Privacy Policy

September 2026

This policy explains what Birds Eye Trading collects when you use our website and our NinjaTrader add-on, why we collect it, how long we retain it, and what you can ask us to do with it.

Birds Eye Trading LLC, a Missouri limited liability company, 8301 State Line Rd. Ste 220 #3953, Kansas City, MO 64114, is the controller of this information. Enquiries and requests go to [email protected].

Summary

  • Birds Eye Trading operates no analytics, advertising, tracking or profiling of its own. We do not measure how you arrived at the site or where you go afterwards. We do keep error logs and overall performance counts so that we can keep the site working; they carry an account number at most, and never an IP address, email address or name.
  • We have no access to your trading. Your broker, balances, positions, orders and charts remain yours; the add-on does not transmit them to us.
  • We do not see or store card numbers. Payments are processed by Stripe.
  • We do not sell, rent or trade personal information, and we receive no payment from anyone for access to our customers.
  • Accounts are not deleted on the spot. An account you ask us to close, or one with no plan that nobody has signed in to for ninety days, becomes inactive, and is deleted with its support requests and screenshots ninety days later unless you sign in first. We email a warning before that happens.

These statements describe our own practices. The companies listed under Service providers run their own platforms — hosting, the network the site is reached through, payments, email, community and logging — and collect technical information in the course of doing so, under their own privacy policies. We do not control that, and we do not receive analytics or visitor data from them about you, except as described for Cloudflare below.

What we hold, and why

Account details

An email address, which also identifies the account, and a hashed password — a one-way transformation from which the password itself cannot be recovered. A name, if you choose to provide one. The date you last signed in, and whether the account is active or inactive, as described under Inactive accounts. That is the entire account record.

Machine ID

A licence is issued for a single computer, and the machine ID is how the software verifies that the copy running is the copy you purchased. It is the identifier NinjaTrader displays under Help → About: an opaque value that discloses nothing about your identity, location, browsing or trading activity.

When a licence is moved to another computer we record the change — the date, the previous identifier and the new one — so that the transfer allowance can be applied. We retain the twenty-five most recent changes per account.

Licence and plan

Your licence key, the plan you hold, its renewal or expiry date, and the date the software last validated. Stripe holds your billing address, card details and invoices under its own privacy policy; we retain only the record of what was purchased.

Security record

Sign-in failures, changes to your email address (with the old and new address), licence and machine ID changes, Discord connections, plan changes and administrative actions taken by our staff, each recorded with the IP address that made the request. We use it to investigate account disputes and to identify licence sharing. For an account that has never made a purchase, entries are deleted automatically after ninety days. For an account that has, they are kept for as long as the account exists, because payment disputes and chargebacks can arise long after the event, and are deleted ninety days after the account itself is deleted.

Our licence server additionally retains, for a matter of minutes, the IP addresses making validation requests, in order to rate-limit excessive automated traffic. Standard web server logs are maintained by our host in the ordinary course.

Support requests

When you contact us through the support form we keep your message, the topic you chose, the address to reply to, and the replies in either direction. If you are signed in, the request also carries your account number, plan, machine ID, Stripe subscription reference and whether your email address is confirmed, so that we need not ask you for them. A copy is emailed to our support inbox. For customers on a paid plan, the request is also posted, without your email address, to a channel on our Discord server that only our staff and moderators can see.

You may attach PNG, JPEG, GIF or WebP images and CSV spreadsheets, up to 5MB each and five per request; nothing else is accepted. Images are rebuilt from their pixels before they are stored, so the location, camera details and anything else carried in the original file are discarded, and spreadsheets are rebuilt from their cells. Attachments are kept outside the public website, and only you and our staff can view them. If a file cannot be accepted, the page tells you why and your message is still delivered.

Discord

Connecting a Discord account is optional. If you connect one from the Discord tab in your settings, Discord tells us your Discord user ID and display name, and we record them with the date you connected. We ask Discord to confirm who you are and nothing else — not your email address, your servers or your messages — and we give up the access Discord grants as soon as we have read those details.

