SightTrade logoSightTrade

Privacy Policy

Last updated: July 27, 2026

1. Introduction

This Privacy Policy explains how SightTrade ("we", "us", or "our"), available at sight-trade.com, collects, uses, shares, and protects information in connection with the website and tools we provide (the "Service"). It also describes your rights under the EU and UK General Data Protection Regulation (together, the "GDPR") and how to exercise them. By using the Service, you acknowledge the practices described in this Policy.

2. Privacy at a Glance

SightTrade is designed to be privacy-first. In short:

  • Your eToro account statement is parsed entirely within your browser and is never uploaded to, stored on, or accessible by our servers.
  • You can use the core statement-analysis features without creating an account.
  • If you choose to sign in, we store your email address and your dashboard preferences so your setup follows you across devices.
  • We use PostHog for privacy-conscious, aggregate usage analytics and Sentry for error and performance monitoring.
  • We do not sell your personal data and do not use it for advertising.

3. Who We Are (Data Controller)

The data controller responsible for the personal data described in this Policy is Popovici Daniel, a private individual based in Arad, Romania. If you have any questions or wish to exercise your rights, you can contact the controller at info@sight-trade.com.

4. Your eToro Statement Data (Processed Locally)

When you upload an eToro account statement (.xlsx), the file is read and parsed locally in your browser. The contents — including your trades, positions, balances, deposits, withdrawals, fees, and other financial details — remain on your device. This data may be cached in your browser's storage (for example, in IndexedDB) so it persists between page reloads. It is never transmitted to us, and we cannot access it. You can delete it at any time using the in-app remove option or by clearing your browser storage.

5. Information We Collect

Beyond the statement data described above (which we never receive), we process the following limited categories of information:

  • Account information (only if you sign in): your email address and, if you sign in with Google, the name and profile image Google provides. We also store the authentication records and tokens needed to keep you signed in.
  • Dashboard preferences (only if you sign in): the arrangement and visibility of the cards on your dashboard, so your customized layout is saved to your account.
  • Usage and analytics data: pages viewed, navigation events, and feature interactions (such as uploading, replacing, or clearing a statement), together with technical details like browser and device type, approximate region derived from your IP address, and referring pages.
  • Error, performance, and diagnostic data: error messages and stack traces, application logs, performance timings, and related technical and browser information used to detect and fix problems.

6. Cookies, Local Storage, and Similar Technologies

We and our providers use cookies and similar browser storage for the following purposes:

  • Strictly necessary / authentication cookies: set by our authentication system to keep you signed in and to protect against cross-site request forgery. These are required for the account features to work.
  • Analytics cookies and storage: set by PostHog to measure aggregate usage. These may include an anonymous device or session identifier.
  • Preference storage: your selected theme (light or dark) is stored in your browser's local storage and is not sent to us.

6a. Managing Cookies

You can control or delete cookies through your browser settings; disabling some cookies may affect account functionality. Where required by applicable law, we will seek your consent before setting non-essential (analytics) cookies, and you may withdraw that consent at any time.

7. How We Use Information

We use the information described above for the following purposes:

  • To provide, operate, and maintain the Service.
  • To authenticate you and keep you securely signed in, if you create an account.
  • To save and restore your dashboard preferences, if you create an account.
  • To understand aggregate usage and improve features and usability.
  • To detect, investigate, and fix errors, security issues, and performance problems.
  • To communicate with you where necessary, for example to send sign-in links.
  • To comply with legal obligations and to enforce our Terms.

8. Legal Bases for Processing (GDPR)

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)): to provide the account features you request, such as authentication and saving your dashboard layout.
  • Legitimate interests (Art. 6(1)(f)): to operate, secure, analyze, and improve the Service, including error monitoring and aggregate analytics, balanced against your rights and freedoms.
  • Consent (Art. 6(1)(a)): where required, for non-essential analytics cookies and similar technologies. You may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)): where processing is necessary to comply with applicable law.

9. Analytics (PostHog)

We use PostHog to understand how the Service is used in aggregate. We have configured PostHog to minimize data collection: automatic capture of on-page content is disabled, and we do not send the contents of your statement or any financial values as event properties. PostHog processes usage events and technical identifiers as described above and may process this data on servers located in the United States.

10. Error and Performance Monitoring (Sentry)

We use Sentry to capture errors, application logs, and performance data so we can diagnose and fix problems. We have configured Sentry not to attach your IP address or request bodies to events. Because diagnostic data (such as an error message or stack trace) can occasionally contain incidental personal data, we limit and, where feasible, redact such information. Sentry may process this data on servers located in the United States.

11. Accounts and Authentication

Creating an account is optional. You can sign in with a one-time link sent to your email address ("magic link") or with Google. When you sign in, we store your email address (and, for Google sign-in, the name, profile image, and authentication tokens returned by Google) in our database in order to authenticate you and to save your dashboard preferences. You can ask us to delete your account and its associated data at any time.

12. Service Providers and International Transfers

We share limited personal data with trusted service providers ("processors") who act on our behalf and only on our instructions. These currently include:

  • Supabase — managed database hosting for account and dashboard-preference data.
  • PostHog — product analytics.
  • Sentry — error and performance monitoring.
  • Google — authentication, if you choose to sign in with Google.
  • Zoho — delivery of sign-in (magic link) emails.
  • Vercel — serving the application.

13. Data Retention

We keep personal data only for as long as necessary:

  • Statement data: stored only in your browser until you remove it or clear your browser storage; we never hold it.
  • Account data: retained while your account is active and deleted or anonymized within a reasonable period after you request deletion or your account becomes inactive.
  • Dashboard preferences: retained with your account and deleted when your account is deleted.
  • Analytics and diagnostic data: retained only as long as necessary for the purposes described, in line with our providers' retention settings, then deleted or aggregated.

14. Data Security

We use reasonable technical and organizational measures — including encryption in transit, access controls, and reputable infrastructure providers — to protect personal data. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. Because your statement is processed on your device, you are responsible for maintaining the security of the device and browser you use.

15. Your Privacy Rights

Depending on your location, you have the following rights regarding your personal data:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your data (the 'right to be forgotten').
  • Restriction — ask us to limit processing in certain circumstances.
  • Objection — object to processing based on our legitimate interests.
  • Portability — receive your data in a structured, commonly used, machine-readable format.
  • Withdraw consent — where processing is based on consent, withdraw it at any time.

16. Automated Decision-Making

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects concerning you.

17. Children's Privacy

The Service is not directed to children under the age of 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

18. Third-Party Services and eToro

SightTrade is not affiliated with, endorsed by, or connected to eToro. This Policy does not apply to eToro or any other third-party websites or services, which have their own privacy policies. We encourage you to review the privacy policies of any third parties whose services you use.

19. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above. Your continued use of the Service after changes take effect constitutes your acceptance of the revised Policy.

20. Contact

If you have any questions about this Privacy Policy or our data practices, or to exercise your rights, please contact us at info@sight-trade.com.