Privacy Policy
This policy explains what personal data Tradante collects when you use our website and trading platform, why we collect it, who handles it on our behalf, how long we keep it, and the choices you have. We wrote it to be read, not skimmed past. If anything here is unclear, write to us at the address in section 16.
Who we are and what this covers
The service is operated by [legal entity name], [registered address] (“Tradante”, “we”, “us”). We are the data controller for the personal data described in this policy.
This policy covers the public website at tradante.com, the documentation site at docs.tradante.com, the logged-in platform (the “App”), the beta registration flow, and the emails and text messages we send you. It does not cover third-party websites we link to, or the prediction-market venues, blockchain networks or wallet apps you may use alongside us. Each of those has its own policy.
Capitalised product terms (levels, passes, challenges, Social Order Book, prize pools) have the meaning given in the Rulebook.
The short version
- We collect what the platform needs to run: your account details, what you do on the platform, the wallet you connect, and technical data such as your IP address and browser.
- Identity verification happens only when money moves. It is done by a specialised provider (Sumsub). We keep the outcome, not copies of your documents.
- We do not sell personal data and we do not run advertising networks or ad-tracking pixels on our pages.
- Optional cookies are optional. Analytics and remembered preferences only run if you allow them in the cookie card. You can change your mind at any time through Cookie settings.
- Some things are public by design: leaderboards, the parts of your profile you choose to show, and any transaction on the Base blockchain.
- You can ask for a copy of your data, a correction, or deletion. Legal record-keeping duties limit deletion of identity and transaction records for a fixed period.
What we collect
We group the data into the categories below. “You give it” means you type it in or upload it. “Collected automatically” means your browser or device sends it as part of using the site. “From others” means a third party passes it to us.
| Category | What it includes | How we get it |
|---|---|---|
| Account and profile | Email address, username, password (stored only as a one-way hash we cannot read), display name, avatar, preferred language, the referral code you registered with, your level, badges and achievements. | You give it; level and badges are generated by your activity. |
| Contact verification | Your email address and, if you add one, your mobile phone number, plus the one-time security codes we send to them. | You give it. |
| Identity verification (KYC) | Government-issued ID document, a selfie or liveness check, full name, date of birth, address, nationality, and the IP address at the time of the check. Collected by our verification provider only when you first deposit or withdraw funds. We store the result (approved, rejected, pending), the date and a reference number. The document images stay with the provider. | You give it to the provider; the provider gives us the result. |
| Wallet and payments | The wallet address(es) you connect, deposit and withdrawal amounts, the USDC balances held for you, transaction hashes on the Base network, and the payment records for any pass or product you buy. | You give it by connecting a wallet; the rest is generated by your transactions. |
| Trading and game data | Your simulated and funded trading accounts, orders, positions and trade history, scores, rankings, challenge and tournament entries, passes, the traders you follow and who follows you, and any signals or posts you publish through the Social Order Book. | Generated by your use of the platform. |
| Technical data | IP address, browser type and version, operating system, screen size, the pages you request and when, the page that referred you, and a device identifier we set so we can recognise a device you have already verified. | Collected automatically. |
| Beta registration | The email address you registered with, the IP address you registered from, the date, and the access code we issued. | You give the email; the IP is collected automatically. |
| Communications | Emails you send to support, replies to our messages, and survey answers. | You give it. |
| Partner and business contacts | Name, company, role and contact details of people who approach us about referral, white-label, introducing-party or venue-integration partnerships. | You give it. |
We do not deliberately collect special-category data (health, religion, political opinions and similar). Do not include it in free-text fields or support messages.
