Compliance & Security

Learn how TradeSim protects your data, maintains security, and ensures compliance with applicable data protection laws.

TradeSim is designed to align with applicable data protection laws, including India's Digital Personal Data Protection (DPDP) Act, the IT Act and SPDI Rules, and is compatible with global frameworks such as GDPR where relevant. The controls summarised below reflect what is implemented today and our roadmap for continued enhancement.

Your Data Controls

Export Your Data

Download a complete JSON export of your account data including profile information, strategies, backtest history, watchlists, and trade journal entries. Available via Settings or our API.

Delete Your Data

Permanently delete your account and all associated data from our systems. Data is removed within 30 days of deletion request. Available via Settings or our API.

Data Portability

Your data is exported in a machine-readable JSON format, enabling you to transfer it to other services if needed.

Consent Management

We currently provide limited analytics and performance telemetry. Granular, region-aware consent controls are on our roadmap.

Security Measures

Encryption in Transit & at Rest

All data transmitted between your device and our servers is encrypted using TLS 1.3. Data stored in our databases is encrypted using AES-256 encryption at rest.

Secure Cloud Infrastructure

Our infrastructure is hosted on SOC 2 compliant cloud providers with enterprise-grade security controls, regular audits, and automated vulnerability scanning.

Access Controls & Monitoring

Role-based access controls ensure only authorized personnel can access systems. All access attempts are logged and monitored for security incidents.

Infrastructure & Hosting

TradeSim is hosted on Supabase (PostgreSQL), Vercel (frontend/API), and AWS (data processing). All providers maintain industry-standard certifications including SOC 2 Type II, ISO 27001, and GDPR compliance.

  • Supabase: Database and authentication services
  • Vercel: Frontend application and API routes
  • AWS: Data processing and backtesting infrastructure

Audit Trails

Security-relevant events including error reports, data exports, and account deletion requests are logged in application logs. A dedicated, queryable audit log store is planned for future releases.

Implemented: Security and error event logging
Planned: Structured, user-accessible audit trails

Data Retention

We retain your data only for as long as necessary for the purposes outlined below:

Account Data

Retained while your account is active. Upon deletion, all personal data is purged within 30 days.

Strategies & Backtests

Retained until you manually delete them or 2 years of inactivity, whichever comes first.

Trade Journal

Retained until you delete entries manually or your account is deleted.

System Logs

Retained for 90 days for security monitoring and incident response purposes.

Marketing Communications

Retained until you unsubscribe or request deletion via our preferences.

Data Residency

Your data is primarily stored and processed in India (Mumbai region) on AWS infrastructure. Certain services (authentication via Supabase, frontend hosting via Vercel) may involve data transfer to servers in the United States for operational purposes.

These transfers are performed under appropriate safeguards including Standard Contractual Clauses and equivalent mechanisms as required by applicable law.

Important Disclaimer

TradeSim provides tools for historical analysis and strategy backtesting. All results are for educational and research purposes only. Past performance does not guarantee future results. We do not make any representations regarding the accuracy or completeness of backtest results.

Always conduct your own due diligence and consider consulting with a qualified financial advisor before making any investment decisions.

Questions or Concerns?

If you have questions about our data practices, security measures, or wish to exercise your data rights, please reach out.

Contact support