← RERO TradeLink
Legal

Privacy Policy

Effective 19 September 2026

Core privacy principle: trading capital remains with the user's broker. TradeLink may process broker telemetry and connection secrets where necessary to provide the service, but it does not require withdrawal authority.

Data we may collect

Account and identity data, contact/support data, subscription and invoice information, broker connection metadata, trading telemetry, risk and analytics data, journal content, verification-profile fields, IP/browser/device information, security logs and audit records.

Broker credentials and connection secrets

Some integrations may require passwords, API tokens, OAuth credentials, refresh tokens or server identifiers. TradeLink should request only the access required for the selected mode, use read-only or scoped permissions where supported, encrypt sensitive secrets at rest and prefer renewable tokens over retained plaintext passwords where possible.

How we use data

We use personal data to operate accounts and workspaces, maintain authorised broker connections, provide monitoring, analytics, journal, verification and Protect features, deliver alerts, support users, manage subscriptions, prevent fraud and abuse, maintain audit records and comply with legal obligations.

TradeLink Protect and automated processing

Where enabled and authorised, Protect may automatically compare broker telemetry with thresholds chosen by the account holder and issue warnings or pre-authorised defensive controls. These controls implement prior user instructions rather than discretionary investment decisions.

TradeLink Verify

If you enable a public or shareable verification profile, approved performance and verification fields may be visible to anyone with the link. Passwords, authentication tokens and full account numbers should never be displayed publicly.

Cookies

Necessary cookies or local storage may be used for authentication, security, preferences and core platform functions. Optional analytics or marketing technologies should only be deployed in accordance with applicable consent requirements.

Sharing

Data may be shared where reasonably necessary with cloud, database, observability, email, security, broker/platform, connectivity and payment providers, professional advisers, regulators or authorities, and with a purchaser or successor in a genuine corporate transaction subject to appropriate safeguards.

International transfers

Where UK GDPR applies and data is transferred internationally, recognised safeguards should be used where required, such as adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses.

Retention and security

Data is retained only as long as reasonably necessary for service delivery, security, audit, legal, tax/accounting and dispute-resolution purposes. TradeLink is designed to use TLS, encryption of sensitive secrets at rest, least-privilege access, audit logging, monitoring and key separation.

Your rights

Where UK GDPR applies, you may have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, plus the right to complain to the Information Commissioner's Office or another competent supervisory authority.

Children

TradeLink is intended for adults. Users must be at least 18 years old to create an account.

Privacy questions and rights requests: privacy@rerotradelink.com. The legal entity and registered address acting as data controller must be inserted before paid-service launch.