Privacy Policy
Last updated: April 2026
1. Data Controller
NakedPnL, operated from Paris, France, is the data controller responsible for the processing of your personal data as described in this Privacy Policy. For any privacy-related inquiries, contact us at privacy@nakedpnl.com.
2. Data We Collect
Account Data
When you create an account, we collect your email address and, if provided, your display name and username. Authentication is handled via passwordless magic links.
Trader Verification Data
When you request verification, we collect the data necessary to verify your performance claims, which may include: fund name, entity type, AUM range, performance figures, brokerage account identifiers (read-only API credentials), and supporting documents such as account statements or SEC filing references.
Usage Data
We automatically collect technical information when you use the Service, including IP address, browser type, operating system, pages visited, time spent, and referring URL. This data is collected through server logs and essential cookies.
Payment Data
Payments are processed by Stripe. NakedPnL does not store credit card numbers or full payment details. We receive from Stripe: a customer identifier, subscription status, payment amounts, and billing dates. Stripe’s privacy policy governs the processing of your payment information.
Cookies
We use strictly necessary cookies for session management and authentication, and a functional cookie for theme preference. We do not use marketing, advertising, or third-party tracking cookies. See our Cookie Policy for details.
3. Legal Bases for Processing (GDPR Art. 6)
| Processing Activity | Legal Basis |
|---|---|
| Account creation and authentication | Performance of contract (Art. 6(1)(b)) |
| Verification of performance data | Performance of contract (Art. 6(1)(b)) |
| Payment processing via Stripe | Performance of contract (Art. 6(1)(b)) |
| Usage analytics and service improvement | Legitimate interest (Art. 6(1)(f)) |
| Security, fraud prevention, and abuse detection | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance and regulatory obligations | Legal obligation (Art. 6(1)(c)) |
| Marketing communications (if opted in) | Consent (Art. 6(1)(a)) |
4. Data Sharing
We do not sell, rent, or trade your personal data to third parties. We share data only with the following categories of service providers, solely for the purposes described in this policy:
- Stripe: Payment processing. Stripe receives billing information necessary to process subscription payments.
- Vercel: Hosting and infrastructure. Vercel processes server logs that may include IP addresses and request metadata.
- Exchange and brokerage APIs: When you connect a brokerage account for Tier 2 verification, we send read-only API requests to the relevant provider to retrieve performance data.
We may also disclose data when required by law, court order, or governmental authority, or to protect the rights, property, or safety of NakedPnL, our users, or the public.
5. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, where our hosting provider (Vercel) and payment processor (Stripe) operate. Such transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, the EU-US Data Privacy Framework (DPF) where applicable, or by the service provider’s participation in an approved data transfer framework.
6. Data Retention
| Data Category | Retention Period |
|---|---|
| Account data | 3 years after account deletion |
| Verification records | 5 years after last verification event |
| Payment records | 10 years (French commercial law obligations) |
| Trade/performance snapshots | Retained for the lifetime of the account plus 5 years after deletion for registry integrity |
| Encrypted API credentials | Deleted immediately upon account deletion or connection revocation |
| Server logs and usage data | 90 days |
| Cookies | See Cookie Policy for per-cookie durations |
7. Security
We implement technical and organisational measures to protect your personal data, including encryption in transit (TLS), access controls, regular security reviews, and infrastructure monitoring. However, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
8. Your Rights
Under the GDPR and applicable French data protection law, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you (Art. 15).
- Rectification: Request correction of inaccurate or incomplete data (Art. 16).
- Erasure: Request deletion of your personal data (Art. 17).
- Restriction: Request restriction of processing (Art. 18).
- Portability: Receive your data in a structured, machine-readable format (Art. 20).
- Object: Object to processing based on legitimate interest (Art. 21).
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time.
To exercise your rights, see our GDPR Rights page or contact privacy@nakedpnl.com. For California residents, please see our CCPA Rights page.
9. Children
The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us at privacy@nakedpnl.com and we will promptly delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. For significant changes, we will make reasonable efforts to provide additional notice, such as an email notification or in-app banner.
Contact: privacy@nakedpnl.com
NakedPnL · Paris, France