Privacy Policy
The Thunder Trader
Last updated: [25 May 2026]
Table of Contents
- Introduction and Data Controller
- Scope of application
- Definitions
- Categories of personal data processed
- Purposes of processing and legal bases
- Processing of biometric data (special category under GDPR Art. 9)
- KYC and AML compliance
- Recipients of the data and data processors
- Transfer of data outside the European Economic Area
- Retention periods
- Data Subject rights
- Users residing in the United Kingdom
- Users residing in the United States of America
- Security measures
- Minors
- Changes to this Privacy Policy
- Contacts
- Applicable law and jurisdiction
1. Introduction and Data Controller
This Privacy Policy describes how The Thunder Trader collects, uses, retains and protects the personal data of users who visit the website thethundertrader.com and access the platform for participation in Performance Arena Event.
The Data Controller (hereinafter “Controller”) is:
LN17 ShapeFuture Limited Flat D, 20/F, Eton Building, 288 Des Voeux Road Central, Sheung Wan, Hong Kong Company Number (CR No.): 80441068 Business Registration Number (BR No.): 80441068-000-05-26-A Contact email: legal@thethundertrader.com
Data Protection Officer (DPO): currently being appointed. Once nominated, the contact details will be published in this Privacy Policy. Until then, any communication regarding the processing of personal data may be addressed to the Controller’s email indicated above.
The Controller processes personal data in compliance with Regulation (EU) 2016/679 (“GDPR”), the UK GDPR for users residing in the United Kingdom, applicable local regulations on anti-money laundering (AML) and know your customer (KYC), as well as any other regulation applicable based on the user’s place of residence.
2. Scope of application
This Privacy Policy applies to the processing of personal data carried out through:
- the public website thethundertrader.com
- the participation platform accessible via the subdomains dashboard.thethundertrader.com, trading.thethundertrader.com, historical.thethundertrader.com and checkout.thethundertrader.com
- email communications sent by the Controller (newsletter, transactional emails, service communications)
- the customer support email channels support@thethundertrader.com and legal@thethundertrader.com
Territorial restrictions. The service is not available to residents, domiciled persons or citizens of Hong Kong (HKSAR) in consideration of specific local regulations on contests, skill-based competitions and consumer protection. For residents of the United States of America, a specific opt-out procedure applies, detailed in the Terms and Conditions (art. 25.6) and described in Section 13 of this Privacy Policy.
Minimum age. Use of the platform is reserved exclusively to natural persons of legal age who have completed their 18th year of age. The Controller does not knowingly collect personal data of subjects under 18 years of age. Should the Controller become aware of any processing of data relating to a minor, it will promptly delete such data and close the corresponding account.
3. Definitions
For the purposes of this Privacy Policy, the following terms shall mean:
- Personal data: any information relating to an identified or identifiable natural person, pursuant to Art. 4 GDPR.
- Processing: any operation applied to personal data, such as collection, recording, organisation, storage, consultation, modification, disclosure and deletion.
- Data Controller: the entity that determines the purposes and means of processing. In this case, LN17 ShapeFuture Limited.
- Data Processor: the entity that processes personal data on behalf of the Controller.
- Data Subject: the natural person to whom the personal data refer, namely the user.
- Participant: the registered user who accesses Performance Arena Event by purchasing Platform Credits.
- Performance Reward: the discretionary economic recognition granted by the Controller to those Participants who reach the highest positions in the final ranking of a Performance Arena Event.
- Available Balance: balance derived from the purchase of Platform Credits, usable to access Performance Arena Event and refundable within 14 days if unused.
- Fee Credits Balance: promotional bonus credit usable exclusively to reduce the access fee of an event; not refundable nor convertible into money.
- Performance Arena Event: skill-based competitive event on simulated trading organised by the platform.
4. Categories of personal data processed
The Controller processes various categories of personal data, collected progressively based on the level of user interaction with the service. Not all data indicated below are collected for every user: processing is proportionate to the type of actual platform use.
