1. Who is responsible for your data
FIFT is responsible for handling the personal data described in this notice for the controlled-beta portal.
Privacy requests use the public form at /contact. Each request is recorded with a reference ID and can be submitted without a portal session.
2. What we collect
Account data: name, email address, password hash (not the password), consent version and time, and limited request security data such as IP address and user-agent.
Broker evidence: provider client and account references, broker, server, masked account number, duplicate-detection fingerprints, evidence freshness, and broker-derived journal data where authoritative evidence is available.
Automatic discovery does not request broker credentials or create paid provider resources. Grandfathered read connections may retain encrypted credentials and an opaque transport reference solely to maintain or remove their existing transport. An invited Calibre setup sends the submitted destination credential directly into the gated provider setup request; FIFT does not display or log it.
Operational data includes security audit records, sign-in attempts, email delivery outcomes, support requests, and product telemetry.
3. Why we use it
To provide authentication, automatic account-evidence matching, journal and product tools, support, and retained-transport health where applicable.
To protect the service through rate limits, duplicate detection, audit trails, and abuse review.
To assess introducing-broker attribution from authoritative broker reports and retained historical evidence. FIFT may receive affiliation compensation from partner brokers. This can subsidise member access to tools, but it never conditions your access on trading more, and it never influences what appears in your journal or signals.
6. Retention and security
FIFT keeps account, consent, request, and audit records while needed to provide the beta and for security, accountability, disputes, or applicable obligations. Tokens are hashed and expire.
Security controls include encrypted storage for retained grandfathered credentials, hashed tokens, server-side authorization, session revocation, and audit logging. No internet service can promise perfect security.
Stopping an optional retained transport stops its new reads; it does not remove authoritative TradeQuo evidence supplied independently by the broker. Deletion requests remove data no longer needed, but limited records may be retained where necessary. FIFT does not claim a fixed universal deletion deadline.
7. Your choices and rights
You may update profile information, stop a grandfathered transport or invited product setup where available, and revoke any optional paper-automation consent in the portal.
You may request access, correction, or deletion through /contact. Use an email FIFT can match to the account where relevant. The response will explain any category that must be retained.
Additional mandatory privacy rights may apply where you live. Those rights are not reduced by this notice; jurisdiction-specific details will be published before commercial launch.