KiwiFX ("we", "us", "our") respects your privacy. This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and your rights regarding your data. This policy applies to all users of kiwifx.nz.
We are committed to complying with the New Zealand Privacy Act 2020 and its Information Privacy Principles.
| Data | Purpose | Basis |
|---|---|---|
| Username | Account identification and login | Required for service |
| Email address | Account verification, password recovery, notifications (if you opt in) | Optional, with consent |
| Password | Account security — stored as a salted SHA-256 hash, never in plain text | Required for service |
| Trade data | Journal entries, performance tracking, analytics — the core service you use KiwiFX for | Required for service |
| License key | Linking your EA or trading platform to your account | Required for EA features |
| MT5 account number | Binding your EA license to a specific trading account | Required for EA features |
| Notification preferences | Controlling which emails you receive | Your choice |
We do not collect your real name, physical address, phone number, payment card details (handled by our payment processor), trading account passwords, or broker credentials. We do not use tracking cookies, analytics cookies, or advertising cookies.
We use your information to provide and operate KiwiFX services, authenticate your account and protect against unauthorized access, send verification codes and account-related emails, display your trading performance and journal data, improve our services, and communicate updates if you opt in.
KiwiFX uses the following third-party services to operate. Your data may be processed by these services as necessary:
| Service | What it does | Data shared |
|---|---|---|
| Supabase | Database hosting (cloud, encrypted) | All account and trade data |
| Vercel | Website hosting and serverless functions | Request logs, IP addresses |
| Resend | Transactional email delivery | Email address, email content |
| TwelveData | Market data API for live prices | No personal data |
| Anthropic (Claude) | AI analysis feature | Trading pair and indicator data only — no personal data |
We carefully select providers with strong security practices. Data may be stored in regions outside New Zealand (primarily US and Asia-Pacific) as required by these services.
KiwiFX uses only essential cookies and local storage for session management (keeping you logged in), storing your display preferences (balance visibility, notification settings), and remembering your cookie consent choice.
We do not use analytics cookies, advertising cookies, or tracking pixels. No data is shared with ad networks.
We take reasonable steps to protect your information, including passwords stored as salted cryptographic hashes (SHA-256) and never in plain text, all connections encrypted via HTTPS/TLS, API endpoints protected by secret keys and authentication tokens, our GitHub repository being private, and regular security reviews.
No system is 100% secure. If you become aware of a security vulnerability, please contact us at support@kiwifx.nz.
Under the New Zealand Privacy Act 2020, you have the right to:
| Right | How to exercise it |
|---|---|
| Access your data | View your account info, trades, and journal in the app. For a full export, email us. |
| Correct your data | Update your email or password in Settings. |
| Delete your data | Delete your account in Settings → Danger Zone. This removes all your trades, journal entries, and personal data. |
| Withdraw consent | Unsubscribe from emails in Settings → Notifications, or click "unsubscribe" in any email. |
| Complain | If you believe we have breached your privacy, contact us first. You may also complain to the NZ Privacy Commissioner. |
We retain your data for as long as your account is active. When you delete your account, we remove your personal information, trade data, and journal entries. Some anonymized, non-personal data may be retained for service improvement. Backup copies are purged within 30 days of account deletion.
KiwiFX is not intended for anyone under 18 years of age. We do not knowingly collect information from minors. If we learn that we have collected data from someone under 18, we will delete it promptly.
KiwiFX is operated from New Zealand but available to users worldwide. By using our service, you consent to having your data processed in New Zealand and in the jurisdictions where our third-party services operate.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. For significant changes, we will notify you by email (if you have one registered) or by a notice on the platform.
For privacy-related questions, data requests, or concerns:
Email: support@kiwifx.nz
Website: kiwifx.nz