FakeTrade

Privacy Policy

How we handle your data.

Effective date: 2026-09-27

1. Who we are

FakeTrade is operated by an individual (the "Operator"). The Operator does not disclose a company name, registered office, or postal address. All correspondence -- including data-protection requests -- happens through a single email address: contact@faketrade.fun.

For the purposes of the EU General Data Protection Regulation (GDPR), the Operator is the data controller for personal data processed through FakeTrade.

2. Lawful basis for processing

We process your personal data under the following lawful bases (GDPR Article 6):

  • Art. 6(1)(b) -- performance of a contract: running your account, persisting your virtual balance, order book, leaderboard rank, etc., so the simulator works as advertised.
  • Art. 6(1)(f) -- legitimate interests: fraud prevention, abuse detection, and the minimum infrastructure logs needed to keep the service available and secure.

3. What data we collect

Authentication data (via Supabase Auth)

  • Your email address.
  • If you sign in via Google OAuth: your Google profile data, specifically your display name and avatar URL.
  • Your user ID (a UUID generated by Supabase).
  • For email/password accounts (if used): your password is stored only as a bcrypt hash. We never see the plaintext.
  • Auth metadata maintained by Supabase: account creation timestamp and last sign-in timestamp.

Application data

  • The username you choose for the leaderboard.
  • Your simulated balances (ranked and practice/sandbox).
  • Your order history, position history, and trade history inside the simulator.
  • When you last topped up your sandbox balance and when you last started it over. The first sets when your next top-up is available; the second sets which sandbox trades your stats and history show. Starting over deletes your sandbox orders and positions, but not your earlier sandbox trades: they stay in your trade history on our side and are no longer shown or counted.
  • Your watchlist: the markets you starred (at most 30).
  • The lines you draw on a market's chart while signed in (trend lines and horizontal lines), stored as a time and a price for each point, per market (at most 50 per market). They are visible only to you.
  • A leaderboard-exclusion flag used for admin and test accounts so they do not appear on the public leaderboard.
  • The timestamp at which you accepted these legal documents (see the registration acceptance flow).

What other people can see (your public profile)

A handle on the leaderboard is a public page. Anyone — signed in or not, including search engines — can open faketrade.fun/u/<your handle> and read all of the following about your ranked balance:

  • Your handle and, if you signed in with Google, the avatar image from that account.
  • Your leaderboard statistics: rank, ROI, realised profit and loss, win rate, biggest win, traded volume and how many positions you currently have open (the count only — never which ones).
  • Your most recent closed trades, and any weekly placements you have won.
  • Your realised profit or loss for each UTC day of the last 26 weeks, and how many trades you closed on each of those days — shown as a calendar grid. This is the same daily breakdown you see on your own dashboard.

Your balances, your open positions, your pending orders, your practice (sandbox) trading and how often you visit the site are not public. Entries are never published while a position is still open — only closed trades appear. If you would rather not appear at all, deleting your account (section 7a) removes your leaderboard entry and replaces your handle with an anonymous one.

Infrastructure data (collected automatically by our processors)

  • Vercel (hosting) records server logs covering your IP address, user-agent string, and requested paths.
  • Cloudflare Workers (price engine) records request logs for the simulator's pricing worker, including IP and the requested URL.
  • Supabase (auth + database) records auth and database logs.

Vercel also derives an approximate country from your IP address and makes it available to the page while it renders. We use it for one thing only: choosing which version of a piece of content to show you. We do not record it in our database, do not attach it to your account, and do not use it to profile you.

Cookies and browser storage (strictly necessary only)

We set no analytics, advertising, or marketing cookies, and we keep nothing in your browser for those purposes. The analytics we do run is cookieless (see below), which is why you are not asked to accept anything. What we do keep in your browser is there to provide the service. Cookies:

  • sb-* -- Supabase Auth session cookies. Without these you cannot stay logged in.
  • market_mode -- set when you switch markets, to remember which list you last viewed: Crypto, Stocks, Forex or Metals (1-year lifetime). The home page also uses it to pick the partner offer it shows: one on the Crypto list, one on the Stocks list, none on Forex or Metals.
  • ft_first_trade_tip -- set only when you close the first-trade tip on the trading screen, so it stays closed (1-year lifetime).
  • Vercel technical cookies used for caching and routing.

