LEGAL

Privacy policy

1. Scope

This policy applies to the TradeSidecar website, Google sign-in, Waffo Pancake subscription checkout and billing portal flows, customer support, and the TradeSidecar Chrome extension. It does not replace the privacy policies of Google, Waffo Pancake, TopstepX, TradingView or any other third-party service.

2. Information we collect

Website and support

You can browse the site without an account. If you contact us, we receive the email address and message you choose to send. Basic server security logs may include an IP address, request time, user agent and requested path.

Account and authentication

When you create an account with email, our server stores the normalized email, a scrypt password hash, email verification and password reset action metadata. Verification and reset tokens are stored only as one-way hashes and expire. When you sign in with Google, our server receives Google's stable account subject identifier, verified email address, and the profile name or picture made available by Google. We do not receive or store your Google password.

Subscription and billing

For a Pro subscription, we store the account and subscription information needed to verify access: selected plan, provider customer and subscription identifiers, status, billing period, renewal or cancellation state, and entitlement dates. Waffo Pancake processes payment details as Merchant of Record; TradeSidecar does not collect or store your card number.

3. What the extension reads

TradeSidecar reads only the active supported page state needed for enabled features. This can include the active contract and favorite-contract list, chart symbol and timeframe, chart OHLC data exported by the active TradingView chart, and the account, position and order state needed to display or perform a requested action.

The current extension reuses state and API clients already loaded by the supported page. It does not create a separate market-data connection, request additional history, or independently read and store a platform authentication token.

4. What the extension does not collect

The current build does not ask for or store your platform password, Google password, payment-card number, unrelated browser history, or unrelated website content. It does not send chart or order data to an AI provider. AI Market Context is not active in the current build.

5. Local browser storage

The extension stores preferences such as panel position, module folds, quantities, drawing-hotkey mappings, indicator settings and automatic-assistance settings in Chrome extension storage. Preference backups are user-initiated files. They do not include credentials, account records, orders, positions or automatic-run state.

6. Product account and indicator requests

The TradeSidecar account service stores website sessions, extension device-pairing records, entitlement state and (when you submit one) a TradingView source URL, note and request status. A public indicator listing contains release metadata for code already shipped in the extension; it is not a remote script repository. We do not upload trading-page data, trade logs or replay files as part of these account and market features.

7. How we use information

8. Service providers and sharing

We share information only as needed to provide the service, process a requested transaction, protect the service, or comply with law.

We do not sell personal information. We do not use an advertising network or AI provider for the extension. Google Analytics is limited to the public website and is not embedded in the TradeSidecar extension.

9. Analytics and telemetry

Public marketing pages use Google Analytics 4 to measure page views and selected calls to action. Google may receive the requested public path, referrer, browser and device information, coarse location derived from the connection, and an analytics identifier. We disable Google Signals and advertising-personalization signals, honor browser Global Privacy Control and Do Not Track signals, and do not load analytics on private account or credential-flow pages. The extension does not send chart, order, position, account, email or payment data as analytics telemetry.

10. AI data

AI Market Context is Coming Soon and is not active. No chart, order, position or account data is currently sent to an AI provider. Before enabling an AI feature, we will describe the provider, data fields, purpose, retention, training use and opt-out controls in this policy and in the product.

11. Retention

We retain account and subscription records for as long as needed to provide access, support billing, reconcile provider events, prevent fraud and meet legal or accounting obligations. Support correspondence is retained for the period needed to resolve the request and maintain service records. Local extension preferences remain in Chrome until you remove them or uninstall the extension.

12. Cookies and sessions

The website uses an HttpOnly tsc_session_v2 server session cookie to keep you signed in and a short-lived OAuth state cookie to protect the Google sign-in flow. The extension stores its opaque device session in extension IndexedDB and uses it only for entitlement checks. Session cookies are Secure when served over HTTPS and SameSite=Lax. We do not use cookies for advertising.

13. Security

We use access controls, signed session tokens, HTTPS, server-side entitlement checks, hosted payment processing and signed webhook verification appropriate to the service. No internet service can guarantee absolute security. Never send a password, token or card number to support.

14. International transfers

Our service providers may process information in countries other than where you live. Where required, we use appropriate contractual or legal safeguards and provide the rights required by applicable law.

15. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, restrict or object to processing of your personal information, and to receive a portable copy. You may also withdraw consent where processing relies on consent. We may need to verify your request and retain information required by law or legitimate billing and fraud-prevention needs.

16. Account deletion requests

To request access or deletion, email support@tradesidecar.com from the account address and describe the request. Deleting an account may end access, and provider or accounting records may need to be retained for the period required by law.

17. Children

The service is intended for adults who are permitted to use the relevant trading platform. We do not knowingly collect personal information from children. Contact us if you believe a child has submitted information.

18. Changes to this policy

We may update this policy when the service, providers or legal requirements change. The updated date above identifies the current version. Material changes will be highlighted in the service where appropriate.

19. Contact

For privacy requests, account questions, billing support or refunds, contact support@tradesidecar.com. For general inquiries and partnerships, contact hello@tradesidecar.com.