Solicitor-review note: this page was drafted by Claude (AI) from UK ICO guidance and standard templates, per our documented drafting approach — it is not solicitor-authored. Independent solicitor review is recommended and currently pending; go-live is not blocked on that certification. Questions in the meantime: privacy@tradingvigilante.com.

How we handle your data

Trading Vigilante is operated by VDM Ltd (the data controller). This page explains, plainly, what data this site handles and why. A fuller legal privacy policy is in preparation; this page is kept deliberately honest and current in the meantime. Questions or requests: privacy@tradingvigilante.com.

Analytics — only if you say yes

We use privacy-respecting product analytics to understand how this site is used — only after you click “Allow analytics” in our cookie banner. Until then, no analytics script loads and no analytics request leaves your browser: the default state for every consent signal is “denied”, and we verify that mechanically before every release. Declining is one click and just as effective. Your choice is stored in your browser; reopen the banner any time via the link in the banner text on your next visit, or clear your site data.

If you opt in, we collect standard analytics data: pages viewed, referrer, approximate location (derived from IP), device and browser type, and interaction events such as “sign-up started” or “purchase completed”. We use Google Analytics 4 (via Google Tag Manager) and PostHog, hosted on PostHog Cloud EU (Frankfurt, Germany) — your PostHog data stays in the EU. Google Analytics data is processed by Google, which may involve transfers outside the UK/EEA under Google’s standard contractual safeguards. We never use advertising cookies — the advertising consent signals are permanently denied.

Error monitoring — Sentry

We use Sentry to catch and diagnose bugs and crashes on this site — a diagnostic tool, not an analytics or advertising one. Sentry is configured with sendDefaultPii set to false, so it does not attach your IP address or other personal identifiers to error reports by default, and it captures no data gated behind the analytics consent signals described above. Because of that, we treat Sentry as outside the scope of the analytics cookie banner and it can load unconditionally — but we name it here for transparency regardless, alongside Google Analytics 4 and PostHog.

Our own records

When you become a customer, subscriber, or enquirer, your contact and transaction records (name, email, phone, marketing-consent status, orders, enquiry messages) are held in our customer platform, and a one-way copy is mirrored to our own private database (Supabase) so our business records don’t depend on any single third-party provider. That database is locked down: no public read or write access exists, and the privileged credential is held server-side only — it never runs in your browser. A copy of conversion events (opt-in / purchase / enquiry) is written to the same private database, server-side, when you have consented to analytics.

Contact form

The contact form on this site is delivered by our customer platform (GoHighLevel, also branded “LeadConnector”) inside an embedded frame, and is protected against abuse by Google reCAPTCHA — both load only on the page where the form appears and may set functional (not advertising) cookies of their own. What you submit — your name, email address, and message — goes straight into our customer platform so we can reply, and a one-way copy is mirrored to our own private database (see “Our own records”). Form submissions are not used for marketing unless you separately opt in, and they are never sold or shared beyond the processors named here.

Support email

Email sent to support@tradingvigilante.com is handled in our self-hosted helpdesk so we can answer you; it is not used for marketing.

Lawful basis for processing

UK GDPR requires us to identify a lawful basis for each way we use your data. Here is ours, purpose by purpose:

  • Customer and transaction records (name, email, phone, orders, enquiry messages, and their Supabase mirror) — performance of a contract (Article 6(1)(b)) where you are a customer, and legitimate interests (Article 6(1)(f)) in keeping accurate, durable business records where you are an enquirer who has not (yet) purchased.
  • Contact-form submissionslegitimate interests (Article 6(1)(f)) in responding to your enquiry, moving to contract performance if you go on to purchase.
  • Support emaillegitimate interests (Article 6(1)(f)) in providing customer support.
  • Analytics (Google Analytics 4 and PostHog, plus the server-side conversion-event mirror) — consent (Article 6(1)(a)), obtained through the cookie banner before any non-essential analytics cookie or script loads, in line with PECR. Withdrawing consent stops future collection immediately.
  • Sentry error monitoringlegitimate interests (Article 6(1)(f)) in keeping the site secure, stable, and free of bugs, balanced against your rights by configuring Sentry to exclude personal identifiers by default.

Where we rely on legitimate interests, we have considered that interest against your rights and freedoms and believe our use is proportionate and within your reasonable expectations; you can object at any time (see “Your rights” below).

Data retention

We keep personal data only for as long as we need it for the purpose it was collected for:

  • Customer and transaction records. For as long as you remain a customer, plus 6 years after your last transaction, to meet UK accounting and tax record-keeping obligations (Companies Act 2006 / HMRC guidance). Enquiry-only records (no purchase) are kept for up to 24 months, then deleted or anonymised.
  • Supabase mirror and conversion-event records. Our Supabase database is a one-way mirror of our customer platform (the system of record), so a mirrored record is kept only for as long as the underlying record exists there, and is removed when you exercise a deletion request (see “Your rights”).
  • Analytics. We rely on each analytics tool’s own default retention window rather than a custom override: Google Analytics 4’s default of 14 months for event-level data, and PostHog’s default of 12 months for raw event data on our plan.
  • Sentry error data. Sentry’s standard default retention window (90 days) for error events, after which it is automatically deleted.
  • Support email. Kept in our self-hosted helpdesk for as long as needed to handle your enquiry and maintain support records; you can request deletion at any time.

Your rights

You can request access to, correction of, or deletion of your personal data at any time: privacy@tradingvigilante.com. You can withdraw analytics consent whenever you like — it is never a condition of using the site.