Privacy Policy

Version 1.0Effective 24 August 2026

1. About this Privacy Policy

Propcockpit is a risk-management and trading interface for users who connect supported cTrader accounts. This Privacy Policy explains how personal data is collected, used, shared, protected and retained when you visit our website, create an account, connect a broker account, configure risk rules, place or manage orders, use integrations, subscribe to a paid plan, or contact us.

The data controller is:

Propcockpit
Storängsvägen 16B

184 31 Åkersberga

Sweden

Phone: 0707543235
Email: info@propcockpit.com

In this Policy, “Propcockpit”, “we”, “us” and “our” refer to that operator. We are established in Sweden and process personal data in accordance with the EU General Data Protection Regulation, or GDPR, and applicable Swedish data-protection law.

This Policy applies to Propcockpit. Your broker, prop firm, cTrader or Spotware account, payment provider and other third-party services have their own privacy notices and act under their own responsibilities where they determine how and why they process your data.

2. Personal data we process

We process the following categories of personal data where relevant to your use of Propcockpit.

2.1 Account and identity data

  • Name, email address and account identifiers.
  • A one-way hash of your password, your session records, and - if you enable two-factor authentication - the shared secret and recovery codes for it. We run our own authentication rather than delegating it to an identity provider, so this material is held by us and is not sent to a third party.
  • If you sign in with Google, the Google account identifier, the email address and the name Google returns to us. We never receive your Google password.
  • Account settings, language, time zone, preferences and plan.
  • Records showing which version of our Terms of Service and Privacy Policy you accepted and when.

We do not receive or store your cTrader password. You enter it only on Spotware’s or cTrader’s authorization pages.

2.2 Broker connection and authorization data

  • cTrader account identifiers and the broker associated with an account.
  • OAuth access and refresh tokens issued after you authorize Propcockpit.
  • The permission scope you approve: accounts for view-only account information and statistics, or trading for account information, statistics and permitted trading operations.
  • Connection state, token refresh events, revocation status and diagnostic information.

The trading permission can allow Propcockpit to place, modify and close orders on an authorized account. It does not allow Propcockpit to withdraw or transfer funds from your broker account.

2.3 Trading, account and risk data

  • Account balance, equity, margin, currency and account status.
  • Open and historical positions, pending orders, deals and trading history.
  • Symbols, prices, volume, stop-loss and take-profit values, timestamps and broker responses.
  • Risk settings and limits you configure, including daily-loss, maximum-drawdown, per-order and account-protection settings.
  • Calculated risk values, daily baselines, cross-account summaries and whether an account is marked as protected or unprotected.
  • Order tickets, pre-trade checks, rejected or resized orders, close attempts, cancel attempts and other risk events.
  • Journal, activity-log and audit entries relating to actions in the Service.

Positions or orders opened directly at your broker may still be read and counted when Propcockpit monitors an authorized account. In version 1, an aggregate or cross-account risk number shown in the interface is informational and is not itself an enforced limit.

2.4 Integration and webhook data

  • Integration settings, endpoint identifiers and secret-verification material.
  • Incoming webhook metadata and payload fields required to validate and process an instruction.
  • Nonces, timestamps, replay-protection results, validation results and the order or action produced.
  • Delivery, retry and error logs.

Webhook secrets are displayed only when created. Verification values are stored in a non-reversible form.

2.5 Billing data

  • Subscription plan, trial status, billing status, transaction identifiers, invoice information, currency, tax information and limited payment-method metadata such as card brand and last four digits.
  • Records needed for refunds, disputes, accounting and tax compliance.

Payments are processed by Stripe. Stripe receives your full payment-card information directly. Propcockpit does not receive or store your full card number or card security code.

2.6 Technical, security and usage data

  • IP address, device and browser type, operating system, language and approximate region inferred from an IP address.
  • Login time, request time, pages or product functions used, application version and referral URL.
  • Server, application, network and security logs, including failed authentication, rate-limit and error events.
  • Cookie and session identifiers required to authenticate you, protect your session and operate the Service.
  • Diagnostic data included in a support bundle that you choose to send us.

