Your privacy · updated 15 July 2026

What we hold, and why

FIFT operates as a controlled beta. These documents describe the portal as it works today. The terms may be updated before commercial launch. FIFT does not claim any licence, registration, regulatory approval, or legal status it does not hold.

What we hold

Only what running the portal needs: your name and email, your consent record, and the broker evidence your broker sends us. Checking who you are is your broker's job, not ours.

  • 01We never ask you for documents. Your broker verifies your identity; their records reach us automatically.

Why we hold it

To sign you in, match your account evidence, run the journal and product tools, and keep the service safe from abuse. Nothing is used to profile or sell to you.

  • 02No figure travels by email. Your numbers stay behind your login.

Who sees it

Only the providers that host and run the portal, each receiving just what their job needs. We never sell your data and never share it with advertisers.

  • 03Affiliation is read from your broker's own reports. It never changes what appears in your journal or your signals.

Behind your login

One strictly necessary cookie keeps you signed in. Records are hashed where they can be, sessions can be revoked, and every access is logged. No internet service can promise perfect security, and we won't pretend otherwise.

  • 04No advertising, no cross-site tracking. The only cookie we set is the one that keeps you signed in.

Your rights

You can update your details, stop an optional connection, and ask what we hold — at any time — through the contact form. Some records we must keep for security or law; the reply will say which.

  • 05You may stop using FIFT at any time. Ask us what we hold whenever you like — the reply explains anything we must retain.

Version 2026-07-15 · a plain-language rewrite of the full notice below, and it never contradicts what you read here. Read the full privacy notice

The full privacy notice

Privacy Notice

Version 2026-07-15

1. Who is responsible for your data

FIFT is responsible for handling the personal data described in this notice for the controlled-beta portal.

Privacy requests use the public form at /contact. Each request is recorded with a reference ID and can be submitted without a portal session.

2. What we collect

Account data: name, email address, password hash (not the password), consent version and time, and limited request security data such as IP address and user-agent.

Broker evidence: provider client and account references, broker, server, masked account number, duplicate-detection fingerprints, evidence freshness, and broker-derived journal data where authoritative evidence is available.

Automatic discovery does not request broker credentials or create paid provider resources. Grandfathered read connections may retain encrypted credentials and an opaque transport reference solely to maintain or remove their existing transport. An invited Calibre setup sends the submitted destination credential directly into the gated provider setup request; FIFT does not display or log it.

Operational data includes security audit records, sign-in attempts, email delivery outcomes, support requests, and product telemetry.

3. Why we use it

To provide authentication, automatic account-evidence matching, journal and product tools, support, and retained-transport health where applicable.

To protect the service through rate limits, duplicate detection, audit trails, and abuse review.

To assess introducing-broker attribution from authoritative broker reports and retained historical evidence. FIFT may receive affiliation compensation from partner brokers. This can subsidise member access to tools, but it never conditions your access on trading more, and it never influences what appears in your journal or signals.

4. Who we share it with

Hosting, database, and configured email providers receive only data needed to provide their services. A retained transport provider may process data for grandfathered read transports and explicitly configured, invitation-bound Calibre destinations.

TradeQuo matching and attribution use broker-provided reports. FIFT does not sell personal data or share it with advertisers.

5. Cookies

A strictly necessary HttpOnly, Secure, SameSite cookie keeps a session signed in for up to 7 days. Its host-wide path keeps authentication functional across the FIFT portal. No advertising or cross-site tracking cookies are used.

A legacy referral cookie may be cleared during signup; it does not create broker attribution. Eligibility and attribution are confirmed from TradeQuo records.

6. Retention and security

FIFT keeps account, consent, request, and audit records while needed to provide the beta and for security, accountability, disputes, or applicable obligations. Tokens are hashed and expire.

Security controls include encrypted storage for retained grandfathered credentials, hashed tokens, server-side authorization, session revocation, and audit logging. No internet service can promise perfect security.

Stopping an optional retained transport stops its new reads; it does not remove authoritative TradeQuo evidence supplied independently by the broker. Deletion requests remove data no longer needed, but limited records may be retained where necessary. FIFT does not claim a fixed universal deletion deadline.

7. Your choices and rights

You may update profile information, stop a grandfathered transport or invited product setup where available, and revoke any optional paper-automation consent in the portal.

You may request access, correction, or deletion through /contact. Use an email FIFT can match to the account where relevant. The response will explain any category that must be retained.

Additional mandatory privacy rights may apply where you live. Those rights are not reduced by this notice; jurisdiction-specific details will be published before commercial launch.