Legal

Privacy policy.

What we hold, why we hold it, and what you can require us to do about it. It is short because we hold very little.

Last updated 17 September 2026

Who is responsible

The data controller is the business identified at the end of this page. If you want to know what we hold about you, or want it deleted, that is the address to write to — or use the contact form, which reaches the same inbox.

We are a small operation. There is no data protection officer because we are nowhere near the size that requires one, and the person who answers your email is the person who wrote the code.

What we collect

Only what the service cannot run without:

  • Your email address, so you can sign in and so we can send access instructions, renewal reminders and refund confirmations.
  • Your name, if you give one at sign-up, so emails are not addressed to a mailbox.
  • Your TradingView username, which is the thing access is granted to.
  • Billing records — what you paid, when, and for which period. Card details go to our payment processor and never reach us.
  • A log of consequential actions on your account: subscription changes, access grants, refunds. This is how a problem at two in the morning gets reconstructed.
  • Anything you write to us, and our reply.

We also count page views, which is described in its own section below and involves no identifier that lasts beyond the day.

What arrives on its own

Some information reaches us because of how the web works rather than because you typed it: the address you requested, the browser and operating system you asked with, the country your request arrived from, and the IP address of the connection.

We use it to serve the page, to keep the service standing up, and to count visits in the way described further down. The IP address is never written into our database — it is used in memory to work out a country and a one-way daily hash, and then discarded.

Our hosting provider keeps short-lived operational logs of requests, as any host does, for security and abuse prevention. Those are theirs, kept briefly, and we do not mine them.

What we never collect

We do not collect your card number, your broker credentials, your account balance, your positions or your trading history. We have no way to see any of it and no interest in it.

We do not buy data about you, we do not enrich what you give us from third-party sources, and we do not sell or rent anything to anyone. There is no advertising on this site and no advertising network watching it.

Specifically, and unlike much of this industry: we run no Google Ads, Meta or TikTok pixel; we do not use Google Analytics; we do not build advertising audiences from our customer list; we operate no social login, so no social network learns you came here; and we share nothing with “business partners” or “affiliates” for their own marketing. If any of that changes, this page changes first and we will say so.

Why we are allowed to hold it

Your email address, name, TradingView username and billing records are processed to perform the contract you entered into when you subscribed. Without them there is no way to give you access or to bill you.

The action log and the abuse protections rest on our legitimate interest in running a service that works and is not being defrauded, balanced against the fact that it holds very little and is never used to profile anyone.

Invoices and payment records are kept because accounting law requires it, not because we want them.

Where we ask for consent — the marketing category in the cookie notice, or a mailing list if we ever run one — you can withdraw it at any time and it is as easy to withdraw as it was to give.

Who else processes it

These are the only companies that touch any of it, and what each one is for:

  • Supabase — Database, authentication and file storage. Processed in: European Union.
  • Stripe — Payment processing, billing and invoices. Processed in: Ireland and the United States.
  • Cloudflare — Hosting, content delivery and protection against abuse. Processed in: Global network, EU-first routing.
  • TradingView — The platform the indicator runs on. Receives the username you give us, and nothing else. Processed in: United States.

Each is engaged under a data processing agreement and may only act on our instructions. Where a transfer outside the EEA is involved, it rests on the European Commission's standard contractual clauses or an adequacy decision.

Nobody else receives your data. We do not pass it to advertisers, data brokers or analytics companies, because we do not use any.

Measuring traffic

We count page views so we know which pages are read. The counting is done by our own server and the result goes into our own database — there is no Google Analytics, no advertising pixel, no session recording and no third party involved at any point.

Each view records the path, the day, a coarse device type, the country your request arrives from, and the domain that linked to you if there was one. We keep the linking domain only, never the full address, because a full referring URL can carry somebody else's search terms.

To count a visit once rather than five times, the server combines the date, your IP address and your browser's user-agent string and stores a one-way hash of the three. The IP address itself is never written down. Because the date is part of it, the value changes every midnight — so the same person tomorrow cannot be matched to the same person today, which is the point.

None of that is stored on your device, and none of it identifies you. You can still switch it off from the cookie notice or the Cookie choices link in the footer, and nothing about the site changes if you do.

How long we keep it

Your account and its data stay while your account exists. Delete the account and we remove the profile, the TradingView link and the access record.

