This Privacy Policy explains what personal data SOFTSHORE TECHNOLOGY LTD ("chartTrigger", "we", "us"), of 128 City Road, London, United Kingdom, EC1V 2NX, collects when you visit charttrigger.com or use the chartTrigger application, why we collect it, and the choices you have about it. It should be read alongside our Terms of Service.
1. Who we are
We are the data controller for the personal data described in this policy. If you are in the UK or the European Economic Area, UK GDPR and, where applicable, the EU GDPR govern how we may use your data; we describe our legal basis for each use in Section 5.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account details | Email address, name, password (stored as a salted hash, never in plain text), time zone | You, at signup |
| Billing records | Plan chosen, amounts and dates you tell us you paid, payment references, broker-partner claim details | You, and an operator confirming the record |
| Rule and trading configuration | Your rules, cohorts, alert destinations, and the values your rules evaluate against | You, and the broker terminal on your behalf |
| Activity and support data | Sign-in history and approximate location by IP, audit log entries, contact-form and enquiry messages | You, automatically as you use the Service |
| Technical data | IP address, browser type, pages viewed, theme preference | Automatically, from your browser and our servers |
We do not collect government ID numbers, payment card numbers, or bank account details — payments are declared by you and confirmed by an operator against records you send us directly, outside the Service.
3. Your broker credentials
Connecting a berth means giving us the login and password for a MetaTrader 5 account. That password is encrypted at rest and is only ever decrypted in memory to authenticate the terminal we run on your behalf; it is never included in exports, logs, or support responses. We do not have or request access to any separate withdrawal password, wallet, or payment method your broker may use.
4. How we use it
- to create and secure your account, and to authenticate you;
- to run the Service: evaluate your rules, operate your berths, record Provenance and audit history, and deliver alerts to destinations you confirm;
- to administer billing: track subscription periods, review declared payments and broker-partner claims;
- to respond to messages you send through the contact form or the exit-intent offer;
- to send account-essential email — verification links, password resets, access-granted and expiry notices;
- to investigate misuse, enforce our Terms, and meet legal obligations; and
- to keep the Service secure, including rate-limiting sign-in attempts and keeping an audit trail of account actions.
We do not use your data to train third-party advertising profiles, and we do not sell personal data.
5. Our legal basis for using it
Where UK/EU data protection law applies, we rely on:
- Contract — processing needed to provide the Service you signed up for (running your rules, billing, alerts);
- Legitimate interests — securing the Service, preventing fraud and abuse, and improving what we offer, balanced against your rights; and
- Consent — where we ask for it specifically, such as an optional marketing message; you can withdraw it at any time.
6. Who we share it with
We do not sell personal data. We share it only with:
- Delivery providers you choose — the email, Telegram, SMS or webhook transport we operate sends alerts and confirmations to the destination you register, which necessarily passes your message content to that provider (e.g. Telegram's servers for a Telegram alert);
- Infrastructure providers — hosting and, where used, transactional email delivery, acting on our instructions under their own confidentiality and security terms;
- Partner brokers, only the account number and deposit details needed to verify a broker-partner access claim you submitted, and only to that specific broker;
- Professional advisers and authorities, where needed to obtain advice or to comply with a legal obligation, court order, or valid regulatory request; and
- A successor, if we reorganise, merge, or sell the business, subject to the same protections described here.
7. Cookies and local storage
Full detail is in our Cookie Policy. In summary: the public site
uses only first-party localStorage for your theme choice and to avoid repeating the
exit-intent offer, with no third-party trackers or advertising pixels. The application sets one
strictly-necessary, first-party, HTTP-only session cookie so you stay signed in; it carries no tracking
identifier and is not shared with any third party.
8. How long we keep it
We keep account and rule data for as long as your account is active, and for a limited period afterwards to meet accounting, tax, fraud-prevention and legal obligations, and to resolve any dispute about billing or account activity. Audit and financial records are generally kept longer than operational data such as chart preferences, because we are required to be able to show what happened to a payment or an order. If you ask us to delete your account, we remove what we can straight away and retain only what the law or a legitimate dispute requires, for no longer than necessary.
9. How we protect it
Broker passwords and other secrets are encrypted at rest. Account passwords are hashed, never stored in plain text. Sign-in attempts are rate-limited per account and per address, with automatic lockout after repeated failures. Sessions are tracked server-side, can be listed and revoked by you at any time, and are automatically invalidated when you change your password. Administrator access to a customer's own account view is itself logged, naming both the customer and the administrator. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
10. International transfers
We and the infrastructure and delivery providers we use may process data outside your own country, including outside the UK or EEA. Where that happens, we rely on appropriate safeguards, such as standard contractual clauses or a provider's own adequacy certifications, to protect your data to a standard consistent with this policy.
11. Your rights
Subject to applicable law, you may ask us to:
- confirm what personal data we hold about you and provide a copy of it;
- correct data that is inaccurate or incomplete;
- delete your data, subject to the retention needs described in Section 8;
- restrict or object to certain processing, including processing based on legitimate interests; and
- receive certain data in a portable format.
You can manage your alert destinations, sessions and profile directly from the app, or contact us using Section 14. If you are in the UK, you also have the right to complain to the Information Commissioner's Office.
12. Children
The Service is not directed at, and must not be used by, anyone under 18. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this policy from time to time. We will post the revised version here with a new "Last updated" date, and for material changes we will make reasonable efforts to notify account holders directly.
14. Contact
To exercise a privacy right or ask a question about this policy, use the contact form, choosing "Something else" and mentioning privacy in your message.
Prefer email? Write to us at write to us directly.