1. Who controls your data
DEALCLUB Limited, registered in England and Wales, is the data controller for personal data collected through DEALFx.
For anything in this notice, including a request to see, export or delete your data, email privacy@dealfx.io.
2. What we collect and why
| What | Why | Lawful basis |
|---|---|---|
| Email and password (stored hashed — we can't read it) |
To create and secure your account | Performance of our contract |
| Broker credentials (encrypted before storage) |
To show your balance and positions, and to place trades you ask for | Performance of our contract |
| Trade journal, settings, auto-pilot sessions | To provide the product and keep your records | Performance of our contract |
| Phone number (optional) | To send SMS alerts you switched on | Consent — withdrawable any time |
| Marketing preference | To send product email if you asked for it | Consent — withdrawable any time |
| Billing records (we never see full card details) |
To take payment and meet tax obligations | Contract, and legal obligation for records |
| Technical data IP address, browser, error logs |
Security, rate limiting, abuse prevention and fixing faults | Legitimate interests — keeping the service safe and working |
| Consent records what you agreed to, when, from which IP |
To prove consent was properly obtained | Legal obligation |
Marketing is separate from service messages. Trade alerts you switch on are part of the product you asked for. Product and marketing email is a separate opt-in you can withdraw at any time from your profile — and withdrawing it removes you from our mailing system, not just from our own database.
3. Who else processes your data
We use a small number of suppliers to run the service. They act on our instructions and may not use your data for their own purposes.
| Provider | What for | What they see |
|---|---|---|
| Netlify | Hosting and serverless functions | Technical data, request logs |
| Neon | Database | Your account and app data, at rest |
| Stripe | Payments and subscriptions | Your email, billing details and card data — held by Stripe, not us |
| SendGrid | Transactional and alert email | Your email address and message content |
| Twilio | SMS alerts (only if you enable them) | Your phone number and message content |
| GoHighLevel | Marketing email (only with your consent) | Your email address and consent record |
| Twelve Data | Market prices | No personal data — price requests only |
| Your broker (IG, or your MetaTrader broker) | Account data and order placement | Whatever your own account holds — governed by their privacy policy |
We do not sell your personal data, and we never will.
We may disclose data if legally required, or to establish or defend legal claims. If our business is ever sold or restructured, data may transfer to the buyer under the same protections.
4. Where your data goes
Some of our suppliers are based outside the UK, mainly in the United States. Where data is transferred out of the UK we rely on the safeguards UK data protection law requires — an adequacy decision where one exists, or standard contractual clauses with the UK addendum.
5. How long we keep it
- Account and app data — while your account is open, then deleted or anonymised within 90 days of closure, unless we must keep it longer.
- Broker credentials — deleted immediately when you disconnect a broker or close your account.
- Billing records — 7 years, because UK tax law requires it.
- Consent records — kept while the consent applies and for a reasonable period after, so we can show it was properly obtained.
- Technical and security logs — typically 90 days.
6. How we protect it
- Passwords are hashed, never stored in a form we could read.
- Broker credentials are encrypted at rest.
- Everything travels over HTTPS.
- Sign-in and password reset are rate limited to frustrate automated attacks.
- Changing your password ends existing sessions on other devices.
- Card details are handled entirely by Stripe and never reach our servers.
No system is perfectly secure. If a breach is likely to put your rights at risk, we will tell you and the ICO as the law requires.
7. Your rights
Under UK data protection law you can:
- See what we hold about you.
- Correct anything inaccurate.
- Delete your data ("right to be forgotten"), subject to records we must keep.
- Export your data in a portable format.
- Object to or restrict how we use it.
- Withdraw consent at any time, for marketing or SMS, without affecting what came before.
Most of this you can do yourself in the app — export and account deletion are both in your profile, and no email to us is required. If you'd rather ask, write to privacy@dealfx.io and we'll respond within one month.
If you're unhappy with how we've handled your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We'd appreciate the chance to put it right first.
8. Cookies and local storage
We don't use advertising or third-party tracking cookies, and there's no consent banner because there's nothing to consent to.
The app stores a few things in your own browser so it works properly:
- Your session token, so you stay logged in.
- Your display settings — chart parameters, selected pairs — which never leave your device.
- A short-lived price cache, so the app doesn't re-request the same data repeatedly.
Clearing your browser data removes all of it and signs you out.
9. Changes to this notice
If we change how we use your data in a way that affects you, we'll update this page and tell you by email or in the app before it takes effect. The date at the top always shows the current version.