4.1 Browsing data
Automatically collected when visiting the website or accessing the platform:
- IP address and approximate geolocation data derived from the IP
- browser type and version
- device operating system
- pages visited, time spent, navigation paths
- referrer (originating website)
- session technical identifiers
4.2 Account registration data
Collected at the time of creating a user account (Light KYC):
- email address
- phone number (verified via OTP)
- password (stored in encrypted form using hashing algorithms)
- username (public handle)
- language and communication preferences
4.3 Participation data (Performance Arena Event)
Collected during the Participant’s involvement in events:
- registration and participation parameters
- simulated trading data (positions opened and closed on the demo account, entry and exit prices, position sizes, simulated profit/loss, session duration)
- placement in the final ranking
- Performance Reward amount potentially accrued
4.4 Payment data (Platform Credits purchase)
Collected at the time of purchasing Platform Credits:
- amount, currency, date and time of the transaction
- last four digits of the payment card (for card transactions only)
- transaction reference at the payment service provider
- cryptocurrency wallet address used (limited to cryptocurrency transactions)
The Controller does not directly collect or store full payment card data or banking credentials of users. Such data is processed exclusively by the payment service providers indicated in Section 8.
4.5 KYC data (Full Know Your Customer)
Collected exclusively at the moment of the first request for disbursement of a Performance Reward, not at the time of deposit:
- first name, last name, date of birth
- nationality
- number and type of identity document (passport, ID card, driving licence)
- image of the identity document (front/back)
- proof of residence (utility bill, bank statement or equivalent document)
- country of residence
4.6 Biometric data (special category of personal data)
Collected together with the Full KYC procedure:
- facial image (selfie) acquired through the liveness check procedure of the provider Sumsub
- facial biometric parameters derived and used for comparison with the identity document and for detecting fraud attempts (deep fake, masks, static photographs, emulators)
The processing of biometric data is specifically governed in Section 6 of this Privacy Policy.
4.7 Communication and support data
Collected in the context of direct communications with the Controller:
- content of emails sent to support@ or legal@
- support requests and tickets
- correspondence relating to requests for the exercise of GDPR rights
4.8 Marketing data (consent-based)
Collected upon the user’s express consent:
- newsletter subscription
- thematic preferences and segmentation
- email engagement data (opens, clicks)
5. Purposes of processing and legal bases
The Controller processes personal data for the purposes indicated below, each with its own legal basis under Art. 6 GDPR.
| # | Purpose | Data categories | Legal basis |
|---|---|---|---|
| 5.1 | Service provision (website access, registration, event participation) | 4.1, 4.2, 4.3 | Performance of a contract (Art. 6.1.b GDPR) |
| 5.2 | Payment management and invoicing | 4.4 | Performance of a contract (Art. 6.1.b) and legal obligation (Art. 6.1.c) |
| 5.3 | Identity verification for KYC and anti-money laundering purposes | 4.5, 4.6 | Legal obligation (Art. 6.1.c) and explicit consent for the special category (Art. 9.2.a) |
| 5.4 | Disbursement of Performance Reward at the end of events | 4.2, 4.3, 4.5 | Performance of a contract (Art. 6.1.b) |
| 5.5 | Fraud prevention, multi-accounting, ranking manipulation | 4.1, 4.2, 4.3, 4.5, 4.6 | Legitimate interest of the Controller (Art. 6.1.f) and legal obligation AML (Art. 6.1.c) |
| 5.6 | Customer support and communication management | 4.7 | Performance of a contract (Art. 6.1.b) and legitimate interest (Art. 6.1.f) |
| 5.7 | IT security, platform integrity, system logs | 4.1 | Legitimate interest of the Controller (Art. 6.1.f) |
| 5.8 | Accounting, tax and legal compliance | all, if necessary | Legal obligation (Art. 6.1.c) |
| 5.9 | Sending newsletters and marketing communications | 4.2, 4.8 | Consent (Art. 6.1.a), revocable at any time |
| 5.10 | Legal defence of the Controller in judicial or out-of-court proceedings | all, if necessary | Legitimate interest of the Controller (Art. 6.1.f) |
| 5.11 | Aggregated analytics (website usage statistics) | 4.1, pseudonymised data | Consent for third-party analytics cookies (Art. 6.1.a); legitimate interest for first-party analytics (Art. 6.1.f) |
The provision of data for purposes 5.1, 5.2, 5.3 and 5.4 is necessary to use the service: refusal to provide them makes it impossible to register, participate in events or receive a Performance Reward. The provision for purposes 5.9 and 5.11 is optional and any refusal does not prejudice the use of the service.
