Privacy Policy
Last updated: 5 July 2025
BRWTrades ("we", "us", "our") operates the Ritual platform ("the Service"). This Privacy Policy explains what personal data we collect, why, how we protect it, and your rights under applicable data protection laws worldwide. We are committed to data minimisation — we only collect what is strictly necessary to operate the Service.
This policy applies to all users regardless of location. Where your local law grants additional rights, those are detailed in the jurisdiction-specific sections below.
1. Data Controller
BRWTrades is the data controller for personal data processed through Ritual. We are based in the United Kingdom.
Contact: support@ritualjournaling.co.uk
2. What We Collect
2.1 Account Data
- Email address — used for authentication, account recovery, and essential service communications
- Password — stored only as a cryptographic hash (bcrypt via Supabase Auth); we never store or see your plaintext password
- TOTP secret — encrypted at rest; used for multi-factor authentication
2.2 Trading Data
- Trade records you enter or import (instrument, entry/exit price, size, P&L, notes, setup tags)
- Screenshots you upload
- Account configurations and journal entries
This data belongs entirely to you. We process it solely to display it back to you and generate your personal analytics. We do not analyse, aggregate, or monetise your trading data in any way.
2.3 Technical & Security Data
- IP address — used for rate limiting and brute-force protection; not used for tracking, profiling, or geolocation beyond country-level
- User-agent string — used to generate a human-readable device label (e.g. "Chrome on Windows") for your trusted devices list; not used for fingerprinting
- Authentication attempt counters — per-email/IP, retained for 15 minutes, used solely to enforce lockout after failed attempts
- Trusted device token hash — stored to recognise returning devices without requiring MFA every session
2.4 Payment Data
Payments are processed entirely by Stripe. We receive only: a confirmation that payment succeeded, your subscription status, and the email used at checkout. We never receive, process, or store your card number, CVV, or billing address. Stripe's own privacy policy governs their handling of your payment details.
2.5 What We Do NOT Collect
- No analytics or tracking pixels (no Google Analytics, no Mixpanel, no Meta Pixel)
- No advertising identifiers or cross-site tracking
- No precise geolocation data
- No third-party cookies or tracking cookies of any kind
- No biometric data
- No social media profile data
- We do not sell, rent, share, or disclose your personal information to advertisers, data brokers, or any third party for marketing purposes — ever
3. How We Use Your Data
- To provide and maintain the Service (hosting your journal, generating analytics)
- To authenticate your identity and secure your account
- To process your subscription payments
- To protect the Service from abuse (rate limiting, bot detection)
- To communicate essential service information (security alerts, billing issues, Terms changes)
- To comply with legal obligations
We do not use your data for profiling, automated decision-making, personalised advertising, or any purpose unrelated to delivering the Service to you.
4. Legal Basis for Processing
Depending on your jurisdiction, we rely on the following legal bases:
- Contract performance (UK/EU GDPR Art. 6(1)(b)) — processing account and trading data to deliver the Service you subscribed to
- Legitimate interest (UK/EU GDPR Art. 6(1)(f)) — security measures (rate limiting, brute-force protection, MFA enforcement) to protect your account and our infrastructure
- Legal obligation (UK/EU GDPR Art. 6(1)(c)) — retaining transaction records where required by tax or financial regulations
- Consent — where required by local law for specific processing activities (you may withdraw consent at any time)
For US users: we process data as necessary to perform our contract with you and for our legitimate business interests as described above. For Australian users: we collect and handle personal information in accordance with the Australian Privacy Principles (APPs).
5. Third-Party Processors
We use the following services to operate Ritual. Each acts as a data processor under appropriate contractual safeguards:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase | Authentication & database | Email, hashed password, all stored data | US/EU |
| Vercel | Application hosting & CDN | IP address, request metadata | Global edge |
| Stripe | Payment processing | Email, subscription status | US/EU |
| Cloudflare | Bot protection (Turnstile) | IP address, browser challenge token | Global edge |
| Upstash | Rate limiting (Redis) | IP address (hashed key), request count | US/EU |
| HaveIBeenPwned | Password breach check | First 5 chars of SHA-1 hash only (k-anonymity) | Global CDN |
We do not use any other third-party services. We do not embed social media widgets, advertising networks, or third-party analytics.
6. Cookies
We use only strictly necessary cookies required for the Service to function:
- Supabase session cookies — authenticate your session; httpOnly, secure, SameSite=Lax
- brw_trusted_device — remembers trusted devices for 30 days to skip MFA re-verification; httpOnly, secure, SameSite=Lax
We do not use advertising cookies, analytics cookies, preference cookies, or any third-party tracking cookies. Because we only use strictly necessary cookies, no cookie consent banner is required under UK/EU ePrivacy regulations — but we document them here for transparency.
