Privacy notice
Version 2026.07-1 · effective 01 Jul 2026
What personal data LotsBack collects, why it holds it, who it is shared with, and the rights you have over it.
01What LotsBack collects
Only what the service needs:
- Account data: your email address, display name, country and the timestamps of your sign-ins.
- Trading account data: the broker, platform, login identifier and account type of each account you connect. Never a credential that can place a trade or move money.
- Trading activity: the closed positions read from your connected accounts — instrument, direction, volume, open and close time and price, and any commission the broker reports.
- Cashback and payout data: the lines derived from your positions, their state history, your payout destinations and the payouts made to them.
- Support data: messages you send, and the notifications LotsBack sent you.
02Why LotsBack holds it
To price cashback from published broker programmes, to verify it against broker reports, to pay it out, to meet legal and anti-fraud obligations, and to answer your support requests.
LotsBack does not sell personal data and does not use your trading activity for advertising.
03Who it is shared with
Your broker, to attribute your account and to verify the lines it produced. The payout provider, to make a payout you requested — the destination address, asset, network and amount. Infrastructure providers that host the database, send email and monitor errors, under contract and on instruction only.
Where the law requires it, to a regulator or law-enforcement body. Where that happens, LotsBack records it in its audit log.
04How long it is kept
Account, cashback, ledger and payout records are kept for as long as the law requires financial records to be retained, and then deleted. Support messages are kept for two years. Sign-in events are kept for twelve months.
Ledger and audit records are append-only: they cannot be edited, which is why a correction is always a new line rather than a change to an old one.
05Your rights
You can ask for a copy of your data, ask for an inaccuracy to be corrected, ask for deletion where no retention obligation applies, and object to processing that is not necessary for the service. Write to [email protected].
You can close your account from Settings at any time. Closing it stops new lines being created; records LotsBack must retain are kept for their retention period and then deleted.
06Security
Access to personal data is restricted by role and logged. Money is only ever written by server-side commands that record who acted and why. Two-factor authentication is required before a payout destination can be added or a withdrawal requested.
07Changes to this notice
A change produces a new version id and a new effective date, published here. Material changes are notified in the application before they take effect.