6. Processing of biometric data (special category of personal data, Art. 9 GDPR)
The Controller processes biometric data exclusively within the Full KYC procedure, activated upon the first request for disbursement of a Performance Reward.
What is processed. A facial scan of the user, acquired in real time through the liveness check procedure, and the biometric parameters derived from it. Such parameters are compared with the photograph on the identity document to verify the authenticity of the user’s identity and to detect any fraud attempts (use of static photographs, deep fakes, masks, emulators).
By whom. The acquisition and analysis are performed by the specialised provider Sumsub (Sum and Substance Limited), acting as Data Processor under a data processing agreement pursuant to Art. 28 GDPR.
Legal bases. The processing is based on two cumulative legal bases:
- Explicit consent of the Data Subject, given freely, in an informed and specific manner pursuant to Art. 9.2.a GDPR, collected before the start of the liveness check procedure
- Legal obligation of the Controller relating to compliance with applicable anti-money laundering (AML) and counter-terrorism financing (CFT) regulations, pursuant to Art. 9.2.g GDPR
Consequences of refusal. Refusal to grant consent to the processing of biometric data results in the impossibility of completing the Full KYC procedure and, consequently, the impossibility of receiving the disbursement of the Performance Reward. Participation in Performance Arena Event remains permitted; the Participant may also use their Available Balance to access subsequent events without having to complete the Full KYC procedure, until they request the disbursement of a Performance Reward.
Right of withdrawal. Consent to the processing of biometric data may be withdrawn at any time by writing to legal@thethundertrader.com. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal itself, but will result in the impossibility of disbursing further Performance Rewards until a possible new KYC procedure is completed.
Storage. Biometric data is retained for the time strictly necessary to perform the verification and subsequently for the period required by applicable AML obligations (typically 5-7 years from the termination of the relationship with the user). Once such term has elapsed, biometric data is deleted or irreversibly anonymised.
7. KYC and AML compliance
The Controller is subject to customer due diligence obligations and to the prevention of money laundering and terrorism financing. Such obligations require the Controller to:
- collect and verify the identity of Participants before the disbursement of Performance Reward
- retain identification documentation for the period prescribed by applicable regulations
- report suspicious transactions to competent authorities
- block the disbursement of Performance Reward in the presence of identification anomalies, multi-accounting or discrepancies between documented and declared identity
Processing of data for AML purposes constitutes a legal obligation for the Controller and prevails, within the limits provided by applicable law, over Data Subject rights of erasure or restriction for the duration of the mandatory retention period.
8. Recipients of the data and data processors
Personal data may be processed, for the purposes indicated above, by the following entities, acting as data processors under Art. 28 GDPR. The relevant appointment agreement is available with the Controller for each of them.
