UK GDPR
Privacy Notice
What we collect, why, what allows us to, who else handles it, how long we keep it and what you can make us do about it. Last updated 8 September 2026. Version 1.0.
1. Who we are, and how to reach us
- Data controller: BTRTrades (United Kingdom). Full legal name and postal address are available on request by email.
- Email: [email protected]
We have not appointed a data protection officer. Everything in this notice is handled by the person named above, so write to that address and it reaches the right person.
2. What this notice covers
It covers btrtrades.uk, the emails we send you about an order, the BTR Bot software you install, and the parts of the BTRTrades Discord server that we run. It does not cover Stripe's checkout pages, Discord's own platform, Instagram, or your broker. Those are separate companies with their own notices.
What this site keeps on your device, and how to switch off the one optional item, is set out in the cookie notice.
3. What we collect, why, and what allows us to
3.1 Joining the waitlist
- What we collect: your email address, your first name if you choose to give it, which product you asked about, and the fact that you ticked the consent box.
- Where it goes: straight into a private staff channel on our Discord server. It is not written to our database. That means Discord holds it for us until we delete the message.
- Why: so we can email you when that product is released.
- What allows us to: your consent - Article 6(1)(a) of the UK GDPR - and, for the marketing email itself, the same consent under the Privacy and Electronic Communications Regulations.
- Changing your mind: reply to any email, or write to us, and we will remove you. Withdrawing consent is as easy as giving it, and it does not affect anything we did before you withdrew it.
- Not collected: your IP address is not stored with your signup. It is used briefly to stop automated abuse - see section 3.8.
3.2 Buying something
- What we collect: your name and email address as you gave them to Stripe, what you bought, the Stripe checkout session and customer references, the amount of any discount and the promotion code used, and - if you type one in at checkout - your Discord username.
- What we never receive: your card number, expiry date or security code. Payment happens entirely on Stripe's pages.
- Where it goes: a Cloudflare D1 database that we control, in a table of orders. A copy of the order also exists in your Stripe account records.
- Why: to deliver what you bought, to give you support afterwards, to keep the accounting records the law requires, and to prevent the same order being fulfilled twice.
- What allows us to: performing our contract with you - Article 6(1)(b) - and, for the accounting records, our legal obligations - Article 6(1)(c).
3.3 Your licence or access key
- What we collect: the key itself, your email address, your Stripe subscription, session and customer references, your Discord username if you gave one, whether the key is active, suspended or withdrawn, and - for BTR Bot - the machine fingerprint in section 3.4 and the time it last checked in.
- Where it goes: the same Cloudflare D1 database, in a table of licences.
- Why: so your key opens what you paid for, so a cancelled subscription stops working, and so a leaked key cannot be run by other people.
- What allows us to: performing our contract with you - Article 6(1)(b).
3.4 The BTR Bot machine fingerprint
This deserves its own section, because it is the only thing we collect that comes from your hardware.
- What it is: when the software first runs, it works out a fingerprint of the computer it is running on. It takes three things - your computer's name, the hardware address of its network adapter, and its operating system version - joins them together and runs them through a one-way cryptographic hash. It sends us the first 32 characters of the result.
- What it is not: the hash cannot be turned back into your computer name, your network address or anything else. We never see those values.
- Why we treat it as personal data anyway: it is stable, it is unique to one computer, and we store it in the same record as your email address. Under the UK GDPR that makes it information relating to an identifiable person, and we would rather tell you that plainly than hide behind the fact that it is hashed.
- Why we use it: your subscription licenses one computer. The fingerprint is how we stop a leaked key running the software on several machines at once. If we did not do this, the subscription would not be enforceable at all.
- What allows us to: our legitimate interests - Article 6(1)(f) - in preventing licence abuse. We weighed that against the effect on you: the value identifies a machine and not a person, it cannot be reversed, we use it for nothing else, and one machine per licence is a term you agree to when you buy. Performing the contract - Article 6(1)(b) - applies for the same reason. You have the right to object; see section 8.
- The check-in time: we also record when the software last contacted us, which it does when it starts and roughly once a day. That is a rough record of when you were running it. It is what tells us a licence is live, and it is what lets us tell you why the software has stopped if your payment has failed.
3.5 Support tickets in Discord
- What we collect: your Discord username and Discord user ID, which ticket channel was opened, which member of staff picked it up and closed it, and the times.
- Where it goes: the ticket record is in our Cloudflare D1 database. The conversation itself stays in Discord.
- Why: so a ticket is not lost, so we can see whether it was answered, and so we can find it again if you come back.
- What allows us to: performing our contract with you - Article 6(1)(b) - or, where you are not a customer, our legitimate interest in running a support desk - Article 6(1)(f).
3.6 Emails you send us
If you email us we keep the message and our reply. What allows us to is our legitimate interest in dealing with your enquiry and keeping a record of what was agreed - Article 6(1)(f) - or performing our contract with you, if you are a customer.
3.7 Website analytics
- What happens: unless you turn it off, each page loads a counter from Cloudflare Web Analytics. Cloudflare states publicly that it does not store anything on your device and does not build a profile of you. Loading it does tell Cloudflare your IP address and your browser's user-agent string, because that is how the request reaches them.
- Why: so we can see which pages are actually used and whether the site is slow.