We use the ID for one purpose: to give your Discord account the Member role on our server while you hold a paid plan, and to remove it when you no longer do. We check this daily. We email you whenever a Discord account is connected to, or disconnected from, your account. Disconnecting removes the stored ID and name and the Member role; the security record keeps the fact of the connection, with the ID, for the period described above.

When a paid plan starts or ends, a notice with your account number, plan, machine ID and subscription reference is posted to the same staff channel as support requests.

If you raise a support request inside our Discord server, we keep your Discord username and user ID with the message and any screenshots. Those requests are not linked to a website account, so to have one deleted, email us.

Our Discord server is moderated automatically. Discord’s own filter checks each message as it is sent and blocks links in the conversation channels, promises of trading results, and offensive language. A blocked message is not posted, you are told why, and our moderators see a copy of it in a channel only staff can read. Members cannot upload files in the community channels. In the members’ chat channel only images may be shared, so our website checks new messages there about once a minute and removes any message carrying a file that is not an image. It tells you in the channel, and shows our moderators, in that staff-only channel, who posted it, the file’s name and the start of the message. To tell an image from another kind of file it reads the first few bytes of the file. The website does not store the messages it checks; it keeps only a marker of the last message it has looked at in each channel. Everything posted automatically to our staff-only channels — the notices about support requests and plan changes, and the moderation reports — is deleted from Discord after ninety days.

Error logs and performance counts

To find and fix faults, the website records warnings, errors and crashes, and counts how many requests it serves and how long they take. This is stored for us by Grafana Labs. Before anything leaves our server, IP addresses, email addresses, names, Discord identifiers, machine IDs, licence keys and passwords are removed; what remains is the error itself, the address of the page without any query, and, where relevant, your account number. The counts are totals, such as requests per minute or members per plan, and describe no individual. If the site crashes, a summary of the error, with no personal information, is posted to our staff channel on Discord.

Cookies

We set only the cookies the site requires in order to function: one that keeps you signed in, one that identifies the account confirming an email address, one used by our caching layer to ensure a signed-in visitor is never served another visitor’s page, and, only while you connect a Discord account, one that makes sure Discord’s reply comes back to the browser that started the connection, which expires after fifteen minutes. Your browser may also retain minor preferences locally, such as which panel was last open. We set no advertising or tracking cookies, and therefore display no consent banner. Cloudflare sets no cookie on an ordinary visit; if it has to check that a visitor is not an automated attack, it may set one short-lived cookie so as not to check again, used for nothing else.

Service providers

We disclose information to the following, each for a single purpose:

  • Stripe — payment processing and subscription renewals.
  • Hostinger — hosting of the site and its database, and the newsletter tooling built into the platform. Under its data processing addendum Hostinger acts as a processor on our instructions; we remain the controller.
  • OVHcloud — a server of ours in the United States that keeps a second copy of the nightly backups of our database, so the site can be restored if our main host loses it. Under its data processing agreement OVHcloud acts as a processor on our instructions; we remain the controller. See OVHcloud’s privacy policy.
  • Cloudflare — the network the site is reached through, and the domain’s DNS. Each visit passes through Cloudflare on its way to our server, so it receives your IP address, your browser’s details and what you send the site, including anything you type into a form, and uses them to deliver the page and to screen out attacks. If a page fails to load, your browser may report the failure to Cloudflare. Cloudflare shows us overall traffic figures that describe no individual, and the details of requests it blocked as suspected attacks, including their IP address. Under its data processing addendum Cloudflare acts as a processor on our instructions; we remain the controller. See Cloudflare’s privacy policy.
  • Google — delivery of account email through Google Workspace, our support inbox, and the two typefaces the site uses, which are served by Google Fonts. Google’s font servers therefore receive the IP address of anyone loading a page.
  • Discord — connecting your Discord account and managing the Member role, support requests raised in our server, the automatic moderation of our server, and the staff notices about support requests and plan changes described above. We never send Discord your email address. See Discord’s privacy policy.
  • Grafana Labs — storage of error logs and performance counts, with personal information removed before they are sent. See Grafana Labs’ privacy policy.
  • Public authorities, where disclosure is required by law. Our host requires formal legal process — a subpoena, court order or search warrant — before releasing subscriber information to law enforcement, and undertakes to notify us unless it is prohibited from doing so.

