Home / Privacy
Last updated 26 August 2026. We collect what is needed to run an account and meet our obligations, and we would rather tell you plainly what that is.
The controller of your personal data is FDO Software LTD, registered in England & Wales under company number 17366935, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. For any question about this policy, or to exercise a right below, write to support@fundedportal.com.
Because we are established in the United Kingdom, our supervisory authority is the Information Commissioner's Office (ICO). Where we are required to appoint a representative in the European Union, the representative's name and address are published here and in the legal information. Either way, you can always complain to the supervisory authority of the country you live in — you are never required to go through a representative, or through us, to do so.
| Account data | Name, email, country, password (stored hashed) |
|---|---|
| Identity data | Identity document and verification result, where verification is required, together with the identity or passport number you enter and the details read from the document (name, date of birth, nationality, country of issue, document type). The image of the document is deleted shortly after the check — see how long we keep it below |
| Payment data | Transaction record and status. Card details are handled by the payment provider, not by us |
| Trading data | Orders, positions, equity history on your assessment account |
| Technical data | IP address, device and browser, sign-in events, security logs |
| Device data | A device fingerprint — a value derived from your browser and device configuration — read when you register, sign in and buy |
| Integrity data | Matches between accounts, risk flags, and the results of automated checks for prohibited practices |
| Screening data | Results of sanctions-list screening, carried out before a reward is paid |
| Payout data | The bank account or crypto wallet you ask us to pay to, billing details and invoices |
| Activity records | An audit trail of actions taken on your account, by you and by us |
| Support data | What you write to us, our replies, and notes our staff add to your record |
| Partner data | If you join our partner programme, the referrals attributed to you and the commission calculated on them |
We would rather list too much here than too little. If you find something we process that is not on this list, tell us — that is a defect in this page, not a detail.
We use service providers who process data on our behalf under contract. They may only use it to provide their service to us, and they may not use it for their own purposes.
| Hosting | Contabo GmbH (Germany), servers in France. Holds everything described above, because it hosts the application and its database. |
|---|---|
| Identity verification | Didit Identity Spain, S.L. (Barcelona, Spain) checks that your identity document is genuine, performs the liveness check, and compares your selfie against the portrait on the document. You present the document and the selfie on its own page; it returns the result together with the details read from the document — name, date of birth, nationality, country of issue, document type. It receives no payment, trading or account history data, and we deliberately do not collect your gender, marital status, place of birth or the video of the document capture. Processing takes place inside the European Economic Area. The accept-or-decline decision remains ours. In use since 25 August 2026. |
| Card payments | A third-party payment provider takes the card payment directly and performs its own identity checks. We never receive your card details. That provider is a controller in its own right for what it collects from you, under its own privacy policy. Card payments are not switched on at present. The provider is named in this row before the first card payment is taken, and this page is updated the same day. |
| Crypto payments | Where you pay in cryptocurrency, a payment processor receives the transaction — not your identity documents. Automated crypto payment is not switched on at present; the processor is named here before it is. Where you pay by transferring to an address we give you, the transaction is settled directly on the blockchain and no processor is involved. |
| Location lookup | When you register or buy, we resolve the country and region behind your network address to apply our restricted-jurisdiction list. That lookup is made by an outside service (currently ip-api.com, operated from outside the EEA), which receives your IP address and nothing else — no name, no account, no payment data. The answer is cached so the same address is not looked up repeatedly. The visitor count described further down does not use this service. |
| Email and SMS delivery | A delivery provider transmits account emails, and where phone verification is switched on, verification messages. It receives your address or number and the message content, nothing else. |
| Market data | Twelve Data supplies the prices the simulation runs on. It receives no personal data — prices flow to us, not your identity to them. |
We do not use an analytics provider, an advertising network or a session-recording tool, so none of them appears on this list. We count visits to the public website ourselves, on our own servers, and that measurement sends nothing to anyone — which is why it adds no name here. If either changes, the list changes first.