- What allows us to: our legitimate interests - Article 6(1)(f) - in understanding and maintaining our own website.
- Your control: a Cookie settings button in the footer of every page turns it off at any time, free of charge. See the cookie notice.
3.8 Stopping abuse of the waitlist form
When you submit the waitlist form, our server reads the IP address the request came from and keeps a count of submissions against it for 60 seconds, held in Cloudflare's edge cache, so that automated scripts cannot flood the form. It expires by itself. It is not written to our database and it is not stored with your signup. What allows us to is our legitimate interest - Article 6(1)(f) - in keeping our own systems usable.
3.9 The gated course library
To open the library your browser sends back the access-key cookie described in the cookie notice, and our server checks it against your entitlement on every request. Audio links are signed and stop working after an hour, so a link copied out of the page is useless to anyone else. What allows us to is performing our contract with you - Article 6(1)(b).
4. What we never do
- We do not sell, rent or trade your data. Not to anyone, not ever.
- We do not use your data for advertising, and we run no advertising cookies or tracking pixels.
- We do not send marketing emails to anyone who has not asked for them.
- We do not receive, store or transmit your broker credentials. They stay on your own computer.
- We do not profile you, score you, or make automated decisions that have a legal or similarly significant effect on you. The licence check is automatic, but all it checks is whether a subscription has been paid.
5. Who else handles your data
These are our processors. Each one only gets what it needs to do its job, and each one is bound to act on our instructions.
- Cloudflare - hosts this website, runs the code behind it, holds our database and our product files, provides DNS and security, and provides the page-view counter in section 3.7.
- Stripe - takes the payment and holds the payment record. Stripe also decides some things about your data for itself, particularly for fraud prevention and its own legal obligations, so for those purposes Stripe is a controller in its own right and Stripe's own privacy policy applies.
- Resend - sends our order, delivery, licence and access emails. That means Resend handles your email address, your first name and, for PDF products, the file being sent to you.
- Discord - runs the community server, the private staff channel that receives waitlist signups and delivery alerts, and the support ticket system.
One thing worth knowing. If an order email fails to send, an alert is posted into our private staff channel on Discord so we can send it by hand, That alert identifies the order by its checkout reference only, it does not contain your email address, and it goes to a channel only we can see.
6. Sending data outside the UK
Cloudflare, Stripe, Resend and Discord are all United States companies, and your data may be processed outside the United Kingdom.
Where that happens, we rely on the transfer terms in each supplier's published data-processing agreement.
7. How long we keep things
We would rather be honest than tidy here. Our software does not currently delete any of these records automatically. The periods below are the periods we work to, and they are applied by hand.
- Order and payment records: six years from the end of the tax year in which the sale falls, the period UK tax rules require us to keep business records.
- Licence and access-key records: while the licence or access is live, and for 12 months after it ends so that we can deal with any dispute or reinstatement; then deleted.
- The machine fingerprint and the last check-in time: deleted 12 months after the licence ends; they have no purpose once it has.
- Waitlist signups: until the product you joined the list for launches and you have been told, or until you ask us to remove you, whichever is first.
- Support tickets: for as long as the matter is open, then for as long as we need a record of how it was resolved.
- Emails: for as long as we need them to answer you and to keep a record of what was agreed.
- Analytics: held by Cloudflare under Cloudflare's own retention period.
8. Your rights
Under the UK GDPR you have the right to:
- Be told what we do with your data - which is what this notice is for.
- Get a copy of the personal data we hold about you.
- Have it corrected if it is wrong or incomplete.
- Have it deleted, where we no longer need it or where you withdraw consent. We may have to keep accounting records even so, and we will tell you if that is the case.
- Restrict what we do with it while a dispute about it is sorted out.
- Take it with you in a portable format, where we hold it on the basis of your consent or your contract.
- Object to anything we do on the basis of legitimate interests, including the machine fingerprint and the page-view counter.
- Withdraw consent at any time, where consent is what allows us to process it.
- Not be subject to a decision made solely by automated means that has a legal or similarly significant effect on you. We do not make any such decisions.
How to use them. Email [email protected]. It is free. We answer within one month, and we will tell you if a complex request needs longer. We may ask you to confirm who you are first, so that we do not hand your data to somebody else.
9. Complaining
If you are unhappy with how we have handled your data, please tell us first - we would rather fix it. You can also complain to the Information Commissioner's Office at any time, and you do not have to come to us first.
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
10. How we look after it
- The whole site is served over HTTPS and browsers are told never to use anything else.
- A content security policy restricts what code a page is allowed to load, and the site cannot be embedded in another site's frame.
- The cookie that opens the paid library cannot be read by any page script, and is only sent over HTTPS.
- Paid files are never public. They are held in private storage and released only by code that has already checked your entitlement, and audio links are signed and expire after an hour.
- Payment notifications from Stripe are cryptographically verified before we act on them, and licence responses are signed so they cannot be forged.
- Your broker credentials never reach us at all.
11. Children
Our products are not intended for anyone under 18 and we do not knowingly collect data about children. If you believe a child has given us their data, tell us and we will delete it.
12. Changes to this notice
If we change how we use your data we will update this page and raise the version number at the top. Where the change is significant we will tell customers by email.
Related: the cookie notice, the terms and conditions and the risk disclaimer.