Privacy Policy
Last updated: June 2026
This policy explains what personal data CandySTX collects, how we use it, and your rights under UK GDPR. We aim to collect only what we need to run the platform.
1. Data we collect
- Account data — email and username, handled via our authentication provider (Supabase).
- Progress data — quiz attempts, Spot the Setup results, demo trades, XP, streaks, badges, and leaderboard stats.
- Payment data — subscription status and a Stripe customer ID. Card details are handled by Stripe; we never see or store your full card number.
- Technical data — basic logs and cookies needed to keep you signed in and to operate the service.
2. How we use it
To create and secure your account, deliver the product (quizzes, the Practice Floor, leaderboards, badges), process subscriptions, provide support, and improve the platform.
3. Cookies & analytics
We use essential cookies for authentication and session management — these are always on because the app cannot work without them. With your consent, we also use PostHog analytics cookies to understand how the product is used (e.g. page views and feature usage). When you first visit, a cookie banner lets you accept or declineanalytics; if you decline, no analytics cookies are set and PostHog is not loaded. You can change your mind by clearing your browser's site data. We do not sell your personal data.
4. Who we share data with
We share data only with the service providers needed to run CandySTX:
- Supabase — authentication and database hosting.
- Stripe — payment processing and subscription management.
- OANDA — practice market data used inside the Practice Floor.
5. Data retention
We keep your data while your account is active. If you close your account, we delete or anonymise your personal data except where we must keep records for legal or accounting reasons.
6. Your rights (UK GDPR)
You have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. You can also hide your profile from leaderboards. To exercise any of these rights, contact us.
7. Contact
For any privacy request or question, email hello@candystx.com.