This privacy policy explains how Phoenix Technologies processes personal data when you visit thortradecopier.com, create a THOR account or use the THOR trade copier. It is provided to meet the transparency requirements of Regulation (EU) 2016/679 (GDPR, in particular art. 13) and of the French loi n° 78-17 du 6 janvier 1978. The full texts of these rules are available at https://www.legifrance.gouv.fr.
This policy is published in English and in French. In case of any discrepancy between the two versions, the French version (/politique-confidentialite) prevails for consumers residing in France.
The controller of the personal data described in this policy is:
PHOENIX TECHNOLOGIES, a French société par actions simplifiée (SAS) with a share capital of 1,000 euros, registered with the Trade and Companies Register of Paris under number 938 548 112 (RCS Paris), SIRET (head office) 938 548 112 00011, intra-Community VAT number FR31938548112, registered office: 60 rue François Ier, 75008 Paris, France. President and publication director: Léon Grimm.
Phoenix Technologies has not appointed a Data Protection Officer (DPO). For any question about this policy or about your personal data, contact us at [email protected].
This policy applies to the public website thortradecopier.com, to the THOR dashboard and application sub-domains, and to our related communications with you.
We process personal data only for the purposes listed in the table below. Data whose legal basis is the contract is necessary to open and operate your account: without it, we cannot provide the service. THOR copies orders between trading accounts that belong to you, so the trade and copy logs we keep concern your own accounts only. We do not use your data for automated decision-making producing legal effects, and we never sell personal data.
Payments are processed by Stripe: your full card number is transmitted directly to Stripe and never touches our servers.
| Purpose | Data | Legal basis (art. 6 GDPR) | Retention |
|---|---|---|---|
| Account creation and management | Identity, email address, login credentials | Performance of the contract | Life of the account, then 5 years after closure for evidence purposes (statutory limitation periods) |
| Billing | Billing identity, billing address, transaction history processed via Stripe; Phoenix Technologies never stores full card numbers | Performance of the contract and compliance with a legal obligation | Invoices kept 10 years (French accounting law) |
| Service operation | Broker and platform connection identifiers and API tokens, copier configuration, TradingView webhook alert data that you choose to send us to automate your own strategies on your own accounts, trade and copy logs | Performance of the contract | Connection data deleted when you disconnect the account; trade and copy logs kept 12 months |
| Customer support | Correspondence with our support team | Performance of the contract and legitimate interest (answering enquiries from prospects and keeping evidence of exchanges) | 3 years after your last contact |
| Security and abuse prevention | IP addresses, technical logs | Legitimate interest (securing the service and preventing fraud and abuse) | 12 months |
| Audience measurement (analytics cookies) | Browsing data, collected only with your consent (see our Cookie Policy) | Consent | Cookies: 13 months maximum; audience measurement data retained in Google Analytics: 14 months maximum |
| Affiliate attribution | Referral code | Consent (marketing cookie). Without that consent, the code is kept only in your browser's session storage for the current visit (legitimate interest in attributing affiliate commissions) | 180 days (cookie, with consent); duration of the visit only (session storage, without consent) |
| Website delivery and protection (CDN, security) | IP address, browser technical identifier (user agent) | Legitimate interest (technical delivery and protection of the website) | Not stored by Phoenix Technologies; processed transiently by Cloudflare, Inc. (see section 3) |
Your data is accessible, strictly within the limits of their respective roles, to the following categories of recipients:
Each processor acts under a data processing agreement compliant with art. 28 GDPR and processes data only on our documented instructions. Phoenix Technologies never sells personal data and never shares it with third parties for their own marketing purposes.
Your account and application data are hosted in the European Union (Hetzner Online GmbH, Germany). The public website is hosted by Namecheap, Inc. in the United States, and Cloudflare, Inc. (USA) delivers and protects it, receiving your IP address and browser technical identifier (user agent) on every visit, independently of your cookie choices. Where you consent to audience measurement cookies, measurement by Google may involve further transfers to the United States. Payment data processed by Stripe Payments Europe, Ltd. may be transferred to Stripe, Inc. in the United States. Where you connect a trading platform operated outside the EU (for example Rithmic, Tradovate or NinjaTrader in the United States), this connection and order data is transferred to that platform because the transfer is necessary for the performance of our contract with you (art. 49(1)(b) GDPR).
Google LLC, Cloudflare, Inc. and Stripe, Inc. are certified under the EU-US Data Privacy Framework. Transfers to Namecheap, Inc. are governed by the European Commission's standard contractual clauses (art. 44 et seq. GDPR). You can obtain a copy of the applicable safeguards on request at [email protected].
Under arts. 15 to 21 GDPR and the loi n° 78-17, you have the following rights over your personal data:
To exercise these rights, write to [email protected] (art. 48 loi n° 78-17). We respond within one month. Where a request is complex or where we receive numerous requests, this period may be extended by two further months; in that case we inform you of the extension and its reasons within one month of receiving your request (art. 12(3) GDPR). If we have reasonable doubts about your identity, we may ask you for additional proof of identity before acting on the request.
We apply technical and organisational measures appropriate to the risk, including:
In the event of a personal data breach likely to result in a risk to your rights, we notify the CNIL within 72 hours of becoming aware of it, in accordance with art. 33 GDPR, and inform the affected users where legally required.
The service is reserved for adults (18 years and over). We do not knowingly process children's data. Under the loi n° 78-17, the age from which a minor may consent alone to the processing of their data in France is 15; the contractual age requirement for using THOR nevertheless remains 18. If we learn that an account has been opened by a minor, we close it and delete the associated data, subject to the statutory retention obligations described in section 2.
When you arrive on our website, a consent banner lets you accept or refuse non-essential cookies. Audience measurement and marketing cookies are set only after you consent, in line with the CNIL guidelines (délibérations n° 2020-091 et 2020-092). For the full list of cookies used, their lifetimes and how to change your choices at any time, see our Cookie Policy.
If we make a material change to this policy, we publish the updated version on this page at least 30 days before it takes effect. The applicable version is the one published on this page; its date always appears at the top of the document.