Privacy Policy
Last updated 9 August 2026.
This is a list of what we actually store, not a list of what we might one day like to. There is no analytics, no advertising, no tracking pixel and no third party watching you read this page.
One thing on that list does touch advertising, so it is said plainly here rather than left for you to find further down: we buy ads on Google, and a link you clicked in one of them may have carried an identifier that Google itself put in it. We keep that identifier, and we tell Google about it only if you later pay for a subscription — so that we can see which ads are worth paying for. It is a string of characters Google already knows, handed back to Google, once. It still means no pixel, no analytics and no third-party code running on this page.
We also buy ads on Reddit, and there the arrangement is simpler still: the
link carries a short campaign label — ours look like
src=reddit-eurusd-v1 — we keep it the same way, and we tell
Reddit nothing at all: not the label, not the click, not the purchase. Nothing
about you ever goes to Reddit. Anyone can put such a label on a link to us, so
what we keep is simply the label that was in the link you followed; it names
an ad, never you.
Who is responsible
Turnmarks is the controller of your personal data. Contact: support@turnmarks.com.
We are in Switzerland, so the Swiss Federal Act on Data Protection (FADP) applies. If you are in the EU or EEA, the GDPR applies as well, and this policy is written to satisfy both.
What we store, and why
| Data | Why | Basis |
|---|---|---|
| Email address | It is your login. Also used for verification, password reset and service notices. | Contract |
| Password, stored only as a bcrypt hash | To check your login. We cannot read your password and cannot tell it to you if you forget it. | Contract |
| Account creation time, email-verified flag, one-time verification and password-reset tokens | To run verification and reset, both of which expire. | Contract |
| Subscription status and expiry, Whop membership id and licence key | To know whether your plan is free or paid. | Contract |
| If you connect Telegram: your Telegram chat id, your Telegram username, when you linked it, and which symbols you ticked | To send the alerts you asked for, to the right chat, for the right instruments. | Consent |
| If you connect Discord: your Discord user id, your Discord username, when you linked it, which symbols you ticked, and the id of the direct message channel Discord opened between you and the bot | To send the alerts you asked for, to the right person, for the right instruments. The channel id is kept so that every alert does not have to ask Discord to open the conversation again. | Consent |
| A record of which alert was sent to you, kept 30 days | So the same marker is not sent to you twice. | Contract |
| The IP address you registered from, kept 48 hours | To count registrations per address and stop bulk sign-ups. | Legitimate interest |
If you arrived from one of our Google ads: the click identifier Google
added to the link (gclid, or wbraid /
gbraid on an iPhone), which of those it was, and the moment
your browser saw it |
To find out which ads bring people who actually subscribe, so we stop paying for the ones that do not. It is sent to Google only if you buy, and only as one line of a file we upload by hand: that identifier, the date, the amount. Your email address is not in it and neither is anything else about you. | Legitimate interest |
If the link you followed carried a campaign label
(src=…) — ours are on our Reddit ads —
that label, and the moment your browser saw it |
The same question — which ads bring people who subscribe — answered entirely in-house. The label names an ad post, not you, and it is never sent to Reddit or to anyone else. | Legitimate interest |
| Your IP address while you make requests | Rate limiting, which happens in memory and is not stored. | Legitimate interest |
| A web server log line: your IP address, the time, what was requested and your browser's user-agent string | The ordinary record any web server keeps, used to diagnose faults and notice abuse. Kept about two weeks, then rotated away. | Legitimate interest |
That is the whole list. We do not ask for your name, your address, your phone number or your date of birth, and we do not build a profile of you. We never see your card details — those go to the payment provider below and never touch our servers.
What is stored in your browser
We use no cookies. The application keeps three things in your browser's
localStorage: your sign-in token, and the instrument and timeframe
you last looked at, so the chart opens where you left it. Signing out or
clearing your browser data removes them.
If you reached us from one of our ads, there is a fourth: the Google click identifier or the Reddit campaign label described above. It is written by a few lines of our own code on the page — nothing is loaded from anywhere and nothing is sent while you read — and it is discarded automatically after 90 days, which for the Google identifier is as long as Google itself will count it. Registering an account hands it to us and clears it from your browser. Clearing your browser data removes it too, and nothing breaks.