Session storage, which your browser deletes when you close the tab:

  • ft:last-symbol -- the last market you opened, so the Trade button in the mobile menu takes you back to it.
  • ft_activity_day -- that today's visit has already been counted towards your login streak, so the page does not send it again.
  • ft:ranked-topup-prompt and ft:kraken-win-prompt -- that a prompt has already been shown in this tab, so it appears at most once.
  • ft:chart-scale -- whether you switched the trading chart to a linear or a logarithmic price scale.
  • ft:trade-tab -- on a phone-sized screen, whether the trading page was showing the chart, the order book or the trades, so the next market you open shows the same one.
  • ft:chart-drawings:<market> -- only when you are not signed in: the lines you draw on that market's chart, so they survive a page refresh. Signed in, they are saved to your account instead (see “Application data” above).
  • phx:fallback:* -- written by our live-data connection only if it has to fall back to a slower connection method, so it does not keep retrying the one that failed.

Our service worker also keeps copies of the site's own public files -- scripts, styles, icons and images -- in your browser's cache storage, with a small index of when each was saved (serwist-expiration, in IndexedDB), so pages load faster and a basic offline page works. It holds no account data. Nothing is kept in local storage: versions of the site before 12 September 2026 stored ft:last-symbol and ft_activity_day there, and the site deletes them on your next visit. Clearing this site's data in your browser removes all of the above.

Following an outbound partner link is a different matter. The destination site may set its own cookies or identifiers in your browser so it can attribute the visit. That happens on their domain, under their privacy policy -- we neither set nor read those cookies, and we do not receive them. See our Terms of Service for how we label such links.

Analytics (cookieless)

We use Vercel Web Analytics to understand which parts of the site get used. It is cookieless: it stores nothing on your device and reads nothing from it. What it records is aggregate and is not tied to your account:

  • Page views, plus coarse technical context -- approximate country, device type, browser, operating system, and the site you arrived from.
  • If a page carries an outbound link to a partner, a count of clicks on it -- and, for every partner offer we show (on the home page, on your portfolio, under the order ticket on a trading page, and after a winning trade), a count of how often it was shown. These events record which offer and which link -- not who saw or clicked it.
  • No identifier is kept that would let us recognise you on a later visit or on any other website.

What we do NOT collect

  • No third-party or advertising analytics: no Google Analytics, no Facebook Pixel, no Hotjar, no session-replay or session-recording tools.
  • No cross-site tracking and no behavioural profiling. We do not follow you onto other websites, we do not build advertising profiles, and we do not share data with ad networks or data brokers.
  • No sale of your data to third parties.
  • No real money, financial, or payment data -- FakeTrade is a simulator and does not process payments.
  • No marketing emails. The only emails we send are transactional (account confirmation, password reset).

4. Processors we rely on

We use a small set of providers to actually run the service. Each acts as a data processor on our behalf:

Bot protection (Cloudflare Turnstile)

Our authentication endpoints are protected by Cloudflare Turnstile, which checks that a request comes from a real browser rather than an automated script. It runs in invisible mode: there is no puzzle and nothing to click. Because signing in to FakeTrade goes through Google, most visitors never encounter it at all -- it exists to stop scripts hitting the sign-up API directly.

To make that decision Cloudflare receives your IP address, basic browser and device characteristics, and a token scoped to this site. It is used only to tell a human apart from a bot, it does not identify you, and it is not used to profile you or to build an advertising audience. We never see the underlying signals -- Supabase verifies the token with Cloudflare and gets back a yes or a no.

Cloudflare processes this data as our processor under the Turnstile Privacy Addendum and the privacy policy linked above.