| Provider | Role | Location | Categories of data processed |
|---|---|---|---|
| Hostinger International Ltd. | Hosting of the public website | Lithuania (data centre in Frankfurt, DE) | 4.1, 4.7 |
| Amazon Web Services EMEA SARL (AWS) | Hosting of the platform and subdomains | Luxembourg (data centre in Frankfurt, DE, eu-central-1) | 4.1, 4.2, 4.3, 4.4, 4.5, 4.6 |
| Brevo SA (formerly Sendinblue) | Email marketing and newsletter | France | 4.2, 4.8 |
| Twilio Inc. (SendGrid) | Sending of transactional and service emails | United States of America (Data Privacy Framework) | 4.2, 4.7 |
| Volumetrica FX / Trade Tech Solutions | Technical infrastructure for trading simulation | European Union | 4.3 |
| Bybit Fintech Limited | Reference price feed for perpetual-style crypto instruments (simulation) | Dubai (UAE) / BVI | market data; not personally identifying data |
| Forex Capital Markets Ltd. (FXCM) | Reference price feed for forex and CFD instruments (simulation) | United Kingdom | market data; not personally identifying data |
| Sum and Substance Limited (Sumsub) | Identity verification, KYC, AML, biometric liveness | United Kingdom (UK company 09688671) | 4.5, 4.6 |
| Google Ireland Limited (Google Analytics 4) | Website usage statistics | Ireland (EU) | 4.1 (in pseudonymised form, upon consent to analytics cookies) |
| Paytiko Ltd. | Payment orchestration (cards, transfers) | European Union | 4.4 |
| Confirmo, a.s. | Cryptocurrency payment processing | Czech Republic | 4.4 |
| EMI provider for SEPA | IBAN account for SEPA collections and disbursements | To be defined upon account activation | 4.4 |
In addition to the entities indicated above, data may be disclosed to:
- professional advisors of the Controller (legal, accounting, audit) for compliance and legal defence purposes only, bound by confidentiality obligations
- competent judicial and administrative authorities, in case of legitimate request under applicable regulations
- entities involved in any corporate reorganisation, merger, demerger or transfer of business of the Controller, subject to adequate guarantee of data protection
The updated list of data processors is available upon request by writing to legal@thethundertrader.com. The Controller reserves the right to add or replace providers, providing information through an update to this Privacy Policy.
9. Transfer of data outside the European Economic Area
Some processing operations involve the transfer of personal data outside the European Economic Area (EEA). Destinations and applied safeguards are as follows:
9.1 Transfer to Hong Kong (Data Controller)
The Controller LN17 ShapeFuture Limited is based in Hong Kong. Hong Kong is not the subject of an adequacy decision of the European Commission under Art. 45 GDPR. Therefore, the transfer of personal data from the European Union to the Controller is carried out on the basis of the Standard Contractual Clauses (SCC) approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, supplemented by additional technical, contractual and organisational measures identified following a Transfer Impact Assessment (TIA) conducted by the Controller.
The supplementary measures include, among others: encryption of data in transit and at rest, restricted access controls, logical segregation of data, response procedures for access requests from public authorities according to principles of necessity and proportionality.
A copy of the SCC applied and a summary of the TIA may be requested by writing to legal@thethundertrader.com.
9.2 Transfer to the United Kingdom
For providers based in the United Kingdom (Sumsub, FXCM), the transfer of personal data takes place on the basis of the adequacy decision adopted by the European Commission on 28 June 2021, currently in force.
9.3 Transfer to the United States of America
For providers based in the United States (Twilio/SendGrid), the transfer is made to entities adhering to the EU-U.S. Data Privacy Framework (DPF), certified under the European Commission’s adequacy decision of 10 July 2023. For transfers not covered by the DPF, the Standard Contractual Clauses apply.
9.4 Transfer to other third countries
For any transfers to other third countries not covered by an adequacy decision, the Controller adopts one of the following safeguards:
- Standard Contractual Clauses approved by the European Commission
- Binding Corporate Rules
- Other safeguards provided for under Chapter V of the GDPR
The user has the right to obtain a copy of the applied safeguards by writing to the Controller’s email.