2.7 Communications

  • Support requests, vulnerability reports, feedback and other messages you send us.
  • Operational email, push or messaging delivery status and your notification preferences.

We do not intentionally collect special-category data such as health information, biometric data, political opinions or religious beliefs. Please do not include such information in support messages or webhook payloads.

3. Where the data comes from

We obtain personal data:

  • directly from you when you register, configure the Service, subscribe or contact us;
  • from Google, if you choose to sign in with a Google account;
  • from our billing provider;
  • from Spotware Systems Ltd through cTrader Open API and from your broker after you authorize the connection;
  • from instructions and integrations that you configure;
  • automatically from your browser, device and use of the Service; and
  • from security, availability and support systems used to operate the Service.

You must have the right to provide any personal data that you submit about another person. Do not place unnecessary personal data in webhook payloads, account labels, journal notes or support messages.

4. Why we process personal data and our legal bases

We process personal data only where we have a legal basis.

4.1 To provide and administer the Service

We use account, broker, trading, risk, integration and billing data to:

  • create and maintain your account;
  • connect the cTrader accounts you authorize;
  • display trading and account information;
  • calculate risk values and evaluate the rules you configure;
  • perform the order, modification, cancellation or closing instructions you submit or arm;
  • keep a journal and activity record;
  • provide exports, alerts, support and plan features; and
  • administer trials, subscriptions, invoices and cancellations.

The legal basis is performance of our contract with you, Article 6(1)(b) GDPR.

If you do not provide data that is required for an account, broker connection or payment, we may be unable to provide the relevant part of the Service.

4.2 To protect and improve the Service

We use technical, usage, audit and security data to prevent abuse, detect incidents, investigate errors, maintain availability, enforce our Terms, improve performance and understand aggregate product usage.

The legal basis is our legitimate interest in operating a secure, reliable and useful service, Article 6(1)(f) GDPR. We balance that interest against your rights and use proportionate access controls, retention limits and data minimization.

4.3 To meet legal obligations

We process billing, transaction and compliance records where required by accounting, tax, consumer, sanctions or other applicable law. The legal basis is compliance with a legal obligation, Article 6(1)(c) GDPR.

4.4 With your consent

Where we ask for optional consent, such as for non-essential marketing communications, the legal basis is your consent, Article 6(1)(a) GDPR. You may withdraw consent at any time. Withdrawal does not affect processing that occurred before withdrawal.

Service messages, security notices, receipts and material contractual notices are not marketing and may still be sent when needed to provide the Service or comply with law.

5. Automated rule evaluation and trading actions

Propcockpit automatically compares authorized trading data with the risk settings you configure. Depending on the features you enable and the permissions you grant, the Service may calculate a permitted size, resize or reject an order, require a broker-side stop-loss, mark an account as unprotected, or attempt to close positions and cancel pending orders when an armed threshold is reached.

These actions directly execute rules selected and expressly armed by you. We do not use automated rule data to infer unrelated personal characteristics or to decide eligibility for credit, insurance, employment, pricing or another unrelated service. You can review your settings, change or disarm rules, disconnect an account and contact us about an action. A broker, market, API or network can delay, reject or alter the outcome of an instruction.

You may ask a person with appropriate authority and competence to review a Propcockpit automated action, provide your point of view, contest the result and receive an explanation of the rule, data and result. A review cannot reverse a trade already executed by a broker or undo market movements, but it can correct Propcockpit records, settings and future handling and address any remedy available under law. Contact info@propcockpit.com.

6. Who receives personal data

We disclose personal data only as needed for the purposes described above.

6.1 Service providers

Our service providers process data under contract and on our instructions where they act as processors. The current provider table, including legal names, roles, processing locations and transfer safeguards, is at propcockpit.com/legal/providers.

The providers in use today are:

  • DigitalOcean for the server that runs the website, the application and the database;
  • Stripe for subscriptions, payments, invoices, fraud prevention and related financial services;
  • Resend for transactional email such as verification, password reset and service notices;
  • Telegram, only for users who connect it, to deliver the alerts they ask for; and
  • Google, only for users who choose to sign in with a Google account.

We do not use a separate identity provider, a managed database provider or a third-party cache. Authentication, the application database and session handling all run on our own server.

