Privacy Policy
Effective: April 17, 2026
This Privacy Policy explains how Trade Replay ("we", "our", "us") collects, uses, and shares information about you when you use the Trade Replay service at tradereplay.net ("the Service").
By using the Service you agree to the practices described here. If you don't agree, please don't use the Service.
1. Information we collect
a. Account information
When you sign up, our authentication provider (Clerk) collects your email address, display name, and a cryptographically hashed password or third-party OAuth identifier (e.g., Google). We receive a subset of this information to link it to your account inside the Service. We never see your raw password.
b. Usage data
Each time you load market data for a symbol and date, we log the symbol, date requested, and timestamp. We use this to enforce tier-appropriate rate limits and detect abuse. Logs are kept for as long as your account is active.
c. Billing information
If you subscribe to a paid tier, our payment processor (Stripe) collects and stores your payment details directly. We never receive or store your card number, CVC, or expiry. Stripe sends us a customer ID and subscription status via webhook so we can set your tier.
d. Imported trade data (client-side only)
When you import a broker CSV via the "Load Trades" feature, your trade data is stored exclusively in your browser's localStorage. It is never transmitted to our servers. Clearing your browser data or logging out of your browser will remove it. We cannot recover it for you.
e. Cookies and similar technologies
-
mr_guest— a session cookie set on anonymous visitors so we can apply per-guest rate limits. 30-day expiry. - Clerk session cookies — set by our authentication provider for signed-in users. See Clerk's Privacy Policy.
2. How we use the information
- To operate and improve the Service (authentication, serving market data, billing, abuse prevention)
- To communicate with you about your account (email verification, payment receipts, critical service updates)
- To enforce our Terms of Service
- To comply with legal obligations
We do not sell your personal information and we do not share it with advertisers. We do not use your imported trade data for any purpose — it never leaves your browser.
3. Third-party service providers
We rely on the following processors to operate the Service. Each receives only the data necessary for their specific function:
- Clerk — authentication and user management. Privacy policy.
- Stripe — payment processing for paid subscriptions. Privacy policy.
- Polygon.io — source of the historical market data served by the Service. We query Polygon on your behalf when a symbol is loaded. Privacy policy.
- Vercel — hosts the frontend web application. Privacy policy.
- Railway — hosts the backend API and stored data. Privacy policy.
- Cloudflare — DNS and edge services. Privacy policy.
4. Data retention
We retain account information and usage logs as long as your account exists. When you delete your account, we delete your account record and cascade-delete associated usage logs within 30 days, except where we must retain records for legal, tax, or fraud-prevention purposes.
Imported trade data in your browser's localStorage is under your control — we cannot see it and cannot delete it remotely. Clearing your browser storage (or using your browser's "Forget this site" feature) removes it instantly.
5. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your account and associated data
- Export your account data in a portable format
- Object to or restrict certain uses of your data
To exercise any of these rights, email support@tradereplay.net from the email address associated with your account. We'll respond within 30 days.
6. Security
We use industry-standard measures to protect your data in transit (TLS) and at rest (encrypted storage volumes). No system is perfectly secure, and we can't guarantee absolute security. If we ever discover a breach that affects your information, we will notify affected users promptly as required by applicable law.
7. Children's privacy
The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If we learn we have collected information from a child under 18, we will delete it.
8. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced in-app or via email. The "Effective" date at the top of this page indicates the most recent revision. Continued use of the Service after changes take effect constitutes acceptance.
9. Contact
Questions or privacy requests: support@tradereplay.net