10. Retention periods
Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected, according to the criteria indicated below:
| Data category | Retention period |
|---|---|
| Browsing data (technical logs) | Maximum 12 months from collection |
| Account registration data | For the entire duration of the contractual relationship, and for 10 years from account closure for legal defence purposes (or equivalent term in the user’s jurisdiction) |
| Event participation data | For the entire duration of the contractual relationship, and for 10 years from termination for legal defence and accounting obligations |
| Payment data | 10 years from the date of the transaction for tax and accounting purposes |
| KYC data (Section 4.5) | For the entire duration of the relationship and for 5-7 years from termination, in compliance with applicable AML obligations |
| Biometric data (Section 4.6) | For the time strictly necessary for the initial verification and subsequently for 5-7 years from termination of the relationship, in compliance with AML obligations; upon expiration, irreversible deletion or anonymisation |
| Communication data and support tickets | 24 months from ticket closure, unless longer retention is required for legal defence purposes |
| Marketing data (newsletter) | Until withdrawal of consent by the user; thereafter, deletion within 30 days |
| Analytics data (Google Analytics 4) | Maximum 14 months, according to the Controller’s configuration |
Once the terms indicated above have elapsed, personal data is deleted or irreversibly anonymised, unless specific legal obligations require longer retention or there are documented legitimate interests of the Controller.
11. Data Subject rights
The user, as a Data Subject, may exercise at any time the rights provided for in Articles 15-22 of the GDPR:
- Right of access (Art. 15): obtain confirmation of the existence of processing of their personal data and access such data.
- Right to rectification (Art. 16): obtain the correction of inaccurate data or the integration of incomplete data.
- Right to erasure – “right to be forgotten” (Art. 17): obtain the deletion of their data, save for cases in which the Controller is required to retain them by law (in particular for AML compliance described in Section 7).
- Right to restriction of processing (Art. 18): obtain the restriction of processing in cases provided for by law.
- Right to data portability (Art. 20): receive their data in a structured, commonly used and machine-readable format, and transmit them to another controller.
- Right to object (Art. 21): object to processing for direct marketing purposes at any time, without need for motivation, and to processing based on legitimate interest, providing a reason related to their particular situation.
- Right not to be subject to automated decisions (Art. 22): not to be subject to a decision based solely on automated processing that produces legal effects. The Controller specifies that, although it uses automated procedures for fraud detection and multi-accounting, any decision that significantly affects the user (for example account suspension or blocking of a Performance Reward) is always reviewed by a human operator before being definitively applied.
- Right to withdraw consent (Art. 7.3): withdraw consent given at any time, without prejudice to the lawfulness of processing carried out previously.
- Right to lodge a complaint with the supervisory authority (Art. 77): lodge a complaint with the competent Authority. For users residing in Italy, the authority is the Italian Data Protection Authority – Garante per la protezione dei dati personali (www.garanteprivacy.it). For users residing in other EU Member States, the authority of the Member State of residence has jurisdiction.
How to exercise the rights. Rights may be exercised by writing to legal@thethundertrader.com. The Controller responds to requests without undue delay and in any case within one month from receipt, extendable for an additional two months in cases of particular complexity, with prior communication to the Data Subject. The exercise of rights is free of charge; the Controller reserves the right to require a reasonable contribution or to refuse the request only in cases provided for by Art. 12.5 GDPR (manifestly unfounded or excessive requests).
Before acting on the request, the Controller may require additional information necessary to confirm the identity of the requester.
12. Users residing in the United Kingdom
For users residing in the United Kingdom, the rights listed above apply under the UK GDPR and the Data Protection Act 2018. The competent supervisory authority is the Information Commissioner’s Office (ICO) (www.ico.org.uk).
The Controller, being established outside the United Kingdom, is not required to appoint a UK representative under Art. 27 UK GDPR unless specific conditions apply, which are assessed on a case-by-case basis.
13. Users residing in the United States of America
As indicated in the Terms and Conditions of the platform (art. 25.6), the service is not actively offered to residents of the United States of America. Users declaring U.S. residence at the time of registration are subject to a specific opt-out procedure and dedicated contractual clauses.
Should a U.S. resident nevertheless access the platform, the following provisions apply:
- for residents of California, under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the user has the right to: (i) know which categories of personal data are collected and for what purposes; (ii) request the deletion of their data; (iii) opt out of the sale or sharing of their data (the Controller does not sell personal data); (iv) not be subject to discrimination for having exercised such rights
- for residents of other States with applicable privacy regulations (Virginia, Colorado, Connecticut, Utah, and others), the rights provided for by the respective regulations apply
Requests may be addressed to legal@thethundertrader.com.