Some providers, including Stripe, may also process data as an independent controller for their own legal, compliance and fraud-prevention purposes. Their privacy notices govern that processing.

6.2 Spotware, brokers and prop firms

When you connect an account, Spotware Systems Ltd, which operates cTrader Open API, and your broker process authorization requests and trading instructions under their own terms and privacy notices. Propcockpit sends instructions only for accounts, scopes and functions that you expressly authorize. Your broker or prop firm may independently retain trading and account records. Deleting data from Propcockpit does not delete records controlled by those third parties.

6.3 Legal and safety disclosures

We may disclose data where reasonably necessary to comply with law, a binding authority request or court order; establish, exercise or defend legal claims; protect users or the public; investigate fraud or abuse; or protect the rights, security and integrity of Propcockpit. Where legally permitted, we will assess requests for validity and scope and disclose only what is necessary.

6.4 The public Charts page

The public Charts page at propcockpit.com/charts embeds TradingView’s own chart widget, loaded from TradingView’s servers. When you open that page, your browser contacts TradingView directly and TradingView receives your IP address, browser information and the symbol you are viewing, under TradingView’s privacy notice rather than ours. That page requires no account and sends nothing to Propcockpit beyond the ordinary request for the page itself.

The chart inside the signed-in product is different: the charting library is served from Propcockpit and its prices come from your authorized broker connection, so using it does not contact TradingView.

6.5 Business changes

If the business is reorganized, financed, sold or transferred, relevant data may be disclosed under confidentiality safeguards and transferred as part of that transaction. We will provide notice where required by law.

We do not sell personal data. We do not share personal data for cross-site behavioral advertising.

7. International transfers

The server that runs Propcockpit - the website, the application and the database - is in London, United Kingdom, in DigitalOcean’s LON1 region. The United Kingdom is outside the EU and the EEA, so sending your data there is an international transfer under Chapter V of the GDPR.

That transfer is made under the European Commission’s adequacy decision for the United Kingdom, which the Commission renewed on 19 December 2025 and which runs to 27 December 2031. An adequacy decision means the transfer needs no further safeguard: the Commission has found that UK law protects personal data in a way that is essentially equivalent to EU law. If that decision were to lapse or be annulled, we would move to the European Commission’s Standard Contractual Clauses with our hosting provider, or move the service back inside the EEA.

Some providers or their support teams may process data outside the EU, the EEA or the United Kingdom. For each of those, the actual safeguard - an adequacy decision, the recipient's participation in the EU-US Data Privacy Framework, or the applicable module of the Standard Contractual Clauses - is named in the provider table. Contact us to obtain a copy where one is available.

8. How long we keep personal data

We keep personal data only for as long as needed for the purpose for which it was collected, including legal, security and dispute-resolution needs. Subject to any longer period required by law or an active dispute, our standard periods are:

  • Account and profile data: while the account is active. Requesting deletion starts a 30-day period in which you can still change your mind; after it, eligible data is deleted.
  • Broker access and refresh tokens: until you disconnect the broker account, revoke access or delete your Propcockpit account. Active copies are then deleted or made unusable without undue delay.
  • Trading journal, order, risk-rule and activity data: while the account is active and until the deletion period above completes, unless you request earlier deletion and no exception applies.
  • Webhook invocation logs: 90 days after the invocation.
  • Security, access and application logs: normally 90 days, with a longer period only where an event is needed to investigate an incident, abuse or legal claim.
  • Support messages and support bundles: 24 months after the support matter is closed. A support bundle may be deleted sooner when it is no longer needed.
  • Audit records needed to establish authorization, consent, acceptance or defend a claim: for the applicable limitation period, and longer only if a claim is ongoing.
  • Billing, invoice and accounting records: for seven years after the end of the calendar year in which the relevant financial year ended, or any longer period required by applicable law.

If an account has had no login, broker connection or other activity for 24 months, we may notify you and close it. Eligible data is then deleted under the same timetable as a requested account deletion.

Encrypted backups rotate out according to our backup schedule and may retain deleted data for up to 30 additional days. Backup data is isolated from ordinary use and is restored only for disaster recovery. If a backup is restored, deletion controls are reapplied.

