Privacy Policy
Last updated: 20 May 2026 · Effective: 20 May 2026
1. Who we are
TradeDNA (“TradeDNA,” “we,” “our,” or “us”) is a post-trade behavioural analytics product for Indian retail traders, operated by TradeDNA.
We are not a SEBI-registered Research Analyst (RA) or Investment Advisor (IA). Nothing on this platform constitutes investment advice, buy/sell signals, price targets, or forward-looking trade recommendations of any kind. All AI analysis is retrospective.
2. What data we collect
- Account data: email address, display name, phone number (optional).
- Trade data: instrument name, entry/exit prices, quantity, direction, timestamps, tags, reflections, and mistake notes — entered manually or imported via broker CSV.
- Trading profile: declared capital range, trading style, years of experience, brokers used, Indian state.
- Billing data: plan tier (monthly or yearly), access window start and end dates, and payment status events received from our payment processor. Each payment is a one-time order — there is no autopay or stored payment instrument. We never store raw card numbers; payment details are tokenised by our PCI-DSS Level 1 certified payment partner.
- Usage data: page views, feature interactions (anonymised), error logs sent to Sentry.
- Consent records: timestamps of your consent to these Terms, Privacy Policy, and AI processing — stored per DPDP Act 2023 §7.
We do not currently collect PAN numbers. If GST invoicing is introduced in future, this policy will be updated and your consent will be sought before any sensitive personal data (IT Rules 2011, Rule 3) is collected.
3. How we use your data
- Provide the TradeDNA service — analytics, discipline scoring, AI reports.
- AI processing (with your explicit consent): We send anonymised trade data to our AI provider Anthropic (USA) for retrospective behavioural analysis. The data sent is limited to: instrument name, P&L amount, quantity, direction, trade date/time, tags you added, and any journal notes or reflections you wrote. We do not send your name, email, PAN, phone number, or IP address to Anthropic. Data sent to Anthropic is not used to train their models under our enterprise data processing agreement.
- Process payments via our PCI-DSS certified payment partner.
- Send transactional emails — receipts, trial reminders, data exports.
- With your marketing consent: send product updates and feature announcements. You can opt out at any time.
- Detect and prevent fraud, abuse, and security incidents.
4. Legal basis (DPDP Act 2023)
We process your personal data under the following grounds as defined by India's Digital Personal Data Protection Act, 2023:
- Consent (§7)— for AI processing, marketing emails, and anonymised analytics. Consent is collected explicitly at sign-up via individual checkboxes. You may withdraw consent at any time from Settings → Privacy; withdrawal does not affect the lawfulness of processing before withdrawal.
- Legitimate use (§8) — for account management, billing, fraud prevention, and security.
- Compliance with law — for GST obligations, responding to lawful government requests.
Under the IT (Reasonable Security Practices) Rules 2011, we have implemented IS/ISO/IEC 27001-aligned security practices for the protection of your sensitive personal data.
5. Data retention
We retain data only as long as necessary for the stated purpose, or as required by Indian law. The table below sets out our retention schedules:
| Data category | Retention period | Reason |
|---|---|---|
| Account data (email, display name) | Duration of account + 30-day grace | Service delivery |
| Trade data | Duration of account + 30-day grace | Core feature |
| Billing & payment records | 7 years from transaction date | IT Act 2000 §43A; financial record-keeping |
| Consent records (timestamps) | Duration of account + 3 years | DPDP Act 2023 audit trail |
| Error logs (Sentry) | 90 days | Debugging; auto-purged by Sentry |
| Analytics data (anonymised) | 2 years | Product improvement; no PII |
Upon account deletion, your account enters a 30-day grace period during which all access is suspended but data is not yet purged (to allow accidental-deletion recovery). After 30 days, all personal data is permanently deleted from our live systems. Billing records subject to statutory retention are archived in an encrypted, access-controlled vault and deleted when the statutory period expires.