5. Third-party data sources

To run the simulator we pull live price data from public market-data APIs. These providers see only the symbols we request (e.g. BTCUSDT, AAPL) and our own server's IP. They do not receive your account, identity, or personal data:

  • Finnhub -- US stock quotes via the IEX feed.
  • Polygon.io -- historical stock candles.
  • Binance public market-data API and binance.vision -- cryptocurrency prices.
  • Coinbase public API -- cryptocurrency price fallback.

6. International transfers

Our processors operate globally. In particular, Supabase stores production data in the United States (region us-east-1) and Vercel runs on a global edge network. Where personal data leaves the European Economic Area, we rely on the European Commission's adequacy decisions where applicable and on standard contractual clauses (SCCs) where they are not. We flag this honestly: if EU-only data residency is critical for you, FakeTrade may not be the right service.

7. Retention

We keep account data (profile, balances, order/position history) for as long as your account exists. Infrastructure request logs from Vercel and Cloudflare are retained per their default policies -- typically around 30 days.

When you delete your account we erase what identifies you and keep the simulated trading record in anonymised form. Section 7a sets out exactly which is which, and why. Backups and infrastructure logs may persist for a short period before they roll off.

7a. Deleting your account

You can delete your account yourself at any time from Account settings. You will be asked to retype your username to confirm. The action is immediate and cannot be undone. If you would rather we did it for you, write to contact@faketrade.fun and we will action it within the deadline the GDPR sets for us.

What we erase. Your e-mail address; the name, photo and account identifier we received from your Google sign-in; your chosen username, which is replaced by an anonymous handle; your leaderboard entry; your push notification subscriptions, watchlist and chart drawings. Your sign-in is revoked and you will not be able to access the account again.

What we keep, and why. Your simulated trades, positions and orders, and any weekly prize placements, stay in our records attached to the anonymous handle. They carry no name, no e-mail and no photo, so they no longer identify you. We keep them because they form the historical results of a competition that other players took part in: weekly placements and prize records have to remain verifiable, and removing one participant would silently falsify everyone else's standings. This is the exception in Article 17(3)(e) GDPR, for the establishment and defence of legal claims. There is no real money in FakeTrade and these records have no financial effect outside the simulation.

Positions you leave open. Before we erase anything, we close every position you still have open at the current market price and cancel any orders you still have pending. Those closes are real and final: they settle to your simulated balance and appear in the trading history we retain. We do this so the account is not left holding a position nobody can act on once your sign-in is revoked. If we cannot get a price we trust for one of your positions -- typically because that market is closed -- we refuse the deletion outright and change nothing at all, rather than closing you out at a stale price. In that case simply try again once the market reopens, or write to us and we will complete it for you within the deadline the GDPR sets.

We also keep a minimal record that an erasure took place -- the date and the number of records affected -- so we can demonstrate we honoured your request, as Article 5(2) requires. That record deliberately does not contain any of the data we erased.

8. Your rights under GDPR

If you are in the EU/EEA (and in many other jurisdictions with similar laws) you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate data rectified.
  • Have your data erased (the "right to be forgotten").
  • Receive your data in a portable format.
  • Restrict or object to certain processing.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your local data-protection supervisory authority.

To exercise any of these rights, write to contact@faketrade.fun. We answer within a reasonable time and, in any event, within the deadlines GDPR sets for us. Erasure is also available directly in Account settings without writing to us at all -- see section 7a for what it erases and what it keeps.

9. Security

We use Supabase Row-Level Security and database-level functions to make sure your account data can only be read and modified by you (or by privileged backend processes that run the simulator). Passwords are stored hashed; OAuth tokens are scoped and short-lived. No system is perfectly secure, but we make a reasonable effort.

10. Changes to this Policy

We may update this Privacy Policy over time. The "Effective date" at the top reflects the latest version. Material changes will be announced on the site.

11. Contact

For privacy questions or to exercise your rights, contact contact@faketrade.fun. See also our Terms of Service and Risk Disclaimer.