Who controls your data
Trading Nomads ("Trading Nomads", "we", "us") operates tradingnomads.store and TN Terminal and is the controller of the personal data described in this policy. You can contact us at tradingnomadsco@gmail.com.
This policy applies to website visitors, account holders, members, email subscribers, and people who contact support.
Information we collect
- Account data: name, email address, Clerk user ID, profile image, authentication and session data, and account preferences.
- Membership and payment data: purchased plan, membership status, renewal date, Stripe customer, subscription and price identifiers, promotions, and transaction records. Stripe, not Trading Nomads, receives your full card details.
- License data: a one-way hash and a masked prefix/suffix of the license key, an encrypted-at-rest copy of the full key (AES-256-GCM) so you can view and copy it again from your account, license and membership status, a SHA-256 fingerprint of the device public key, the public key, key provider (TPM or Windows CNG), Windows platform label, device-binding and validation timestamps, and security-event history.
- Communications: support messages, email-list details, and other information you send us.
- Security and technical data: request and error logs, IP-derived location, browser, device, referrer, pages viewed, and similar operational data.
- Local device data: interface preferences saved in browser local or session storage.
TN Terminal and local data
TN Terminal is local-first. Trading executions, accounts, trades, models, journal entries, notes, attachments, Drive files, drawings, profile images, preferences, and other workspace content are stored in the TN Terminal databank and application storage on your computer.
TN Terminal may create readable files in a local ai folder so tools you choose can work with your data. Those files remain on your computer and are not automatically sent to Trading Nomads or to an AI provider.
TN Service runs locally on 127.0.0.1. Supported platform connectors deliver executions to TN Service through local files or the authenticated loopback interface. TN Service stores its queue and import tables locally, and TN Terminal alone writes accepted trades to the local journal. Trading data, journal data, attachments, and Drive files are not sent to the Trading Nomads Store for this process.
License verification data
TN Service sends only the data required to verify access: the license key, the SHA-256 fingerprint of a device public key, that public key, its TPM or Windows CNG provider, the Windows platform label, and a short-lived challenge ID, nonce, and cryptographic proof signature. The Store returns license status and a signed, time-limited lease.
The raw license key is used to validate the request. The Store keeps it only as a one-way hash and a masked prefix and suffix, plus an encrypted-at-rest copy (AES-256-GCM) so you can view and copy your own key again; the encryption secret is held separately from the database, so a database leak alone does not expose usable keys. The device private key is non-exportable and stays in Windows CNG. We do not collect Windows MachineGuid, hardware serial numbers, the private device key, trading data, journal data, or local files for licensing.
Production license requests use HTTPS and fixed Trading Nomads endpoints. Local HTTP is permitted only for developer builds using localhost. The saved license key, signed offline lease, trusted-time value, and local-session secret are kept in Windows Credential Manager; the local session secret is used only between TN Terminal and TN Service.
Other desktop network requests
TN Terminal downloads public economic-calendar data from a Trading Nomads data endpoint and public COT data from the U.S. Commodity Futures Trading Commission. It also checks the public Trading Nomads GitHub release feed for application updates. These requests do not include your trading, journal, account, or Drive content.
As with ordinary internet requests, the receiving host may process network metadata such as IP address, request time, and user agent. TN Terminal does not upload the local workspace for analytics, cloud storage, or AI processing.
Where the data comes from
Why we use data and our legal bases
- Contract: create and secure accounts, provide TN Terminal access, process billing, manage licenses, and provide support.
- Consent: send optional marketing, process information where consent is specifically requested, and place any non-essential technology that legally requires consent. You may withdraw consent at any time.
- Legitimate interests: secure and troubleshoot the service, prevent fraud and abuse, understand aggregated product usage, improve features, and protect our legal rights, balanced against your rights.
- Legal obligations: keep required tax, accounting, transaction, compliance, and dispute records and respond to lawful requests.
Service providers and recipients
We disclose only the data needed to operate the relevant service:
- Clerk — authentication, accounts, sessions, and connected sign-in providers.
- Stripe — checkout, card processing, invoices, subscriptions, tax and fraud prevention.
- Vercel — website hosting, server logs, and privacy-focused Web Analytics.
- Supabase — the Store database used for account, membership, and license records.
- Resend — requested email-list messages and transactional or support email delivery.
- Google — optional Google sign-in for the email list; we request basic profile and verified email information.
- Upstash — request-rate limiting used to protect Store and license endpoints from abuse.
- GitHub — public TN Terminal release metadata and software downloads.
- U.S. CFTC — public Commitments of Traders datasets requested by TN Terminal.
We may also disclose information when legally required, to protect users or the service, or as part of a merger or sale subject to appropriate protections. We do not sell personal data or share it for cross-context behavioral advertising.
How long we keep data
- Account, membership, and license data is kept while your account is active and afterward only as reasonably needed for support, security, disputes, and legal obligations.
- License challenges expire after two minutes. Expired challenge records are periodically removed; device-binding and license-security events may be retained for fraud prevention, support, and dispute records.
- Email-list data is kept until you unsubscribe or request deletion; we may retain a minimal suppression record so we do not email you again.
- Support, transaction, tax, and consent records are kept for the period reasonably required for the purpose and applicable recordkeeping law.
- Vercel Web Analytics states that its visitor-session identifier is discarded after 24 hours; aggregated statistics may remain longer.
International transfers
Your privacy rights
Depending on where you live, you may ask to access, correct, delete, restrict, or receive a portable copy of your personal data, object to certain processing, withdraw consent, or appeal a denied request. You may unsubscribe from marketing using the link in each message.
Send a request to tradingnomadsco@gmail.com from the email connected to your account. We may verify your identity and may retain data where law permits or requires it. EEA users may complain to their local supervisory authority; in Sweden this is Integritetsskyddsmyndigheten (IMY). California residents may also exercise applicable access, correction, deletion, and opt-out rights without discrimination.