Privacy Policy
Last updated: 29 June 2026
Who we are
TraderM8 (“TraderM8”, “we”, “us”, “our”) is a trading dashboard, journal, and backtesting tool available at traderm8.com, operated by Banjo Tomlinson, a sole trader registered in Australia (ABN 95 107 325 700) and based on the Gold Coast, Queensland.
TraderM8 is an independent venture and is not owned by, operated by, or affiliated with any other business. You can reach us about privacy or data matters using the contact details provided in this policy.
This policy explains what we collect, why we collect it, who we share it with, and the rights you have over your personal data. As an Australian business, we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). The service is available worldwide, and we extend equivalent protections to users elsewhere, including the EU/EEA, the UK, California, and Canada.
Information we collect
We collect personal information only where it is reasonably necessary for our functions and activities, and wherever practical we collect it directly from you. This includes:
- Account & identity: your name, email address, and password (your password is hashed by our authentication provider, Supabase, and is never visible to us), your date of birth (used only for age verification), your timezone, and an optional avatar image.
- Content you create: trades, journal entries and any images you upload, trade plans, backtest sessions, settings, feedback, and the messages you send to our AI features.
- Billing data: your subscription status, plan tier, and the Stripe customer and subscription identifiers tied to your account. Full card numbers are handled directly by Stripe and are never stored on our servers.
- Usage & device data: your IP address, browser and device type, the pages and features you use, and approximate time on site and activity. We collect this through PostHog, Vercel Analytics, and our own activity log.
- Notification tokens: a push token, but only if you choose to enable browser push notifications.
- Cookies and similar technologies: see our Cookie Policy for the cookies and analytics we use.
We do not generally collect “sensitive information” as that term is defined in the Privacy Act (such as health, biometric, or racial information). Your financial and trading data is private to you, but it is not “sensitive information” under that definition.
How we use your information & our legal bases
As an Australian business, we use and disclose your personal information only for the purpose we collected it, for a directly related purpose you would reasonably expect, or where you have consented or the law permits or requires it. Where the EU/UK GDPR applies, we also rely on the legal bases noted in parentheses below.
- Provide and operate the service and sync your data across your devices (performance of a contract).
- Keep accounts and data secure and prevent fraud and abuse (legitimate interests; legal obligation).
- Process payments and manage subscriptions (contract).
- Understand and improve the product through analytics (legitimate interests, or consent where required).
- Send you service messages and, where you have opted in, marketing emails (consent/contract).
- Comply with the law and resolve disputes (legal obligation).
We only send marketing emails where you have opted in, and every marketing email includes a way to opt out. You can unsubscribe at any time using the link in the email or by contacting us at the address below, and we will stop sending them. Service messages you need to run your account (for example billing and security notices) are not marketing and may still be sent.
AI features
When you use AI tools such as the AI Coach, the messages and the context needed to answer them are sent to our AI provider, Anthropic, so it can generate a response.
When you use the AI Position Calculator, the chart image and details you provide are sent to OpenRouter, which routes the request to the underlying model (Google's Gemini), so it can read the chart and return a result.
We do not permit your content to be used to train third-party models beyond what is needed to answer your request.
Who we share it with (service providers)
We use a small set of trusted service providers (sub-processors) to run TraderM8. Each processes data only to deliver its service to us:
- Supabase: authentication and database.
- Vercel: hosting and Vercel Analytics.
- Stripe: payment processing.
- PostHog: product analytics.
- Anthropic: AI Coach responses.
- OpenRouter:routing for the AI Position Calculator (which uses Google's Gemini model).
- Resend: transactional and opt-in emails.
- Google: only if you choose Google sign-in.
Market-data providers (such as Finnhub and Financial Juice) supply market information to us and do not receive your personal data.
We may also share information where required by law or to protect rights and safety, and in connection with a business transfer such as a merger or acquisition, under the same protections described in this policy.
Where your data is stored & overseas transfers
Your account and the content you create (trades, journal entries, plans, backtests, and settings) are stored in our primary database, hosted by Supabase on managed cloud infrastructure in Singapore (the ap-southeast-1 region).
Because this database is located in Singapore, your personal information is stored outside Australia. We rely on Supabase's security controls and contractual commitments to keep it protected to a standard consistent with the Australian Privacy Principles.
Some of our service providers operate overseas and will store or process limited personal data outside Australia. These include payments with Stripe, hosting and analytics with Vercel and PostHog, AI responses with Anthropic and OpenRouter, and email with Resend, which run primarily from the United States.
Before we disclose personal information to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles (APP 8), including relying on each provider's contractual commitments, such as Standard Contractual Clauses where applicable. By using TraderM8 you acknowledge that your personal information may be stored and processed outside Australia.
How long we keep it (retention)
We keep your data while your account is active and for as long as needed to provide the service. After you delete your account, we delete or anonymise your personal data within a reasonable period, except where we are required to retain certain records (for example billing and tax records, or to comply with the law).
Your privacy rights
Wherever you are, you have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data.
- Export your data (portability).
- Object to or restrict certain processing.
- Withdraw consent at any time.
Depending on where you live, you may have additional rights:
- EU/EEA & UK (GDPR / UK GDPR):all of the above, plus the right to lodge a complaint with your local supervisory authority (for the UK, the Information Commissioner's Office, the ICO).
- California (CCPA/CPRA): the right to know and access, delete, and correct your personal information; to opt out of the sale or sharing of personal information (we do neither); to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.
- Canada (PIPEDA): the right to access your information and to challenge its accuracy.
- Australia (Privacy Act / Australian Privacy Principles): the right to access and correct your information, to deal with us anonymously or by pseudonym where it is lawful and practical, and to complain about how we handle your personal information. Contact us first at the address below; if you are not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
To exercise any right, email traderm8.business@gmail.com. We may need to verify your identity, and we respond within the timeframe required by applicable law.
How we protect your data (security)
Every user's rows are isolated by database row-level security, so only your authenticated account can read them. Data is encrypted in transit using HTTPS, and your password is hashed by Supabase.
That said, no method of transmission over the internet or method of electronic storage is completely secure, so we cannot guarantee absolute security.
Notifiable Data Breaches scheme
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth).
If we become aware of a data breach involving your personal information that is likely to result in serious harm, and we are unable to prevent that harm through remedial action, we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable. Our notification will describe the breach, the kinds of information involved, and the steps you can take in response.
If you believe your account or your data has been compromised, please tell us straight away at traderm8.business@gmail.com so we can investigate and respond.
Children & age
If you believe a child under 16 has provided us with personal data, please contact us and we will delete it. Signup requires a date of birth, and we take steps to block accounts that do not meet the minimum age. This is our compliance posture for COPPA and other child-data rules.
Cookies
We use cookies and similar technologies to keep you signed in, remember your preferences, and measure how the product is used. For the full detail, see our Cookie Policy at /cookies.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, notify you in-app or by email.
Contact
Questions or requests? Email traderm8.business@gmail.com.
Users in the EU/EEA and the UK may also contact their local supervisory authority.