7. Data Retention
- Account & trading data — retained while your account is active; permanently deleted within 30 days of account deletion
- Authentication attempt logs — automatically purged after 15 minutes
- Trusted device records — expire after 30 days; capped at 10 per user
- Payment/transaction records — retained as required by applicable tax law (typically 6–7 years depending on jurisdiction)
- CSP violation reports — anonymised security telemetry containing no personal data; retained up to 90 days
8. Data Security
We implement the following measures to protect your data:
- Mandatory multi-factor authentication (TOTP) for all accounts
- Content Security Policy (CSP) with strict nonce-based script control
- Row-Level Security (RLS) ensuring users can only access their own data at the database level
- All data encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Rate limiting and brute-force lockout on authentication endpoints
- Password breach checking against known compromised credentials
- CSRF protection via origin verification on all state-changing requests
- Fail-closed architecture — security misconfigurations block access rather than allowing it
9. International Data Transfers
Our infrastructure providers may process data in countries outside your own. We ensure all international transfers are protected by appropriate safeguards:
- UK → US/other: UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs)
- EU → US/other: EU Standard Contractual Clauses (SCCs) or EU-US Data Privacy Framework where applicable
- Australia → overseas: Transfers comply with Australian Privacy Principle 8 — we ensure overseas recipients are bound by enforceable obligations substantially similar to the APPs
We select providers that maintain SOC 2 Type II certification or equivalent security standards.
10. Your Rights
10.1 All Users (Global)
Regardless of where you live, you can:
- Access and export all your data at any time from within the app
- Correct any inaccurate information (edit directly in the app or contact us)
- Delete your account and all associated data
- Contact us with any privacy question or concern
10.2 UK & EU Users (UK GDPR / EU GDPR)
You additionally have the right to:
- Data portability — receive your data in a structured, commonly used, machine-readable format
- Restriction of processing — request we limit processing in certain circumstances
- Object to processing — object to processing based on legitimate interest
- Withdraw consent — where processing is based on consent
- Lodge a complaint — with the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority
10.3 US Users (State Privacy Laws)
If you reside in California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), or another state with comprehensive privacy legislation, you have the right to:
- Know what personal information we collect, use, and disclose
- Delete your personal information
- Opt out of sale or sharing — we do not sell or share your personal information with third parties for cross-context behavioural advertising, so there is nothing to opt out of
- Non-discrimination — we will not discriminate against you for exercising your privacy rights
- Correct inaccurate personal information
California-specific disclosures: In the preceding 12 months, we have collected the categories of personal information described in Section 2 above. We have not sold any personal information. We have not shared personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes other than those permitted under CCPA §1798.121.
To submit a verifiable consumer request, email support@ritualjournaling.co.uk. We will verify your identity by confirming your account email. You may designate an authorised agent to submit requests on your behalf.
10.4 Australian Users (Privacy Act 1988)
Under the Australian Privacy Principles (APPs), you have the right to:
- Access your personal information held by us
- Request correction of inaccurate, out-of-date, or incomplete information
- Complain about a breach of the APPs — we will respond within 30 days
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if unsatisfied with our response
We do not disclose personal information to overseas recipients without appropriate protections as required by APP 8.
10.5 Canadian Users (PIPEDA / Provincial Laws)
Under PIPEDA and applicable provincial privacy legislation, you have the right to:
- Access your personal information and be informed of its use and disclosure
- Challenge the accuracy and completeness of your information and have it amended
- Withdraw consent to the collection, use, or disclosure of your personal information (subject to legal or contractual restrictions)
- Lodge a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca)
11. Do Not Track & Global Privacy Control
We honour Do Not Track (DNT) browser signals and Global Privacy Control (GPC) signals. However, since we do not track users, serve targeted advertising, or share data with third parties for marketing, these signals do not change our behaviour — we already operate in the most privacy-protective mode by default.
12. Children
The Service is not directed at anyone under 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal data from minors. If we learn that a user is under the applicable age threshold, we will delete their account and data promptly. If you believe a minor has provided us with personal information, contact us immediately.
13. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights, we will:
- Notify affected users without undue delay (and within 72 hours where required by UK/EU GDPR)
- Notify the relevant supervisory authority as required by law
- Provide clear information about what happened, what data was affected, and what steps to take
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email or an in-app notice at least 30 days before they take effect. The "Last updated" date at the top indicates the most recent revision. Continued use after the effective date constitutes acceptance; if you disagree, you may delete your account before the changes take effect.
15. Contact
For privacy-related questions, data access/deletion requests, or concerns:
Email: support@ritualjournaling.co.uk
Response time: Within 30 days (or sooner where required by local law)
If you are not satisfied with our response, you may escalate to your local data protection authority:
- UK: Information Commissioner's Office — ico.org.uk
- EU: Your local supervisory authority
- US (California): California Attorney General — oag.ca.gov
- Australia: Office of the Australian Information Commissioner — oaic.gov.au
- Canada: Office of the Privacy Commissioner — priv.gc.ca