Why we use it
Where the law requires a legal basis (for example under the GDPR or UK GDPR), the basis for each purpose is shown in the right-hand column.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and run your account, execute your orders, keep your scores and rankings, pay out awards | Account, wallet and payments, trading and game data | Performance of our contract with you |
| Verify your identity and screen against sanctions lists before funds move in or out | Identity verification, wallet | Legal obligation (anti-money-laundering and sanctions rules); our legitimate interest in preventing fraud |
| Send security codes and recognise devices you have already verified | Contact verification, technical data | Performance of contract; legitimate interest in account security |
| Keep the game fair: detect duplicate accounts, coordinated offsetting trades, script abuse and other rule breaches | Technical data, trading and game data, account | Legitimate interest in the integrity of competitions and prize pools; performance of contract (the Rulebook) |
| Credit the partner who referred you and calculate partner earnings | Referral code, trading and payment data in aggregate | Performance of contract (with you and with the partner) |
| Send you service messages: confirmations, security alerts, changes to terms | Contact data | Performance of contract; legal obligation |
| Send you news and offers about our own products | Contact data | Consent, which you can withdraw at any time using the link in every message |
| Understand which pages are read and improve the site | Technical data (analytics) | Consent, given through the cookie card |
| Remember your display preferences between visits | Theme choice | Consent, given through the cookie card |
| Run the beta programme and count seats | Beta registration | Legitimate interest in running a controlled launch; the IP address is kept to detect repeated or automated sign-ups |
| Answer your questions and complaints | Communications | Legitimate interest; legal obligation where a complaint is regulated |
| Comply with law, respond to lawful requests, establish or defend legal claims | Any category as required | Legal obligation; legitimate interest |
Cookies and browser storage
On your first visit a card in the bottom-right corner asks which optional categories you allow. Necessary items cannot be switched off because the site does not work without them. Your choice is saved for one year and can be changed at any time via Cookie settings in the footer of every page. Optional items are not set, and the related scripts are not loaded, until you allow them.
Set by us
| Name | Type | Category | What it does | Lifetime |
|---|---|---|---|---|
.AspNetCore.Cookies | Cookie | Necessary | Keeps you signed in. Shared across our subdomains so you stay signed in on docs.tradante.com. | Expires after 4.5 hours without activity |
.AspNetCore.Session | Cookie | Necessary | Links your browser to your server-side session (your dashboard data while you are logged in). | Expires after 4.5 hours without activity |
.AspNetCore.Antiforgery.* | Cookie | Necessary | Protects forms against cross-site request forgery. | Browser session |
Devices | Cookie | Necessary | Remembers the identifiers of devices you have already verified with a security code, so we do not ask you again on every login. | 1 year |
BetaBypass, BetaInviteCode | Cookie | Necessary | Records that you passed the beta access gate. | 1 year |
BetaRegistered, BetaAccessEmail | Local storage | Necessary | Same purpose as above, kept in the browser so the beta gate does not re-ask you. | Until you clear your browser data |
ReferralCode | Cookie | Necessary | Holds the referral code from the link you arrived on so the referrer is credited when you register. | 30 days |
UserLanguage | Cookie | Necessary | Set only when you pick a language; shows the site in that language on later visits. | 1 year |
tr_consent, tr_cookie_consent | Cookie + local storage | Necessary | Your cookie choices from the consent card. | 1 year |
tr_theme | Local storage | Preferences | Remembers the colour theme you picked. Not stored if you decline Preferences. | Until you clear your browser data |
| Wallet connection data | Local storage | Necessary | Set by the wallet connection library only when you connect a wallet, so the connection survives a page reload. | Until you disconnect or clear your browser data |
Set by third parties
| Provider | Names | Category | What it does | Lifetime |
|---|---|---|---|---|
| Clicky (Roxr Software Ltd) | _jsuid and related Clicky cookies | Analytics | Page-view statistics: which pages are read, from which country and browser. Loaded only after you allow Analytics. | Up to 1 year |
| Google reCAPTCHA | _GRECAPTCHA | Necessary | Tells automated sign-ups apart from people on the registration and beta forms. | 6 months |
| Google Fonts, jsDelivr | None | Necessary | Deliver the web fonts and script libraries the pages use. They set no cookies, but your browser sends them your IP address and browser details when it fetches the files. | — |
The Marketing category in the consent card is reserved for future campaign-attribution tags. Nothing is set under it today; if that changes we will update this table and ask for consent again.
