Privacy Policy

Last updated: July 15, 2026

This Privacy Policy describes how personal data is collected, used, and protected when you use TradeStack (the "Service"). It is written in compliance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Swedish Data Protection Act (Dataskyddslagen, SFS 2018:218), and the ePrivacy Directive (2002/58/EC).

1. Data controller

The data controller responsible for your personal data is:

Lucas Af Petersens - sole proprietorship (enskild firma), trading under the name TradeStack.
Corporate registration number (organisationsnummer): 0602217614
Registered address: Fyndvägen 4, Sweden
Approved for Swedish F-tax
Email: support@internalstandards.com

We are not required to appoint a Data Protection Officer (DPO) under Article 37 GDPR. All privacy-related requests are handled directly by the controller at the address above.

2. What TradeStack does

TradeStack is a software-as-a-service (SaaS) trade journal and analytics platform for individual traders. We help you manually log trades, import trade history from supported brokers (Alpaca, Tradovate, and CSV files), visualise your equity curve, calculate win rate and performance statistics, and review your trading on a calendar interface. We do not execute trades, custody funds, or provide financial, investment, or tax advice.

3. Categories of personal data we process

  • Account data - email address, hashed password, account creation date.
  • Profile and preference data - display name, account size, base currency, theme.
  • Trading data you provide - trade logs, instrument, side, entry/exit prices, quantity, P&L, journal notes, screenshots, tags, and CSV imports.
  • Broker integration data - read-only API credentials you choose to connect (Alpaca, Tradovate). These are stored encrypted and used solely to import your own trade history into your account.
  • Billing data - where applicable, billing country, VAT identifier, subscription status, and invoice history. TradeStack is currently free and does not require a payment method. Card numbers are never stored on our servers; any future payment processing would be handled directly by Stripe.
  • Technical data - IP address, browser type, device identifiers, and session cookies, processed for security and to keep you logged in.
  • Communications data - emails you send to support, our replies, and your marketing preferences (for example whether you have unsubscribed from product emails).

4. Purposes and legal bases (Art. 6 GDPR)

  • To provide the Service (account creation, journaling, analytics, broker imports) - performance of a contract (Art. 6(1)(b)).
  • To comply with Swedish accounting and tax law (Bokföringslagen 1999:1078, Mervärdesskattelagen 1994:200) - legal obligation (Art. 6(1)(c)).
  • To secure the Service, prevent fraud, and debug - legitimate interests(Art. 6(1)(f)).
  • Service-related transactional emails (security alerts, account confirmations, updates to Terms or Privacy Policy) - performance of a contract or legitimate interests, as applicable.
  • Product updates, feature announcements, and promotional emails - consent (Art. 6(1)(a)), which you may withdraw at any time by using the unsubscribe link in any email or contacting support@internalstandards.com.

5. Communications and marketing

We use your email address to send you service-related messages and, with your consent where required, product updates and marketing communications. Marketing emails include an unsubscribe link and we honour opt-out requests promptly. Even if you opt out of marketing, we may still send you transactional emails that are necessary to operate or secure your account.

We track whether you have logged trades so we can send relevant, helpful lifecycle messages (for example tips for new users or feature announcements). This processing is based on our legitimate interest in improving user onboarding and engagement, and you may object at any time.

6. Sub-processors and recipients

We do not sell, rent, or share your personal data with advertisers or data brokers. We rely on the following sub-processors, each bound by a Data Processing Agreement under Art. 28 GDPR:

  • Stripe Payments Europe, Ltd. (Ireland) - payment processing would be handled by Stripe if paid features are introduced in the future. Currently no payments are processed.
  • Supabase Inc. (acting through EU-region infrastructure) - managed database, authentication, file storage, and serverless functions powering the Service.
  • Loops Inc. - email marketing and lifecycle communication platform used to send product updates, onboarding messages, and feature announcements.
  • Alpaca Securities LLC / Tradovate LLC - only when you connect a broker account; data flows from the broker into your account at your request.

7. International transfers

Where a sub-processor processes data outside the European Economic Area (e.g. Stripe US affiliates, Supabase US affiliates, Loops US infrastructure, Alpaca in the US), transfers are protected by the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) and supplementary technical measures including encryption in transit (TLS 1.2+) and at rest (AES-256).

8. Retention

  • Account, profile, and trading data: kept while your account is active. Deleted within 30 days of account closure on request.
  • Marketing consent records: kept for as long as necessary to demonstrate compliance, generally until you withdraw consent or delete your account.
  • Backups: rotated and overwritten within 60 days.
  • Invoices, billing records and accounting data: retained for 7 years as required by the Swedish Bookkeeping Act (Bokföringslagen 7 kap. 2 §).
  • Support correspondence: 24 months.

9. Your rights under GDPR

You have the right to:

  • request access to your personal data (Art. 15);
  • request rectification of inaccurate data (Art. 16);
  • request erasure ("right to be forgotten") (Art. 17);
  • request restriction of processing (Art. 18);
  • receive your data in a portable, machine-readable format (Art. 20);
  • object to processing based on legitimate interests, including direct marketing (Art. 21);
  • withdraw consent at any time, without affecting prior lawful processing.

To exercise any right, email support@internalstandards.com. We respond within one month (Art. 12(3) GDPR). You also have the right to lodge a complaint with the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm.

10. Automated decision-making

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22 GDPR). Performance statistics shown in the Service are calculations on data you provide, not decisions about you.

11. Security

We apply organisational and technical measures appropriate to the risk (Art. 32 GDPR), including: TLS encryption in transit, AES-256 encryption at rest, hashed passwords, row-level security in the database, scoped service credentials, and audit logging. In the event of a personal data breach likely to result in a risk to your rights, we will notify the IMY within 72 hours and affected users without undue delay (Art. 33-34 GDPR).

12. Children

The Service is not directed to children under 18. We do not knowingly collect data from minors. Contact us if you believe a minor has created an account, and we will delete it.

13. Changes to this Policy

We will notify you by email at least 14 days before any material change takes effect. The "last updated" date at the top of this page reflects the most recent revision.