Privacy Policy
Last Updated: July 24, 2026
1. Overview & Single Purpose
TradeGuard ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, handle, store, and safeguard your information when you use the TradeGuard browser extension and our associated web application (https://droptrades.dev).
TradeGuard operates as an automated "tilt firewall" designed exclusively to enforce trader risk management controls and protect futures traders from exceeding pre-configured loss limits on supported trading broker platforms (Tradovate and NinjaTrader). We process user data strictly for the single purpose of providing, operating, maintaining, and securing the TradeGuard risk management service.
2. User Data Collection & Host Permissions
We collect only the minimum data strictly necessary to provide our risk management service:
- Account & Login Credentials: When you register or log in to TradeGuard via the browser extension popup or web application, we collect your email address and account password. Your password is submitted securely over an encrypted HTTPS connection for user authentication.
- Broker Session Tokens: We collect temporary authentication and session tokens from your trading broker platform (e.g., Tradovate / NinjaTrader) to allow our backend engine to execute automated position liquidation ("flatten-all") orders when your pre-set risk limits are breached.
- Real-Time Trading Metrics: We monitor real-time PnL, account balance metrics, open position counts, and order activity on supported broker platforms strictly to evaluate your configured risk rules.
- Host & Website Access (Extension Host Permissions): The TradeGuard browser extension requests permissions restricted to supported broker domains (
*://trader.tradovate.com/*,*://web.ninjatrader.com/*, and*://droptrades.dev/*). Content scripts run strictly to identify active trading tabs and inject the risk monitoring script on supported broker portals. TradeGuard does NOT collect, read, track, or store browsing history, web content, or user data on any non-broker websites. - Technical & Diagnostic Logs: We collect minimal operational metrics (e.g., connection status, extension version, API response latency) to maintain software stability, troubleshoot errors, and prevent software bypass attempts.
3. User Data Handling & Usage
We handle and use your data strictly for the single purpose of operating TradeGuard:
- User Authentication: Login credentials (email address and password) submitted via HTTPS are processed by our backend authentication service to verify user identity, issue authorized session tokens, and grant secure access to the TradeGuard service.
- Risk Rule Enforcement: Real-time trading data (PnL and position state) is evaluated against your pre-configured daily loss or trailing drawdown limits.
- Automated Order Execution: Ephemeral broker session tokens are used exclusively to submit market order cancellations and position liquidations when your risk limits are breached.
- Security & Bypass Prevention: Technical diagnostic logs are processed to detect connection failures and prevent unauthorized bypass of active lockout timers.
4. User Data Storage, Retention & Security
- Password Security & Hashing: Account passwords submitted during login are transmitted using modern TLS 1.3 / HTTPS encryption. Passwords are salted and password-hashed (using standard bcrypt algorithms) before storage in our encrypted database. We never store plaintext passwords.
- Broker Passwords: We do NOT request, collect, or store your third-party broker account passwords.
- Temporary Token Storage: Broker session tokens and real-time trading statistics are processed temporarily in-memory. Ephemeral session tokens are automatically purged upon token expiration or user logout.
- Log & Data Retention: Technical diagnostic logs are retained temporarily for system maintenance and automatically deleted within 30 days. Account information is retained for active registered accounts.
- Browser Local Storage & Cookies: The browser extension uses
chrome.storage.localand browser local storage strictly for retaining authenticated session states and user display preferences.
5. User Data Sharing & Disclosure
We maintain strict confidentiality over user data:
- No Sale or Commercial Transfer: We do NOT sell, rent, trade, lease, or transfer user personal information, account credentials, passwords, trading data, or browsing activity to any third parties, advertisers, data brokers, or marketing networks.
- No Credit Evaluation or Lending: We do NOT use, share, or transfer user data to evaluate creditworthiness or for lending purposes.
- Broker Communication: Data (session tokens) is transmitted directly to your broker's official API strictly to perform authorized risk enforcement actions (e.g., closing positions).
- Essential Service Providers: Data is processed through secure, trusted cloud infrastructure providers (e.g., Render, Vercel, Supabase) operating under strict confidentiality and data protection agreements.
6. Chrome Web Store Developer Program Disclosures & Limited Use Clause
In full compliance with the Chrome Web Store Developer Program Policies:
- Chrome Web Store Limited Use Statement: TradeGuard's use and transfer of information received from Chrome APIs to any other app will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
- User passwords collected during login are disclosed clearly herein and are processed solely for authenticating the user into TradeGuard.
- User data is not used or transferred for purposes unrelated to TradeGuard's single purpose of trader risk management enforcement.
- User data is not used or transferred to determine creditworthiness or for lending purposes.
- User data is never sold to third parties or data brokers.
7. User Data Rights & Account Deletion
You have complete control over your data:
- Access & Correction: You may view and update your profile information and risk settings at any time through the TradeGuard web dashboard (https://droptrades.dev).
- Account & Data Deletion: You have the right to delete your account and request complete erasure of all your personal data. You may request account deletion at any time by emailing support@droptrades.dev or through the account settings on https://droptrades.dev. Upon receiving your request, all personal data, saved rules, and account credentials will be permanently erased from our active databases within 30 days.
8. Children's Privacy
TradeGuard is intended exclusively for adult traders. We do not knowingly collect or solicit personal information from individuals under 18 years of age.
9. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in software functionality, legal requirements, or Chrome Web Store policies. The updated policy will be posted on our website at https://droptrades.dev/privacy with a revised "Last Updated" date.
10. Contact Us
If you have questions, concerns, or data deletion requests regarding this Privacy Policy or our privacy practices, please contact us at:
- Email: support@droptrades.dev
- Website: https://droptrades.dev/privacy