or in the service before the changes take effect.

11. Contact

Privacy questions or requests? Email support@apollotrader.app.