Privacy Policy
How we collect, use, and protect your personal data
Last updated July 31, 2026
1. Introduction and Scope
This Privacy Policy explains how TraderStudy, operating the TraderStudy.com platform ("TraderStudy", "the Company", "we", "us") collects, uses, discloses, and protects personal data when you visit https://www.traderstudy.com, register for or use the TraderStudy client portal, admin systems, or purchase access to the Service (together, the "Service"). It applies to visitors, registered users, and paying Clients worldwide, with particular attention to the requirements of Brazil's Lei Geral de Proteção de Dados (LGPD), Colombia's Ley 1581 de 2012 / Decree 1377, and, where applicable, the EU/UK GDPR and other applicable privacy laws.
2. Who Is Responsible for Your Data
TraderStudy, operating the TraderStudy.com platform ("TraderStudy", "the Company", "we", "us") acts as the data controller (or, under LGPD terminology, "controlador") for personal data collected through the Service. Where third-party processors act on our instructions (see Section 6), they act as data processors/operators.
3. Categories of Personal Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account & identity data | Name, email, country, phone, password (hashed) | Provided by you at signup |
| Payment & billing data | Billing details, transaction history, purchase/access status, and limited payment metadata made available by the payment provider | Collected or received through third-party payment services selected by us from time to time; where the provider collects card details directly, we do not store the full card number ourselves |
| Portal & product usage data | Login timestamps, licence key activation, EA configuration/settings, support tickets | Generated by your use of the Portal and Software |
| Marketing & communications data | Email opens/clicks, campaign engagement, opt-in/opt-out status | Collected via our CRM/email platform |
| Technical & device data | IP address, browser type, device identifiers, cookie identifiers | Collected automatically via website and Portal |
| Advertising identifiers | Ad click IDs, pixel/conversion events (e.g., Meta Pixel, Google Ads tag) | Collected via advertising platform tags on our website |
We do not collect your MT5 trading account password or bank account details directly. Licence activation uses an account/licence identifier only. Where payments are handled by a third-party payment provider, full payment credentials are generally submitted to and handled by that provider rather than stored by us, unless we clearly disclose otherwise.
4. How We Use Personal Data (Purpose and Legal Basis)
- To provide the Service — creating your account, issuing and validating licence keys, delivering Portal access and support (legal basis: performance of a contract).
- To process payments — handling the initial access purchase, any optional monthly or annual continued-access purchase, refunds, and fraud prevention (legal basis: performance of a contract; legitimate interest in fraud prevention).
- To communicate with you — service notices, renewal and billing reminders, security alerts, and responses to support requests (legal basis: performance of a contract; legal obligation for required disclosures).
- To market our Service — sending promotional emails and running ad campaigns (e.g., via Meta and Google), where you have opted in or as otherwise permitted by applicable law (legal basis: consent, or legitimate interest, depending on jurisdiction and channel).
- To improve the Service — analyzing aggregate usage and website analytics to improve features, content, and performance reporting (legal basis: legitimate interest).
- To comply with law — responding to lawful requests from regulators, tax authorities, or law enforcement, and maintaining records required for payment and consumer-protection compliance (legal basis: legal obligation).
5. Cookies and Tracking Technologies
Our website and Portal use cookies and similar technologies, including advertising pixels from Meta and Google where enabled, to operate the site, remember preferences, measure campaign performance, and personalize ads. Where required by applicable law, non-essential cookies and advertising technologies are activated only after the user has been given an appropriate consent choice, including the ability to accept, reject, or customize such technologies.
- Strictly necessary cookies — required for login, security, and core site functionality; cannot be disabled.
- Analytics cookies — help us understand aggregate site and Portal usage.
- Advertising/pixel cookies — used by Meta and Google to measure ad conversions and build custom or lookalike audiences from consenting users; these are only set with your consent where required by local law.
6. Third Parties We Share Data With
We share personal data only as necessary to operate the Service, and we require our processors to protect data under written agreements. Categories of recipients include:
- Payment providers — independent third-party payment processors, merchants of record, card-network-connected providers, or other payment services selected by us from time to time to process purchases, refunds, billing records, and fraud checks. We do not commit in this Policy to using any specific provider.
- CRM / email marketing platform (e.g., Brevo) — to send transactional and, where consented, marketing communications.
