1. Who is responsible
This installation is being prepared. The operator's legal name and contact details must be completed in Administration → Settings before opening to the public. We do not assume that the TradeVerdict brand is a legal entity.
2. What data we use and why
- Account: public name, email, password hash, account status and email confirmation, for registration, access and prevention of misuse.
- Reviews: platform, rating, title, account of events and experience date, to publish and moderate opinions. The public name accompanies the review; the email is not published.
- Administration: change logs and the responsible person's identifier, for traceability. The 2FA secret is stored encrypted.
- Security: sessions and attempt counters. The system hashes the network identifier used for access limits. The Apache server may maintain its own technical logs, whose configuration must be reviewed by the operator.
- Optional analytics: public pages visited, source, UTM campaign and a daily pseudonymous identifier, only with your permission.
- Requests: type, text, date and progress of requests relating to your data.
3. Grounds and choices
Data needed for accounts and publication is processed to provide the requested service and fulfil its terms. Proportionate security and moderation measures may rely on legitimate interest, subject to the controller's assessment. Legal obligations may require specific retention. Optional analytics depend on consent and can be disabled without preventing account use.
4. What is visible
Approved reviews, public names, ratings, experience dates and team replies are visible on the platform profile. The “Email verified” badge only indicates completion of email confirmation. It does not confirm legal identity, a relationship with a broker or an investment.
5. Sharing and providers
In the local version, the database and test mailbox stay on the operator's computer. Emails are not actually sent while local mode is active. If SMTP is configured, the recipient and content needed for confirmation or recovery are sent to the chosen provider. Production hosting, providers actually used and any international transfers must be identified and assessed before public opening.
Visiting a platform's official website via a link takes you to an independent service with its own privacy rules. We do not sell data or install advertising trackers in this version.
6. Retention and deletion
Accounts and reviews remain while needed for the service. Confirmation links expire after 24 hours and password recovery links after one hour. Analytics are retained for up to 90 days and cleaned when events arrive and by the maintenance command. Admin sessions expire after 30 minutes of inactivity and client sessions after two hours. Test mailbox messages are removed after seven days by the maintenance command, which should run daily. The operator must set retention periods for backups and server logs. Deletion requests are assessed against legal retention obligations.
7. How to exercise your rights
You may request confirmation and access, correction, anonymisation, restriction or deletion where applicable, information on sharing, portability under applicable rules, and withdrawal of consent. In My account → My data, download your account data and submit a request. You can also use the privacy contact above. Responding may require appropriate verification of the requester's identity.
For full information, see the Brazilian General Personal Data Protection Law and the channels of the ANPD.
8. Security and changes
We use password hashing, input validation, parameterised queries, form protection, separate sessions and administrator 2FA. No system is immune to incidents; the operator must keep the server and software updated and handle incidents according to applicable requirements. Material policy changes will receive a new version and be communicated where necessary.
Claimed profiles, reports and widgets
To verify businesses, we record the responsible account, official domain, request and DNS verification date. The domain and badge may appear publicly; the email and challenge code do not appear on the public profile. Reports and explanations help the team assess violations. Authors can see decision explanations in their accounts. Business replies and published reviews may appear in cookieless widgets on verified domains.
Google sign-in
If you choose Google, we receive your Google account identifier, verified email and name to create or access your reviewer account. We do not request your contacts, files or email messages, and do not store Google access tokens.