Legal
Last updated 21 July 2026. This explains what data HavenTrade collects and why.
This is a plain-language draft describing how HavenTrade actually handles data today. It has not been reviewed by a lawyer and should not be treated as a final compliance document — get qualified legal review before relying on it, especially for regulatory submissions or GDPR/data-protection obligations in your users' jurisdictions.
HavenTrade collects the minimum data needed to run your account, execute the features you use, and process payments. We don't sell your data.
Account data: email address and authentication data, handled via our Supabase-hosted auth provider.
Trading activity: paper-trading balances, positions, and trade history you generate inside the app.
Payment data: phone number and M-Pesa transaction references when you pay for a subscription. We don't see or store your M-Pesa PIN or full payment credentials — that's handled by our payment processor.
Notifications: phone number (for SMS price alerts), email address (for email alerts and digests), and a push-notification subscription token, only if you opt in to those alert channels.
AI chat & digest content: messages you send the AI assistant and the market/portfolio data needed to generate summaries, sent to our AI provider to produce a response.
Local device data: your watchlist and a couple of UI preferences are stored only in your browser's local storage — never sent to our servers.
When you connect a Deriv or Alpaca account, we store the OAuth access token issued by that provider so HavenTrade can fetch your balance/positions and place orders on your behalf. This token is stored server-side only — it is never sent to or readable by your browser. You can disconnect a broker account at any time, which deletes the stored token immediately.
To run your account and the features you actively use: authenticating you, tracking your paper portfolio, executing live orders you confirm, processing subscription payments, sending alerts you've opted into, and generating AI summaries/chat responses you request.
We use the following providers to run HavenTrade, each of which processes the data necessary for its function:
We don't sell personal data to advertisers or data brokers.
Data is stored in our Supabase database and accessed only through authenticated, server-side API routes. Broker access tokens and other credentials are never exposed to the browser. No system is perfectly secure, but we don't store anything beyond what's needed to run the features described above.
We keep your account data for as long as your account is active. Disconnecting a broker account deletes its stored access token immediately. You can request full account deletion at any time (see Your rights, below).
You can request a copy of your data, ask us to correct it, or ask us to delete your account and associated data, by emailing us. We'll act on verified requests as quickly as we reasonably can.
HavenTrade is not directed at children and is not intended for anyone below the age of legal capacity in their jurisdiction.
We'll update the "Last updated" date above whenever this policy changes materially, so check back periodically.
Questions about this policy, or want to exercise your data rights? Email havenwaysltd@gmail.com.