We may retain aggregated or irreversibly anonymized statistics that can no longer identify you.

9. Account deletion and data export

You may export your profile, connected-account identifiers, rules, journal and activity ledger as a JSON file from your account settings, at any time and without asking us. You may also delete your account from the same place, or by emailing info@propcockpit.com.

Deleting your Propcockpit account disconnects broker access and schedules eligible personal data for deletion. It does not:

  • close positions or cancel orders at your broker unless the product expressly confirms that action;
  • delete records held independently by your broker, prop firm, cTrader, Spotware, Stripe or another controller;
  • remove accounting records or evidence that we must retain by law; or
  • remove data needed to resolve an active payment dispute, security incident or legal claim.

Before deleting an account, secure any export you need and separately review your open positions, pending orders and broker connection.

10. Security

We use technical and organizational measures designed to protect personal data. Broker tokens are encrypted at rest using envelope encryption with AES-256-GCM. Each connected broker account has its own data-encryption key, and the key that protects those keys is held outside the application database, so a copy of the database alone cannot decrypt anything. Tokens are handled server-side, are never sent to the client browser and are not written to application logs.

We also use access controls, session protection, logging, monitoring, provider security features and procedures for handling vulnerabilities and incidents. No internet service is perfectly secure, and we cannot guarantee that unauthorized access, loss or misuse will never occur. See the separate Security page for a plain-language description of current controls and limitations.

You are responsible for protecting your device, email, authentication factors and broker account. Contact us promptly if you believe your Propcockpit account or a connected credential has been compromised.

11. Cookies and similar technologies

We use cookies and similar local-storage technologies that are necessary to:

  • sign you in and maintain your session;
  • prevent forgery, fraud and abuse;
  • remember security and interface preferences; and
  • route and operate the Service reliably.

We do not use advertising or cross-site tracking cookies, and we show no cookie banner because we set nothing that would need consent. The public Charts page is the one exception worth naming: TradingView’s embedded widget is their technology on their terms, and what it stores in your browser is described in their privacy notice.

If we introduce non-essential analytics or marketing technologies, we will update this Policy and request consent where required before using them.

12. Your rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  • receive information about our processing;
  • access personal data we hold about you;
  • correct inaccurate or incomplete data;
  • request deletion of data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive data you provided in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller;
  • withdraw consent at any time where processing is based on consent; and
  • request human review of an automated decision where Article 22 GDPR applies.

To exercise a right, email info@propcockpit.com. We may need to verify your identity and clarify your request. We will respond without undue delay and normally within one month. A request is generally free of charge, although the GDPR permits a reasonable fee or refusal where a request is manifestly unfounded or excessive.

You may complain to the Swedish Authority for Privacy Protection:

Integritetsskyddsmyndigheten (IMY)
www.imy.se
Box 8114, 104 20 Stockholm, Sweden

You may also contact the supervisory authority in the EU or EEA country where you live or work or where you believe an infringement occurred.

13. Children

Propcockpit is intended only for persons aged 18 or older. We do not knowingly offer the Service to children or knowingly collect personal data from them. If you believe a child has provided personal data, contact us so that we can investigate and delete it where appropriate.

14. Changes to this Policy

We may update this Policy to reflect changes in the Service, providers, law or our processing. The current version will show its effective date and version number. If a change materially affects your rights or how we use personal data, we will provide reasonable advance notice by email, in the Service or by another appropriate method. Where the law requires consent, we will ask for it.

15. Contact

Questions, privacy requests and complaints may be sent to:

Propcockpit
Storängsvägen 16B

184 31 Åkersberga

Sweden

Phone: 0707543235
Email: info@propcockpit.com

Keyboard

?
Open and close this sheet.
Escape
Stand down anything that is armed - the kill switch, an open notification panel, this sheet. It never commits anything.
Tab / Shift + Tab
Move between controls. Every one of them shows a focus ring.
Arrow keys
Nudge a focused panel around the canvas. Hold Shift to move it further per press.
Enter or Space
Activate the control that is focused, and only that one. There is deliberately no key anywhere that sends an order on its own.