Privacy Policy

Last updated: October 5, 2026

This policy explains how we collect, use, share and protect your personal data, in line with Thailand's Personal Data Protection Act (PDPA) and, for users in the EU and UK, the GDPR.

1. Who is responsible

the operator of LearnTrader (a sole trader based in Thailand) (“we”) is the data controller.

Privacy contact: [email protected]

The merchant name verified with Stripe appears on your receipt, and we will give you the controller's full details by email straight away on request.

2. What we collect

Account data: your email address and language, when you sign up or buy.

If you continue with Google: your Google account ID and the email address Google has verified, nothing else. We never receive your password and never ask for access to Gmail, contacts or other Google data.

Sign-in data: how you signed in and when each session started and ended, so that signing out really ends a session.

Purchase data from Stripe: the email you paid with, transaction ID, amount, currency, date and refund status. We never receive your card number or card details.

Learning data: lessons you have finished (saved to your account when you are signed in).

Technical and security data: IP address, browser type and server request logs, used to rate-limit repeated requests, block bots and fix errors.

Aggregate visit statistics through Cloudflare Web Analytics, which uses no cookies and does not identify you.

We do not collect sensitive data such as health, religious or biometric data.

3. Why we use it, and our legal bases

To create your account, give you the content you bought and save your progress (contract).

To confirm who you are when you sign in, and to give PRO to the account that proves it controls the purchase email (contract).

To send sign-in links, email confirmations, purchase confirmations and important account messages (contract).

To keep the service secure, prevent fraud and abuse, and improve it from aggregate statistics (legitimate interests).

To keep accounting and tax records and respond to authorities where the law requires (legal obligation).

We do not send marketing email unless you give separate consent, and you can unsubscribe at any time.

Without your email address we cannot create an account or deliver what you bought.

4. Who receives your data

Processors acting on our behalf under data-protection terms: Stripe (payments), Google (sending our email through Gmail), Resend (backup email delivery) and Cloudflare (hosting, database, security and visit statistics).

When you choose “Continue with Google”, Google confirms who you are and knows that you signed in to LearnTrader, under Google's own privacy policy.

Public authorities, only where the law requires it.

We never sell, rent or trade your personal data, and we do not use it for tracking-based advertising.

5. International transfers

These providers may process data outside your country, for example in the United States. We only transfer what is necessary, and the providers use legally recognised safeguards such as Standard Contractual Clauses, as required by Section 29 of the PDPA and the GDPR.

6. How long we keep data

Account and progress data: while your account is active or until you ask us to delete it. Accounts with no purchase and no activity for 3 years are deleted.

Purchase records: as long as accounting and tax law requires (no more than 10 years).

Email links expire after 30 minutes and are deleted within a day; rate-limit records are deleted within a day.

Sign-in sessions last up to 30 days and are deleted within a day after they expire or you sign out. A linked Google account is kept with your account.

Server request logs: no more than 30 days.

7. Your rights

You can ask to access and copy, correct, delete or restrict your data, object to processing, port your data, and withdraw consent (withdrawal does not affect earlier processing).

Email [email protected] from the address on your account. We reply within 30 days, free of charge.

You may complain to Thailand's Personal Data Protection Committee (PDPC) or to the data-protection authority in your country.

8. Security

We use encrypted connections (HTTPS), digitally signed sign-in cookies, hashed email links, Google sign-in verified to the OpenID Connect standard, restricted access to data, and we never store card details.

If a data breach is likely to put your rights at risk, we will notify the relevant authority within 72 hours as the law requires, and tell you without undue delay where the risk is high.

9. Children

LearnTrader is not intended for anyone under 18. We do not knowingly collect their data, and we delete it if we find it.

10. Cookies

We only use essential cookies. See the Cookie Policy.

11. Changes to this policy

We will announce material changes on the site or by email before they take effect. The date of the latest update is shown above.