1. Information We Collect
Account Information
- Name, email address, and hashed password when you register
- Payment information processed securely through Stripe (we do not store card numbers)
Trading Data
- Trade logs you enter manually or import via CSV
- Trades synced from connected platforms (Tradovate)
- Notes, tags, strategies, and screenshots you attach to trades
Usage Data
- IP address for rate limiting and security purposes
- Browser type and device information
- Pages visited and features used within the app
2. How We Use Your Information
- To provide and maintain the Service
- To process payments and manage your subscription
- To send transactional emails (verification, password reset, billing)
- To detect and prevent fraud, abuse, and security threats
- To improve the Service based on usage patterns
We never sell your personal data or trading information to third parties.
3. Data Storage and Security
Your data is stored securely using Turso (distributed SQLite database) with encrypted connections. Passwords are hashed using bcrypt with 12 salt rounds. All data transmitted between your browser and our servers is encrypted via HTTPS/TLS.
Additional security measures include:
- Rate limiting on authentication endpoints
- Account lockout after repeated failed login attempts
- Secure session tokens with automatic rotation
- Security headers (HSTS, CSP, X-Frame-Options)
4. Third-Party Services
We use the following third-party services:
- Vercel — Hosting and deployment
- Turso — Database hosting
- Stripe — Payment processing
- Resend — Transactional emails
- Yahoo Finance, Finnhub, Tiingo — Market data (no personal data shared)
- Tradovate — Trade sync (only when you connect your account)
Each service has its own privacy policy. We only share the minimum data required for each service to function.
5. Cookies
DreamzCore uses essential cookies only — a session cookie for authentication. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
6. Data Retention
- Account data is retained as long as your account is active
- When you delete your account, all data is permanently deleted within 30 days
- Backups containing deleted data are purged within 90 days
- Rate limiting logs (IP addresses) are automatically purged
7. Your Rights
You have the right to:
- Access — View all data associated with your account in Settings
- Export — Download your trade data
- Delete — Permanently delete your account and all data from Settings
- Correct — Update your profile and trade information at any time
8. Children
DreamzCore is not intended for users under 18 years of age. We do not knowingly collect information from minors. If you believe a minor has created an account, please contact us.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email. Your continued use of the Service after changes constitutes acceptance.
10. Contact
Questions about your privacy? Contact us.