Each processes information under its own privacy policy and its own terms, and each engages sub-processors of its own; Hostinger’s are listed in the addendum linked above.

Where information is held

The website, its database, the backups of it and our error logs are hosted in the United States. Cloudflare, Stripe, Google and Discord operate internationally and process information in the locations set out in their own policies; Cloudflare handles each visit in whichever of its data centres is nearest the visitor.

If you are in the European Economic Area, the United Kingdom or Switzerland, using this site therefore involves a transfer of your information outside your own jurisdiction. Those transfers rely on the European Commission’s standard contractual clauses, and on the UK International Data Transfer Addendum where the transfer originates in the United Kingdom.

Email

We send the email required to operate your account: address confirmation, licence details, receipts, password resets, and the warning before an inactive account is deleted. Marketing email is sent only to those who have requested it, and each such message carries an unsubscribe link. Unsubscribing does not affect the account email described above.

Inactive accounts

An account with no current plan that nobody has signed in to for ninety days is marked inactive. So is an account you ask us to close. An inactive account is kept as it is, but it no longer appears in our staff’s list of members.

Sixty days after an account becomes inactive, we email a warning to its address. Ninety days after it became inactive, and never sooner than thirty days after that warning was sent, the account is deleted permanently, together with its support requests, their screenshots and any Discord connection. If you sign in at any point before then, the account becomes active again and nothing is deleted.

Accounts with a current plan are never marked inactive; for an account whose plan has ended, the ninety days begin when the plan ends. If you would rather your account were deleted straight away instead of waiting, tell us and we will delete it.

Retention

  • Account, licence and machine ID: for the life of the account.
  • Inactive accounts: deleted ninety days after becoming inactive, and at least thirty days after the warning email, unless you sign in first.
  • Machine ID changes: the twenty-five most recent.
  • Security record: ninety days; for an account that has made a purchase, for the life of the account and ninety days after it is deleted.
  • Support requests and their screenshots: for the life of the account, and deleted with it. Requests raised in Discord: until you ask us to delete them.
  • Discord connection: until you disconnect it or the account is deleted.
  • Staff notices and moderation reports the website, its bot or Discord’s filter posts to our staff-only Discord channels: ninety days.
  • Error logs: ninety days.
  • Backups of the database: fourteen days with our host, and thirty days in the copy kept with OVHcloud. Something deleted from the site leaves the backups when the last one taken before the deletion expires.
  • Rate-limiting records: minutes.
  • Invoices: retained by Stripe for seven years as tax and accounting rules require. This is the one category a deletion request cannot reach.

Your rights

You may change your email address, your name and your registered machine ID from your account page at any time, connect or disconnect a Discord account from the Discord tab, and change your billing details through the Stripe portal linked from your Plan page. On request we will provide a copy of the information we hold about you, correct anything inaccurate, or delete your account and the personal data attached to it — straight away if you ask, rather than after the inactive period. We respond within thirty days.

Depending on where you live, these rights may also be conferred by law — the GDPR and UK GDPR in the EU, the UK and Switzerland; the CCPA and CPRA in California; comparable statutes in other US states — covering access, correction, erasure, portability, objection, and the right to complain to your data protection authority. As we neither sell nor share personal information for advertising, there is no opt-out to exercise in that respect. In every case the route is the same: email [email protected].

Please note that deleting your account terminates your licence and does not refund an active plan. See our Terms & Conditions.

Children

This service is not intended for anyone under 18, and we do not knowingly collect information from children. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. The date at the top records when it last changed, and we will give notice of material changes by email or on the website. Questions and complaints: [email protected].