14. Security measures
The Controller adopts technical and organisational measures appropriate to the risk to protect personal data from unauthorised access, accidental loss, destruction, alteration and disclosure, in compliance with Art. 32 GDPR. Such measures include, on a non-exhaustive basis:
- encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256)
- logical segregation of data by category and purpose
- access controls based on the principle of least privilege
- mandatory two-factor authentication (2FA) for the Controller’s administrative accounts and for users before the first Performance Reward request
- activity logs and anomaly detection procedures
- periodic backups and disaster recovery procedures
- staff training on data protection and breach management
- Data Processing Agreements (DPA) with all Data Processors
In the event of a personal data breach presenting a risk to the rights and freedoms of users, the Controller notifies the breach to the competent supervisory authority within 72 hours of discovery, and informs the affected users without undue delay in cases where the breach presents a high risk.
15. Minors
As indicated in Section 2, the service is reserved to natural persons of legal age, not under 18 years of age. The Controller does not knowingly collect personal data of minors under 18 years of age.
Should a parent or legal guardian believe that a minor has provided personal data to the Controller without authorisation, they are invited to contact legal@thethundertrader.com immediately to request the deletion of the data and the closure of any account.
16. Changes to this Privacy Policy
The Controller reserves the right to modify this Privacy Policy at any time to adapt it to:
- regulatory developments
- organisational changes
- changes to the service and technical stack
- recommendations from supervisory authorities
In case of substantial modifications affecting the purposes or legal bases of processing, the Controller will inform registered users in advance via email to the address associated with the account and, where necessary, will collect new consent.
The date of the last update is indicated at the beginning of this Privacy Policy. Users are invited to consult the page periodically to check for any modifications.
17. Contacts
Data Controller LN17 ShapeFuture Limited Flat D, 20/F, Eton Building 288 Des Voeux Road Central Sheung Wan, Hong Kong
Email for legal and privacy matters legal@thethundertrader.com
Email for general support support@thethundertrader.com
Data Protection Officer (DPO) Currently being appointed. Contact details will be published in this Privacy Policy once nominated.
Italian Supervisory Authority Garante per la protezione dei dati personali Piazza Venezia 11, 00187 Rome, Italy www.garanteprivacy.it
18. Applicable law and jurisdiction
This Privacy Policy is governed, in coordination with the Terms and Conditions of the service, by the provisions contained therein regarding applicable law and jurisdiction.
For users qualifying as consumers and residing in the European Union, the mandatory provisions for consumer protection provided by the legal system of the country of residence remain unaffected, including the jurisdiction of the place of residence for disputes relating to their rights.
For any matter relating to the processing of personal data, users residing in the European Union may also lodge a complaint with the supervisory authority of the Member State of residence, as provided for by Art. 77 GDPR.
Document drafted in compliance with Regulation (EU) 2016/679 (GDPR), the UK GDPR for users of the United Kingdom, applicable local sector regulations and the guidelines of the European Data Protection Board (EDPB).
Cookie Policy
The Thunder Trader
Last updated: [25 May 2026]
Table of Contents
- Introduction
- What cookies and other identifiers are
- Categories of cookies used
- Detailed list of cookies
- Third-party cookies and transfers outside the EEA
- Legal basis and retention period
- How to manage cookie preferences
- How to disable cookies from the browser
- Consequences of refusal
- Changes to this Cookie Policy
- Contacts
1. Introduction
This Cookie Policy describes the types of cookies and other tracking tools used on the website thethundertrader.com and on the The Thunder Trader platform subdomains (dashboard, trading, historical, checkout), as well as the ways in which the user can manage their preferences.