We do not sell personal data, and we do not share it with data brokers.
Your data is stored on servers in France, operated on our behalf by Contabo GmbH, a hosting provider established in Germany. Both are inside the European Economic Area, so the transfer from the United Kingdom — where we are established — relies on the UK's adequacy regulations for the EEA rather than on standard contractual clauses. Where a provider named above is outside the EEA, that specific transfer is covered by the UK International Data Transfer Agreement or the Addendum to the EU standard contractual clauses.
We keep data for as long as it is needed for the purpose it was collected for, or for as long as the law requires — whichever is longer. In practice:
| Account and trading records | While the account is open, then 6 years. This covers our accounting and tax obligations and the period in which a claim about the contract could still be brought. |
|---|---|
| Identity document images | 90 days after the verification decision. The scan of your passport or ID card is then deleted from our storage. We keep the result of the check rather than the picture: an image we no longer hold cannot be taken from us in a breach, and keeping it for years would not make the check any more provable. |
| Verification and screening records | 5 years after the relationship ends — what was checked, the outcome, who reviewed it and when, and the sanctions-screening result. This is the evidence that the check was carried out, and five years is the period anti-money-laundering practice sets for verification records. |
| Security logs | 12 months, unless a log is attached to an open investigation. |
| Device fingerprint records | 24 months from the last time the value was seen. See the cookie notice. |
| Support correspondence | 3 years from the last message in the thread. |
| Complaint files | 6 years from the final response. See complaints. |
| Marketing consent records | Until you withdraw consent, then 2 years as evidence that consent existed and when it ended. |
After the period ends the data is deleted or anonymised. Two things override the table: material attached to an open investigation, complaint or legal claim is kept until that ends, and anything we are ordered to preserve is preserved.
Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable form, and complain to a supervisory authority. Write to support@fundedportal.com and we will respond within the period the applicable law sets.
Some data we cannot delete on request — records we are legally required to retain, for example. Where that applies we will say so and explain why.
You can complain to us first, and we would rather you did. You can also complain to the Information Commissioner's Office whether or not you come to us first.
Some things here happen without a person looking at them. A limit breach ends an assessment the moment it is crossed. A sanctions-list match blocks a payout. A duplicate-account or fraud signal can suspend an account. That is deliberate — a rule you can only discover by breaking it is not a rule.
Automatic does not mean final. Where an automated decision affects your account you can ask for a person to review it, tell us why you think it is wrong, and get an explanation of what triggered it. Write to support@fundedportal.com or open a support request from your account panel and say you want a human review.
Two limits, stated honestly. Where a sanctions match is involved we may be unable to give you the details, because doing so can itself be unlawful. And where the trigger was a fraud-detection signal we will explain enough for you to answer it, without publishing a map of how to defeat the check.
We use cookies to keep you signed in and to remember display preferences such as light or dark theme, and we read a device fingerprint at registration, sign-in and purchase to detect duplicate accounts and payment fraud.
We do not use advertising or social-media tracking. There is no Google Analytics, no advertising pixel, no heat-mapping and no session recording, and nothing on this site reports your visit to a third party.
We do count visits to the public website, with our own measurement that writes nothing to your device. There is no cookie for it and no identifier that follows you: the key that stops one person being counted twice is derived from a secret that changes every day, so tomorrow the same browser is a different, unlinkable key. Your IP address is never stored for this count, and the country in it is read from a database on our own server rather than an outside service. (The separate restricted-jurisdiction check at registration and purchase does use an outside lookup — it is listed in the table above.) The cookie notice sets out exactly what is and is not recorded.
Because that measurement keeps no lasting identifier, it needs no consent banner. If we ever add an advertising pixel, a third-party analytics service or anything else that stores an identifier on your device, we will ask for your consent before switching it on, not after.
You can clear or block cookies in your browser, though signing in will stop working if you block the ones that carry your session.
This service is not for anyone under 18 and we do not knowingly collect their data.