6. Cross-border data transfers
Some of your data is processed outside India. We disclose these transfers and the safeguards in place:
- Anthropic (USA) — receives anonymised trade data for AI analysis (see §3 for the exact fields). Transfer is governed by a Data Processing Agreement with contractual protections equivalent to applicable Indian law. Anthropic does not use your data for model training.
- Vercel (USA/Global) — hosts our application and processes HTTP requests globally for performance. No persistent trade data is stored outside India; Supabase (primary database) is hosted in the Mumbai region.
- Sentry (USA) — receives anonymised error logs. Error payloads are scrubbed of trade amounts, instrument names, and all PII before transmission.
You consented to the Anthropic transfer at sign-up. You may revoke this consent at any time from Settings → Privacy, which will disable all AI features.
7. Your rights (DPDP Act 2023)
- Right to access— Download all your personal data from Settings → Privacy → Download your data. You can also view and export your complete transaction history (payments, credit grants, and AI feature usage) at any time from Billing → Transactions.
- Right to correction — Update your profile details at any time from Settings.
- Right to erasure— Delete your account from Settings → Privacy. Data is purged after the 30-day grace period.
- Right to withdraw consent— Toggle AI, marketing, or analytics consent at any time from Settings → Privacy.
- Right to grievance redressal — Lodge a complaint with our Grievance Officer (see §10). We acknowledge within 48 hours and resolve within 30 days.
- Right to nominate — You may nominate another individual to exercise your rights in the event of your death or incapacity, in accordance with DPDP Act §14.
8. Data security
We implement the following security measures in accordance with the IT (Reasonable Security Practices and Procedures) Rules 2011:
- All data encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Row-Level Security (RLS) enforced at the database layer — no query can access another user's data.
- Authentication managed by Supabase Auth with bcrypt password hashing.
- Payment card and UPI details tokenised by our payment partner; never stored on our servers.
- Access to production data limited to named engineers with MFA enabled.
Breach notification: In the event of a personal data breach that is likely to result in harm, we will notify affected users within 72 hours of becoming aware of the breach, and report to the Data Protection Board of India as required under DPDP Act §8(6).
9. Cookies
- Strictly necessary cookies — Supabase authentication session cookies. These are essential for the service to function and cannot be disabled.
- Optional analytics cookies— Anonymised usage tracking (with your consent). You can accept or reject these via the banner shown on your first visit, and update your preference at any time from Settings → Privacy.
10. Third-party services
- Supabase (auth + database) — Mumbai region, India.Privacy policy
- Anthropic (AI inference) — USA. Enterprise DPA in place; no training on your data.Privacy policy
- Payment processor — India. PCI-DSS Level 1 certified.
- Vercel (hosting) — global edge, primary region India.Privacy policy
- Sentry (error tracking) — USA. Anonymised payloads only.Privacy policy
- PostHog(product analytics & session recording) — EU region (
eu.i.posthog.com). We use PostHog to understand which features are used and where users encounter difficulty. PostHog processes pseudonymous behavioural data only (page views, button clicks, feature usage counts); it does not receive your trade data, P&L figures, or AI conversation content. User identification uses your account UUID only — never your name or email. You can disable analytics tracking at any time via Settings → Privacy → Anonymized Analytics Consent.Privacy policy
11. Grievance Officer & Data Protection Officer
In accordance with the Digital Personal Data Protection Act 2023, the Information Technology Act 2000 §43A, the IT (Reasonable Security Practices) Rules 2011, and the Consumer Protection (E-Commerce) Rules 2020, we have appointed a Grievance Officer:
Grievance Officer / Data Protection Officer
TradeDNA
Vijayawada, Andhra Pradesh – 520012, India
Email: privacy@tradedna.in
We will acknowledge your complaint within 48 hours and resolve it within 30 days of receipt. If you are not satisfied with our resolution, you may escalate to the Data Protection Board of India once it is established under the DPDP Act.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email and/or a prominent in-app notice at least 7 days before taking effect. Continued use of TradeDNA after the effective date constitutes acceptance of the updated policy.