You can also block or delete cookies in your browser settings. If you block the necessary ones you will not be able to sign in.
Who processes data for us
We use specialised companies to run parts of the service. They act on our instructions under written contracts and may only use the data to provide their service to us. The table lists every provider that receives personal data today.
| Provider | What they do for us | What they receive | Location |
|---|---|---|---|
| Microsoft Azure | Hosting, databases, file storage and message queues for the whole platform. | All categories in section 3, stored encrypted at rest. | [Azure region, e.g. West Europe / East US] |
| Sumsub (Sum and Substance Ltd) | Identity verification and sanctions screening. | ID document images, selfie, name, date of birth, address, nationality, IP address. | United Kingdom / European Union |
| Twilio Inc. | Sends SMS security codes. | Mobile phone number, the code text. | United States |
| Twilio SendGrid | Sends our emails (security codes, confirmations, service notices). | Email address, message content. | United States |
| Reown (WalletConnect) | Relays the connection between your wallet app and our site. | Wallet address, connection session data, IP address. | [Switzerland / United States] |
| Google (reCAPTCHA, Fonts) | Bot protection on forms; web font delivery. | IP address, browser details, interaction signals on protected forms. | United States |
| jsDelivr | Content delivery network for script and style libraries. | IP address, browser details. | Global network |
| Clicky (Roxr Software Ltd) | Website analytics, only with your consent. | IP address, pages viewed, browser details. | United States |
Prediction-market venues. When an order you place is executed on an external venue such as Kalshi or Polymarket, the venue receives the order details (market, side, size, price). Orders are routed through accounts held by us, so the venue does not receive your name or account identity. If you choose to connect your own venue account, that venue collects data under its own policy.
Base blockchain. Deposits, withdrawals and prize payouts are settled in USDC on the Base network. The wallet addresses, amounts and timestamps of those transactions are written to a public ledger that we do not operate and cannot edit or erase. Anyone can read them. Do not connect a wallet whose history you want to keep private.
What is public by design
- Leaderboards and rankings show your username, level, badges and score to everyone on the platform.
- Your profile shows what you allow it to show. In the App you can switch personal information, trading experience, social profile and follower lists between public, followers-only and private.
- The Social Order Book shows positions and signals you choose to publish, under the visibility you set. Anything you post there can be seen by the audience you selected and may be copied by them.
- Blockchain transactions are public and permanent, as described in section 6.
Your email address, phone number, identity documents, IP address and wallet-to-account link are never shown to other users.
When we share data
We share personal data only in these cases:
- With the processors in section 6, to run the service.
- With partners who referred you: they see that a referred user registered and the earnings the referral generates in aggregate. They do not receive your name, email or trading detail.
- When the law requires it: to courts, regulators, tax authorities or law enforcement acting under a valid legal process, and to sanctions or anti-money-laundering authorities where we are obliged to report.
- To protect the platform and its users: to investigate fraud, cheating or security incidents, and to enforce the Rulebook.
- In a corporate transaction: if we merge, are acquired or sell assets, the data transfers with the business under this policy, and we will tell you before it does.
We do not sell personal data, we do not share it with data brokers, and we do not place advertising trackers on our pages.
Where data is stored
Our systems run on Microsoft Azure in [region]. Some providers in section 6 are based in the United States or elsewhere. Where data about people in the European Economic Area, the United Kingdom or Switzerland leaves those areas, we rely on [the European Commission’s Standard Contractual Clauses and the UK Addendum / the EU-US Data Privacy Framework where the provider is certified], plus the provider’s own security commitments. You can ask us for a copy of the safeguards that apply to a given provider.