Invoices and payment records are kept for seven years, because accounting law requires it. That is the one thing we cannot delete on request, and it holds the amount and the date rather than anything about you as a trader.

Page view rows are kept for twenty-five months and then dropped. The action log is kept for two years.

Messages you send us are kept while they are useful for support history, and cleared out after two years.

Your rights

Under the GDPR you may ask for a copy of what we hold, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, object to processing based on legitimate interest, and ask for it in a portable form.

Write to the address at the end of this page or use the contact form. We will answer within one month, and normally within a few days, because there is not very much to look through.

You do not have to give a reason and we will not ask for one. We may need to confirm you are who you say you are before we act, which protects you rather than us.

If you think we have handled your data badly, you may complain to your national supervisory authority. In Sweden that is Integritetsskyddsmyndigheten (IMY). We would rather you told us first so we can put it right.

Cookies

Signing in stores a session token in your browser so you stay signed in. That is strictly necessary for the account area to work, is not used for anything else, and is the only cookie this site sets.

Your answer to the cookie notice is kept in your browser's local storage so we do not ask again on every page. It holds nothing but your choice and the date you made it.

There are no advertising cookies, no analytics cookies, no pixels and no fingerprinting. The marketing category in the notice is switched off and nothing currently uses it; it exists so that anything added in future starts off rather than on.

Checkout is operated by our payment processor and may set cookies strictly necessary to complete a payment and prevent fraud, governed by that processor's own policy.

If you are in the United States

We apply the same standard to everyone rather than running a weaker policy outside Europe. So the rights described above — access, correction, deletion, and a copy of what we hold — are available to you wherever you live, on the same terms and at no charge.

For residents of California and other states with comparable laws: we do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in that legislation. There is nothing to opt out of, because we do not do it. We do not use or disclose sensitive personal information beyond what is needed to provide the service you bought.

You will not be treated differently for exercising any of these rights.

Children

This service is not for anyone under 18 and we do not knowingly collect anything about a child. If you believe a child has given us data, tell us and we will delete it and close the account.

Where your data is held

The database and the application are hosted in the European Union. Some of the companies listed above operate globally, so a transfer outside the EEA can happen — support tooling, fraud checks at the payment processor, or a request routed through a network edge outside Europe.

Where that happens it rests on the European Commission's standard contractual clauses, or on an adequacy decision covering the destination. We do not transfer anything to a country without one of those two things in place.

You can ask us for a copy of the safeguards that apply to a particular transfer and we will send it.

Automated decisions

We do not profile you and we make no decision about you by automated means that has a legal or similarly significant effect. There is no scoring of customers, no automated refusal, and no algorithm deciding what you are shown.

The indicator scores readings on your chart, not you. That happens inside TradingView on your own machine and none of it comes back to us.

Marketing

We do not add you to a mailing list because you bought something. Service email — access, renewals, refunds, security — is part of the contract and is sent regardless.

If we ever run a mailing list it will be opt-in, the opt-in will not be pre-ticked, and every message will carry a one-click unsubscribe. Unsubscribing will never affect your access or your subscription.

Security

Data sits in a managed database with row-level security, which means an account can only ever read its own rows even if a mistake is made in the application above it. Administrative actions are logged with who did them.

We do not store passwords — authentication is handled by our infrastructure provider, which stores a hash we cannot reverse.

If a breach happens that puts your rights at risk, we will tell the supervisory authority within seventy-two hours and tell you without undue delay. We will say what happened rather than what sounds best.

Changes to this policy

If we change what we collect or what we do with it, we update this page and change the date at the top. Where a change is material we tell account holders by email before it takes effect rather than relying on you to notice.

We will not start using data we already hold for a new and incompatible purpose without asking you first.

How to contact us about this

Use the contact form and pick the data topic, or write to the address in the block below. It reaches a person, not a queue.

For a request about your own data we will answer within one month, and normally within a few days — there is not very much to look through. We may need to confirm you are who you say you are first, which protects you rather than us.

If you are not satisfied with how we have handled something, you may complain to your national data protection authority. In Sweden that is Integritetsskyddsmyndigheten (IMY). We would rather you told us first so we have the chance to put it right.

Who you are dealing with

AvestAlgo
Sweden
Email: support@avestalgo.com

Registered address and organisation number are being added and will appear here.

Questions about this document go to that address, or through the contact form.