Last updated: April 25, 2026

This Privacy Policy describes how MyTradeEdge (“we”, “our”, “the Platform”) collects, uses, and protects your information when you use autotrading.mytradeedge.com and related services.

1. Information We Collect

Account Data

  • Email address, username, and password (password stored as salted SHA-256 hash)
  • Display name and account preferences

Broker Connection Data

When you connect a broker account (Rithmic, DXtrade / TradersLaunch, Tradovate), we receive and store:

  • OAuth access and refresh tokens (Tradovate) — we never see or store your Tradovate password. The Tradovate login happens on Tradovate’s own site; we only receive the token that Tradovate issues to us.
  • API credentials (Rithmic, DXtrade) — username, password, and system/gateway settings you provide. Stored on our VPS database, protected by OS-level file permissions.
  • Account IDs, balances, daily P&L, and position snapshots (read from broker APIs)

Trading Activity

  • Signals sent to the Platform (from TradingView webhooks, Bookmap, or custom sources)
  • Orders placed, fills received, and resulting trades
  • Strategy subscriptions and configuration (quantity, SL/TP settings, risk limits)

Technical Data

  • IP address, user agent, and request logs (stored for 30 days for security and debugging)
  • Session tokens (JWT, 30-day expiry) stored in your browser’s localStorage

2. How We Use Your Data

  • Authenticate you and maintain your session
  • Execute automated trades on your connected broker accounts as you configure
  • Display live P&L, positions, and trade history on your dashboard
  • Send notifications you opt into (fills, locks, daily limits)
  • Improve reliability (aggregated, de-identified error and latency metrics)

3. Where Data Is Stored

All data is stored on a single VPS hosted by Contabo (US-East, Ashburn VA). We run a SQLite database on this server. We do not replicate your data to external clouds, analytics vendors, or third-party data warehouses.

4. Third-Party Sharing

We do not sell, rent, or share your personal data for marketing. We transmit data only to:

  • Your connected brokers (Rithmic, DXtrade / TradersLaunch, Tradovate) — to place orders and fetch account state at your instruction
  • Email/Telegram providers (optional, only if you enable notifications)
  • Law enforcement or regulators when compelled by valid legal process

For Tradovate specifically: we exchange authorization codes for access tokens via Tradovate’s OAuth endpoint. We never transmit your Tradovate password because we never receive it.

5. Security

  • HTTPS (TLS 1.2+) on all web traffic
  • JWT session tokens signed with HMAC-SHA256
  • Broker credentials stored server-side, never sent to the browser after initial setup
  • Root SSH key-only access to the VPS; no password login

No transmission or storage method is 100% secure. We use commercially reasonable safeguards but cannot guarantee absolute security.

6. Your Rights

  • Access — view all data we hold about you via your dashboard
  • Export — request a JSON export of your trades and account data
  • Deletion — request full account deletion at support@mytradeedge.com. We revoke all broker tokens, delete your account record, and purge trade history within 14 days
  • Disconnect brokers — unlink any broker account from your dashboard at any time; this revokes tokens and stops order flow

EU/EEA users have additional rights under GDPR (rectification, restriction, portability).

7. Data Retention

  • Account data: retained while account is active
  • Trade history: retained for 7 years (tax / compliance)
  • OAuth tokens: retained while broker is connected; revoked on disconnect
  • Server logs: 30 days

8. Children

The Platform is not intended for anyone under 18. We do not knowingly collect data from minors.

9. Changes to This Policy

We will post material changes at this URL and notify active users by email at least 30 days before taking effect.

10. Contact

Questions or requests: support@mytradeedge.com