How long we keep it
| Data | Kept for | Why that long |
|---|---|---|
| Account and profile | While your account is open, then [24 months] | Handle reopening requests, disputes and support after closure |
| Identity verification result and reference | [5 years] after the last transaction or account closure, whichever is later | Anti-money-laundering record-keeping |
| Deposits, withdrawals, payouts and purchase records | [7 years] | Financial and tax record-keeping |
| Trading and game history | While your account is open, then anonymised: the username is removed but the trades stay in aggregate statistics | Historic leaderboards and competition results must stay verifiable |
| Security codes | Until used or expired, at most [15 minutes] | Only needed for the login attempt |
| Verified-device identifiers | 1 year from the last visit | Cookie lifetime |
| Server access logs including IP address | [90 days] | Security investigation window |
| Beta registration (email + IP) | Until public launch plus [12 months], or until you ask us to remove it | Seat allocation and abuse detection during the beta |
| Analytics (Clicky) | Up to [1 year] | Trend comparison year over year |
| Support correspondence | [3 years] from the last message | Complaint handling and legal claims |
| Blockchain transactions | Permanent | Public ledger we do not control |
When a period ends we delete the data or strip everything that identifies you. We may keep data longer if it is needed for an ongoing investigation, dispute or legal hold.
How we protect it
- All traffic between your browser and our servers is encrypted (HTTPS). Data is encrypted at rest on Azure.
- Passwords are stored only as salted one-way hashes. We cannot see your password and will never ask for it.
- New devices must be confirmed with a one-time code sent to your email or phone.
- Identity documents never touch our servers; they go directly to the verification provider.
- Secrets and API keys are held in Azure Key Vault with role-based access; staff access to production data is limited to named administrators and logged.
- Customer funds are held in audited vault contracts on Base, not in a company bank account, and every movement is visible on-chain.
No system is perfectly secure. If a breach affects your data in a way that puts you at risk, we will notify you and the relevant authority as the law requires.
Your rights and choices
Depending on where you live you may have some or all of the following rights. We apply them to everyone regardless of location, within the limits of the retention duties in section 10.
- Access: ask for a copy of the personal data we hold about you.
- Correction: fix inaccurate or incomplete data. Most profile fields you can edit yourself in the App.
- Deletion: ask us to close your account and erase your data. Identity-verification results and financial records are kept for the periods in section 10 because the law requires it; everything else is deleted or anonymised.
- Portability: receive your account and trading data in a machine-readable file.
- Objection and restriction: object to processing based on legitimate interest, or ask us to pause processing while a dispute is resolved.
- Withdraw consent: change cookie choices at any time via Cookie settings; unsubscribe from marketing through the link in any message. Withdrawing consent does not affect processing that already happened.
- Complain: you can lodge a complaint with your local data-protection authority. We would appreciate the chance to resolve it first.
To exercise a right, email info@tradante.com from the address on your account. We may ask you to confirm your identity before acting. We answer within [30 days]; if a request is complex we will tell you why and when to expect the answer.
California residents: we do not sell or share personal information for cross-context behavioural advertising, and we do not use or disclose sensitive personal information other than to provide the service. You may exercise the rights above without discrimination.
Automated decisions
Two processes run automatically and can affect what you may do on the platform:
- Identity and sanctions screening by our verification provider. A rejection blocks deposits and withdrawals. You can ask for a human review by contacting us; a member of our team looks at the file and the provider’s reasons.
- Fair-play checks flag patterns such as duplicate accounts, mirrored positions between accounts, or scripted order flow. A flag never disqualifies you on its own: a person reviews it before any competition result, payout or account is affected, and you are told the reason and can respond.
Age requirement
The platform is for adults. You must be at least 18 years old, or the age of majority where you live if that is higher, to create an account. We do not knowingly collect data from anyone younger. If you believe a minor has registered, tell us and we will remove the account and its data.
Changes to this policy
We will update this page when what we collect or who processes it changes. The version number and effective date at the top move with each change. For a material change, such as a new category of data or a new purpose, we will tell you by email or by a notice in the App before it takes effect, and where consent is required we will ask for it again.
Contact
Privacy questions and requests: info@tradante.com
Postal address: [legal entity name, registered address]
Data protection contact: [name or role, if one is appointed]