Get in

YTrading

Privacy Policy

Effective and last updated: 2 October 2026

This policy explains the information YTrading handles when people visit the public website, sign in, or use member services. It also explains the limited Google user data used for Google Sign-In.

1. About this policy

YTrading is a trading education and technology brand. This policy applies to the YTrading website and member application at ytrading.co. It does not describe the separate privacy practices of a broker, exchange, Google, or another service a person chooses to use.

2. Information YTrading collects

Depending on the features a person uses, YTrading may handle:

  • account identifiers such as email address, internal user ID, sign-in method, role, and account dates;
  • profile and onboarding details such as country, legal name, Room nickname, and account settings;
  • member content such as direct messages, Room messages, support subjects and replies, reviews, and operational notes;
  • copy, licence, and OS-request information such as status, broker or platform references, account-number references, server, PC name, request notes, and licence records;
  • security and technical information such as login IP address, authentication method, last-seen time, session records, rate-limit signals, audit events, and security outcomes; and
  • information a member deliberately includes in a message, Room post, support ticket, or request.

The website does not ask for broker passwords, investor passwords, exchange API secrets, or withdrawal keys. People should not put those secrets, full identity numbers, or unrelated personal information into free-text fields.

3. Google Sign-In and Google user data

Google Sign-In is the production sign-up and sign-in method for YTrading. The application requests only the basic openid, email, and profile scopes. Google may return basic profile claims under those scopes. YTrading uses the Google account's unique subject identifier, email address, and email-verification signal for authentication, account creation or secure account linking, identity, and account security. The application does not use or store a Google profile photo or profile name from this sign-in flow.

YTrading stores the normalized email address and Google subject identifier with the member account. If Google reports an updated email for the same subject, the account email may be updated. Linking checks are used to prevent one Google identity from being attached to a different account.

YTrading does not request or access Gmail, Google Drive, Google Contacts, Google Calendar, Google payments, or unrelated Google services. Google user data is not used for advertising, sold, or transferred for unrelated purposes. Access is limited to YTrading's application and the service providers needed to operate it. YTrading uses Google user data only for the practices disclosed in this policy and will update this policy before changing that use.

4. How information is used

YTrading uses information to:

  • create, link, authenticate, secure, and administer accounts and sessions;
  • provide Room, messages, support, copy-status, licence, and OS-request functions;
  • show the member the records and settings associated with that account;
  • moderate misuse, enforce role boundaries, investigate security events, and apply rate limits;
  • operate, diagnose, maintain, and improve the application; and
  • respond to signed-in support, privacy, and deletion requests.

YTrading does not use member or Google user data for third-party advertising.

5. Essential cookies and sessions

YTrading uses essential, first-party cookies for signed sessions, OAuth state, login request protection, and to recognize whether a browser has previously signed in. These cookies are not advertising cookies. Session records are designed to expire after seven days; signing out revokes the current server-side session. Short-lived OAuth and login-protection cookies support secure sign-in, while the returning-browser indicator may remain longer so the sign-in screen can use the appropriate wording.

6. Messages, Room, support, licences, and OS requests

Direct messages are visible to the relevant member and authorized YTrading roles. Room nicknames and Room posts are visible to signed-in Room participants and may be moderated. Member Room posts are pruned after about 14 days or when the member-message limit is reached; staff posts may remain until an authorized purge.

Support tickets and replies are visible to the member and authorized support or administrative roles. Licence, copy-status, and OS-request records are limited to the relevant member and authorized administrative roles. YTrading does not collect a payment card, bank account, or cryptocurrency payment through this application, and the public website does not execute trades.

The public Floor may show aggregated member signup counts by country. It does not publish member email addresses or individual account records.

7. Screenshot attachments currently unavailable

Screenshot attachments are currently unavailable. Text-only support remains available. The initial production service has no screenshot object-storage or scanning service. If attachments are introduced later, YTrading will update this policy before activation to explain the information, storage, scanning, access, and retention involved.

8. Service providers and infrastructure

Google provides the third-party identity service used by the production Google Sign-In flow. Cloudflare provides application hosting, network delivery, D1 database storage, security processing, and shared rate limiting. These providers process information as needed to deliver their services and under their own applicable terms and privacy commitments.

If a member follows an external broker or platform link, that third party receives the resulting request and applies its own privacy practices. YTrading does not send the member's Google profile data through those links.

YTrading does not use an advertising network or a separate marketing-analytics tracker in the application. The initial production design does not use Cloudflare R2 object storage.

9. When information may be disclosed

Information may be disclosed to the infrastructure providers described above when necessary to operate the service; to authorized people supporting or administering YTrading according to their roles; to comply with a valid legal obligation; or to protect users, YTrading, and the service from fraud, abuse, or security threats. YTrading does not sell personal information or Google user data and does not share it for unrelated marketing.

10. Data retention

YTrading keeps information while it is needed to operate accounts and requested features, protect the service, maintain accurate licence and request records, resolve support issues, and meet legitimate recordkeeping needs. Except for the session and member Room behavior described above, the current application does not apply a single fixed deletion period to every record. Security and audit records are designed to be append-only and may be kept when needed to preserve the integrity and security history of the service.

A verified deletion request is assessed against the account's operational, security, and recordkeeping needs. YTrading does not promise immediate or complete deletion where records must be retained for those purposes.

11. Security

YTrading uses access controls, role separation, signed and revocable sessions, step-up authentication for sensitive roles, request validation, rate limiting, restricted caching, and encrypted handling of authentication secrets. No online service can guarantee absolute security. Members should protect their Google account, device, and YTrading session and should report suspected account misuse through support.

12. User choices and privacy requests

Members can choose what they place in optional profile, Room, message, support, and request fields, can sign out to revoke the current session, and can stop using the service. To ask about account information, correction, privacy, or deletion, sign in and open a Help ticket at YTrading support. This is the implemented privacy-request path; YTrading does not publish a separate public email address or automated account-deletion form. Identity verification may be required before account information is changed or disclosed.

13. Changes to this policy

YTrading may update this policy when the application, providers, or data practices change. The date at the top shows the current version. Material changes to Google user-data use or a future attachment feature will be disclosed before the changed practice is activated.

14. Contact and support route

The supported contact route for privacy questions is the signed-in Help ticket path at /app/tickets. If a person does not yet have an account, the public sign-in path is /get-in. No private Owner contact information is published.