- Hosting and infrastructure providers — to host the website, Portal, and admin systems.
- Advertising platforms (Meta, Google) — to measure conversions and deliver ads, limited to data you have consented to share via pixels/tags.
- Professional advisors and regulators — where necessary for legal, accounting, audit, or compliance purposes, or in response to a lawful request.
- Successors — in the event of a merger, acquisition, financing, or sale of assets, subject to continued protection of your data under equivalent terms.
We do not sell personal data to third parties for their own independent marketing purposes.
7. International Data Transfers
Given our Clients may be based across Brazil, Colombia, and other markets, and our service providers may process data in other countries (including the United States and the European Economic Area), personal data may be transferred across borders. Where required, we use appropriate contractual, organizational, or other lawful safeguards recognized under applicable privacy law to protect personal data transferred internationally.
8. Data Retention
We retain personal data for as long as necessary to provide the Service, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Billing records are typically retained for the period required by applicable tax and financial-recordkeeping law. Marketing data is retained until you opt out or, if shorter, for the period permitted under applicable consent rules. Upon a valid deletion request (Section 10), we will delete or anonymize data not otherwise required to be retained.
9. Data Security
We use administrative, technical, and organizational safeguards appropriate to the sensitivity of the data we hold, including encrypted transmission (HTTPS/TLS), restricted internal access, and reliance on third-party payment providers for payment-card processing where applicable, so that full card numbers are not intended to reside on our own systems when the provider collects them directly. No system is completely secure, and we cannot guarantee absolute security, but we take reasonable steps to protect personal data against unauthorized access, loss, or misuse, and will notify affected individuals and, where required, regulators, in the event of a qualifying data breach, in line with applicable law.
10. Your Rights
Depending on your country of residence, you may have some or all of the following rights over your personal data, which you can exercise by contacting [privacy@yourdomain.com]:
- Access — request confirmation of, and a copy of, the personal data we hold about you.
- Correction/rectification — request correction of inaccurate or outdated data.
- Deletion/elimination — request deletion of personal data we no longer have a lawful basis to retain.
- Portability — request a copy of certain data in a structured, machine-readable format.
- Objection / opt-out — object to processing for direct marketing at any time, including by using the "unsubscribe" link in any marketing email.
- Withdraw consent — where processing is based on consent (e.g., certain cookies or marketing), withdraw that consent at any time without affecting the lawfulness of prior processing.
- Lodge a complaint — with the relevant privacy or data-protection authority in your country (for example, Brazil's ANPD or Colombia's SIC), if you believe your rights have been violated.
We will respond to verifiable requests within the timeframe required by applicable law (including, where relevant, LGPD, Ley 1581, or GDPR timelines), and may need to verify your identity before actioning a request.
11. Marketing Communications
Where you have opted in, we may send you promotional emails about the Software, new features, or offers via our CRM/email platform. You can opt out at any time using the unsubscribe link included in every marketing email, or by contacting [support@yourdomain.com]. Transactional messages (e.g., billing receipts, security notices, renewal reminders) are sent regardless of marketing opt-out status, as they are necessary to operate your Subscription.
12. Children's Privacy
The Service is not directed to, and we do not knowingly collect personal data from, individuals under 18 years of age. If we become aware that we have collected personal data from a minor without appropriate consent, we will take steps to delete that data.
13. Advertising Platform Disclosures (Meta / Google)
Where our website uses Meta Pixel or Google Ads/Analytics tags, those platforms may process certain technical and behavioral data as independent controllers of their own advertising ecosystems, under their own privacy policies. We configure these tools to align with each platform's financial-services advertising and data-use policies, including restrictions on sharing sensitive financial identifiers, and we honor applicable consent signals (e.g., cookie-consent choices) before activating non-essential advertising tags where required by local law.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or legal requirements. Material changes will be notified via the Portal or by email, and the "Last Updated" date at the top of this document will be revised accordingly. Continued use of the Service after an update constitutes acceptance of the revised Policy.
15. Contact Us
For privacy questions, data-subject requests, or complaints, please contact us at [legal@TraderStudy.com]. General support inquiries can be directed to [support@TraderStudy.com].
Recommended before launch: confirm final entity/contact details, actual payment and technology providers, and have qualified counsel confirm any additional registration, notice, consent, or data-transfer obligations that may apply in each market where the Service is offered.