The application loads Cloudflare Turnstile, a bot check used on the sign-in and registration forms. It is the only third-party code that runs in your browser here. On a wide screen the front page and each instrument page also embed the live chart, which is the application, so Cloudflare sees the request from those pages too. The per-instrument trading-hours pages embed nothing and load nothing from anywhere.
Who else processes your data
We use a small number of service providers. Each gets only what it needs to do its job, and none of them is allowed to use your data for their own purposes.
- Whop Inc. (United States) — payments, as merchant of record. They take your payment details directly; we receive only your membership status. Their own privacy policy governs what they hold.
- Contabo GmbH — hosting. Our server, and therefore the database, is located in France.
- Mailgun / Sinch (EU region) — sending verification, password-reset and notice emails. They see your email address and the contents of those messages.
- Telegram — delivering alerts, if and only if you connect it.
- Discord Netherlands BV (Schiphol, Netherlands) — delivering alerts, if and only if you connect it. Discord names that entity as the controller for its users in the EEA, the UK and Switzerland, and Discord, Inc. (San Francisco, United States) everywhere else. Connecting also means joining our Discord server, because Discord only lets a bot message someone it shares a server with; your membership of it is visible to that server's other members, as membership of any Discord server is.
- Cloudflare, Inc. (United States) — the Turnstile bot check on the sign-in and registration forms.
- Google Ireland Ltd. — advertising. If you bought a subscription after clicking one of our ads, we tell Google that the click it labelled turned into a purchase, with the date and the amount. That is the only thing that ever goes to Google, it only happens after a purchase, and Google runs no code on this site.
Reddit is deliberately not on that list. We advertise there, but nothing is ever sent back to Reddit — no click, no registration, no purchase. The campaign label described above stays in our own database, full stop.
Whop and Cloudflare are in the United States, so using them involves a transfer of data outside Switzerland and the EEA. Those transfers rest on the safeguards in each provider's own data-processing terms, including the EU standard contractual clauses where they apply.
We do not sell your data, and we never will. We would disclose it to an authority only where Swiss law obliges us to.
How long we keep it
- Account data — for as long as your account exists.
- Telegram and Discord links and symbol choices — until you disconnect that channel or delete the account.
- Alert delivery records — 30 days, then deleted automatically.
- Registration IP addresses — 48 hours, then deleted automatically.
- The ad click identifier or campaign label — 90 days in your browser, whether or not you ever register. On your account it is kept, along with the record of the purchase it led to, for as long as the account exists, and it goes when the account goes.
Deleting your account removes your email, password hash, subscription record, Telegram and Discord links, symbol choices and delivery records immediately and permanently, along with the ad click identifier and the conversion record if there was one. Leaving our Discord server is separate and yours to do: your membership of it is held by Discord, not by us.
One deliberate exception: the 48-hour registration-IP counter survives an account deletion, because otherwise deleting an account would hand a bot a fresh allowance. Those rows contain an IP address and a timestamp, nothing else, and they expire on their own within two days.
Your rights
You can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything wrong;
- delete it — though the account page does this yourself, immediately;
- restrict or object to a particular use;
- hand it over in a portable form;
- withdraw your consent to alerts, which you can also do yourself: press
Disconnect on the account page, or send
/stopto the Telegram bot or/unlinkto the Discord one.
Write to support@turnmarks.com. We answer within 30 days and we do not charge for it. We may need to confirm you control the account's email address first — otherwise the right to a copy of your data becomes a way for someone else to obtain it.
If you think we have handled your data badly, you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or, in the EU or EEA, to your national supervisory authority.
Security
Everything travels over HTTPS. Passwords are stored as bcrypt hashes, never in a readable form. Sign-in tokens carry a version number so that changing your password or resetting it invalidates every other session immediately. Registration, sign-in and password-reset are rate limited per IP address, and the forms are behind a bot check.
No system is perfect. If a breach affects your personal data and puts you at high risk, we will tell you and the relevant authority, as the law requires.
Children
The Service is not for anyone under 18, and we do not knowingly hold data about children.
Changes
If this policy changes, the date at the top changes with it. Anything that materially affects how we use data you have already given us will be emailed to the address on your account.