Privacy Policy
Last updated: 15 July 2026
This Privacy Policy explains what personal data RT TradeJournal ("the Service", "we", "us") collects, why, and the choices and rights you have. We are based in the Netherlands and process personal data in line with the EU General Data Protection Regulation (GDPR).
1. Who we are
The data controller is HarCop VOF, registered at Zuiderlicht 71, 1705 TS Heerhugowaard, Netherlands (Chamber of Commerce / KvK 95694374, VAT NL867244446B01). For any privacy question or to exercise your rights, contact contact@harcop.nl.
Our Data Protection Officer is Albert Coppens, reachable at contact@harcop.nl.
2. The data we collect
Data you give us
- Account & identity — your name, email address, and a securely hashed password (and two-factor authentication settings, if you enable them).
- Sign-in identifiers — if you sign in with Google, we receive your Google account's email, name and identifier. If you enter through Retail Traders single sign-on, we receive the identifier needed to link your membership.
- Trading data — the trading accounts, executions, trades, notes, tags and screenshot uploads you create, and the broker/exchange CSV export files you import. This can include financial information about your positions and results.
- Billing data — if you subscribe, your payment is handled by Stripe; we receive billing details such as name, country, the last four digits and card brand, and invoice records. We never see or store your full card number.
Data we collect automatically
- Technical data — IP address, browser type and essential session data needed to keep you logged in and secure the Service (for example rate-limiting and error logs).
We do not use advertising or analytics trackers, and we do not build marketing profiles.
3. How and why we use your data
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create and run your account and journal; compute your analytics | Performance of our contract with you (Art. 6(1)(b)) |
| Process subscriptions, payments and invoices | Performance of a contract (Art. 6(1)(b)); legal obligation for tax/accounting records (Art. 6(1)(c)) |
| Secure the Service, prevent abuse, diagnose errors, keep backups | Our legitimate interests in a safe, reliable service (Art. 6(1)(f)) |
| Send essential service emails (verification, password resets, billing, important notices) | Performance of a contract (Art. 6(1)(b)) |
| Comply with legal requests and defend legal claims | Legal obligation / legitimate interests (Art. 6(1)(c), (f)) |
4. Cookies
We use only strictly necessary, first-party cookies — to keep you signed in, remember your appearance/sidebar preferences, and protect against cross-site request forgery. Because these are essential to a service you have asked for, no consent banner is required. We set no advertising, analytics or third-party tracking cookies.
5. Who we share it with
We do not sell your personal data. We share it only with the processors that run the Service on our behalf, under contracts that require them to protect it:
| Processor | Purpose | Location |
|---|---|---|
| mijn.host | Hosting, database and backups | Netherlands (EU) |
| Stripe (Stripe Payments Europe, Ltd.) | Subscription payments and invoicing | Ireland (EU), with group entities elsewhere |
| "Sign in with Google" — only if you choose it | EU / United States | |
| mijn.host (SMTP) | Sending essential service emails | Netherlands (EU) |
If you enter through Retail Traders single sign-on, your membership status is exchanged with the Retail Traders platform to grant the corresponding access. We may also disclose data where legally required (for example a valid authority request).
6. International transfers
Your data is stored in the EU. Where a processor (such as Google or a Stripe group entity) processes data outside the European Economic Area, that transfer is covered by an adequacy decision or the European Commission's Standard Contractual Clauses.
7. How long we keep it
- While your account is active — we keep your account and trading data so the journal works. Nothing is deleted just because a membership or subscription lapses.
- When you delete your account — we permanently erase your personal and trading data from the live system.
- Billing records — invoices and payment records are kept for about 7 years to meet Dutch tax and accounting law, then deleted.
- Backups — residual copies in encrypted backups are overwritten on our backup cycle, within 30 days.
8. Your rights
Under the GDPR you can, at any time:
- access the personal data we hold about you, and get a copy;
- correct data that is wrong or incomplete;
- delete your data ("right to be forgotten");
- export your data in a portable format — the Service also gives you self-service JSON/CSV export;
- restrict or object to certain processing; and
- withdraw any consent you have given, without affecting prior processing.
To exercise these, email contact@harcop.nl. You also have the right to complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
9. How we protect your data
Passwords are hashed (argon2), transport is encrypted with TLS, optional two-factor authentication is available, and every record is scoped to its owner so users cannot see each other's data. Access to production systems is limited and logged.
10. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children.
11. Changes to this policy
We may update this policy as the Service evolves. We will change the "last updated" date above and, for material changes, notify you by email or in-app before they take effect.
12. Contact
Questions about this policy or your data: contact@harcop.nl.