Privacy Policy

Last updated: December 11, 2025

At TradeKhata (operated by Shilpakar Tech LLP, GST: 27AFJFS1790R1Z1), we take your privacy seriously. This Privacy Policy explains how we collect, use, protect, and handle your personal information when you use our Service.

1. Information We Collect

1.1 Account Information

  • Email address
  • Name
  • Phone number (for invoicing)
  • Password (encrypted, never stored in plain text)

1.2 Trading Data (via OAuth or CSV Upload)

  • Trade history from connected brokers
  • Symbol, quantity, entry/exit prices, P&L
  • Timestamps, order IDs
  • Broker account identifiers (encrypted)

1.3 User-Generated Content

  • Emotion tags you create and apply
  • Strategy tags
  • Notes on trades
  • Screenshots uploaded

1.4 Payment Information

  • Payment details processed by Razorpay (we never see your card numbers)
  • Transaction IDs, payment status
  • GST information for invoicing

1.5 Usage Data

  • Pages visited, features used
  • Device information, browser type
  • IP address, general location (city/country level)
  • Analytics via Mixpanel (anonymized)

2. How We Use Your Information

We use your data to:

  • Provide the Service: Import, store, analyze, and display your trading data
  • Improve the Service: Understand usage patterns, fix bugs, add features
  • Communicate with you: Account updates, important notices, support responses
  • Process payments: Handle subscriptions, generate invoices
  • Ensure security: Prevent fraud, unauthorized access
  • Comply with law: Tax reporting (GST), legal requirements

We do NOT:

  • ❌ Sell your data to third parties
  • ❌ Share your trading data with anyone without your consent
  • ❌ Use your data for advertising or marketing to third parties
  • ❌ Execute trades or access your broker funds

3. Data Storage & Security

3.1 Where We Store Data

  • Hosting: Digital Ocean (servers in India)
  • Database: PostgreSQL (encrypted at rest)
  • File Storage: Cloudflare R2 (screenshots, exports)

3.2 Security Measures

  • HTTPS/TLS encryption for all data transmission
  • OAuth tokens encrypted using Rails encrypted attributes
  • Passwords hashed with bcrypt (never stored in plain text)
  • Regular security updates and patches
  • Access controls and audit logging

3.3 Data Retention

  • Active accounts: Data retained indefinitely
  • Cancelled accounts: Data retained for 90 days, then permanently deleted
  • Payment records: Retained for 7 years (Indian tax law requirement)

4. Data Sharing

We share data only with:

Service Providers

  • Razorpay: Payment processing
  • Postmark: Transactional emails
  • Sentry: Error tracking (anonymized)
  • Mixpanel: Analytics (anonymized)

Legal Requirements

We may disclose your information if required by law, court order, or government request (e.g., tax authorities, law enforcement).

Business Transfers

If TradeKhata is acquired or merged, your data may be transferred to the new entity (you'll be notified 30 days in advance).

5. Your Rights (GDPR & Indian Data Protection)

You have the right to:

  • Access: Request a copy of all data we hold about you
  • Correct: Update inaccurate or incomplete information
  • Delete: Request account deletion (data removed within 30 days)
  • Export: Download your data in CSV format anytime
  • Object: Opt out of non-essential communications
  • Restrict: Limit how we process your data

To exercise these rights, email us at hello@usetradekhata.com. We'll respond within 30 days.

6. Cookies & Tracking

We use cookies and similar technologies to:

  • Essential cookies: Keep you logged in, remember preferences
  • Analytics cookies: Understand how you use TradeKhata (via Mixpanel)
  • No advertising cookies: We don't track you for ads

You can disable cookies in your browser, but some features may not work properly.

7. Third-Party Links

TradeKhata may contain links to third-party websites (e.g., broker sites). We are not responsible for their privacy practices. Always review their privacy policies.

8. Children's Privacy

TradeKhata is not intended for users under 18 years of age. We do not knowingly collect data from children. If you believe we have inadvertently collected such data, contact us immediately for deletion.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email 30 days in advance. Continued use of the Service after changes constitutes acceptance.

10. Contact Us

For privacy-related questions or requests:

Email: hello@usetradekhata.com

Company: Shilpakar Tech LLP

GST: 27AFJFS1790R1Z1

Website: usetradekhata.com