Legal · Effective 2026

Privacy Policy

Last updated: 2026. This policy describes what personal data Lipsius Trading (“we”, “us”) collects when you use the Service, how we use it, and the rights you have under the GDPR.

1 · Data We Collect

  • Account data: email address, display name, hashed password.
  • Subscription data: plan, status, billing cycle (processed by Stripe).
  • Usage data: pages visited, feature interactions, IP address, user-agent — used for security, anti-abuse and product analytics.
  • Support data: messages you send via the contact form.
  • Trading journal: entries you voluntarily store in the Journal section.

2 · How We Use Data

  • To provide and secure the Service.
  • To process payments via Stripe.
  • To respond to support requests.
  • To detect scraping, abuse and Terms of Service violations.
  • To send transactional emails (password reset, billing notices).

3 · Legal Basis (GDPR)

We process your data based on the contract you enter when creating an account (Art. 6(1)(b) GDPR), our legitimate interest in operating and protecting the Service (Art. 6(1)(f) GDPR), and your consent where applicable (Art. 6(1)(a) GDPR).

4 · Sub-processors

  • Supabase — authentication and database hosting (EU region).
  • Stripe — payment processing.
  • Cloudflare — edge runtime and DDoS protection.
  • Resend / transactional email provider — outbound email.

5 · Retention

Account and journal data is retained for as long as your account is active. After deletion, we keep minimal records required for tax and anti-fraud purposes for up to 7 years.

6 · Your Rights

You have the right to access, rectify, delete, or export your personal data, and to object to processing. Requests can be sent to info@lipsius-trading.nl. You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens.

7 · Cookies

We use strictly necessary cookies for authentication and language preferences. We do not use third-party advertising cookies.

8 · Security

Passwords are hashed; data is encrypted in transit (TLS) and at rest. Access to production systems is restricted and logged.

9 · Contact

Data controller: Lipsius Trading · KVK 97095001 · info@lipsius-trading.nl.