This document supplements the Privacy Policy and is drafted in compliance with:
- Regulation (EU) 2016/679 (GDPR)
- Directive 2002/58/EC as amended by Directive 2009/136/EC (ePrivacy Directive)
- the Italian Data Protection Authority Order of 10 June 2021 “Guidelines on cookies and other tracking tools”
Data Controller: LN17 ShapeFuture Limited, Flat D, 20/F, Eton Building, 288 Des Voeux Road Central, Sheung Wan, Hong Kong (CR No. 80441068). Contact email: legal@thethundertrader.com.
2. What cookies and other identifiers are
Cookies are small text files that visited websites send to the user’s device (computer, tablet, smartphone), where they are stored to be retransmitted to the site at the next visit. Cookies allow the user’s device to be recognised, certain information about visits to be recorded, and essential or additional functionalities to be provided.
In addition to cookies, there are other tracking technologies that the Controller may use and that are treated in this Policy with the same safeguards provided for cookies:
- Local storage and session storage (local storage in the browser)
- Tracking pixels (web beacons, transparent images)
- Fingerprinting (device recognition through the combination of parameters)
- Third-party SDKs integrated into the platform
For simplicity, the term “cookies” in the rest of this document refers to all the tracking tools listed above, unless otherwise specified.
3. Categories of cookies used
The site uses three categories of cookies, according to the classification of the Italian Data Protection Authority:
3.1 Technical cookies (essential)
Cookies strictly necessary for the operation of the site and the provision of the service requested by the user. They include:
- Navigation and session cookies: keep the user session active, manage the cart and purchase flow, maintain login in the reserved area
- Functionality cookies: store preferences such as site language, displayed theme, acceptance of the cookie banner
- Security cookies: protection against automated attacks (technical CAPTCHA), detection of session anomalies, two-factor authentication
- Load balancing cookies: distribution of traffic across platform servers
Legal basis: legitimate interest of the Controller in providing the service (Art. 6.1.f GDPR). Such cookies do not require the user’s prior consent under Art. 122 of the Italian Privacy Code.
3.2 Analytics cookies
Cookies used to collect information in aggregate form on the number of users and how they visit the site. The Controller uses exclusively third-party analytics cookies (Google Analytics 4) configured with the following mitigation measures provided for by the Italian Authority’s Order:
- IP address anonymisation (IP masking)
- Disabling of data sharing with other Google services for profiling and advertising purposes
- No data enrichment with information from third-party sources
- Maximum retention period of 14 months
In consideration of these measures, Google Analytics 4 is equivalent to a first-party analytics cookie under the Order. However, for greater user protection, prior consent is still requested through the cookie banner at the site’s entry.
Legal basis: user consent (Art. 6.1.a GDPR; Art. 122 Italian Privacy Code).
3.3 Profiling and marketing cookies
Cookies used to build a profile of the user based on their browsing habits, in order to send advertising messages in line with their interests.
Current status: the Controller does not use profiling cookies or behavioural marketing cookies on the site. Should they be introduced in the future, this Policy will be updated and the user will be asked for new explicit consent through an updated banner.
4. Detailed list of cookies
The following table lists the cookies actually active on the site at the time of the last update of this Policy.
4.1 Technical cookies
| Name | Provider | Purpose | Duration |
|---|---|---|---|
wordpress_logged_in_* |
thethundertrader.com (first party) | Maintenance of the login session in the reserved area | Session |
wp-settings-* |
thethundertrader.com (first party) | Storage of user interface preferences | 1 year |
trp-form-language |
thethundertrader.com (first party) | Storage of the language selected by the user (TranslatePress) | Session |
tt_cookie_consent |
thethundertrader.com (first party) | Storage of user preferences expressed in the cookie banner | 6 months |
tt_session_id |
thethundertrader.com (first party) | Technical session identifier for the platform | Session |
tt_2fa_token |
thethundertrader.com (first party) | Temporary token for two-factor authentication | 10 minutes |
4.2 Analytics cookies (upon consent)
| Name | Provider | Purpose | Duration |
|---|---|---|---|
_ga |
Google Ireland Limited | Unique identification of users for aggregate statistics | 13 months |
_ga_<container-id> |
Google Ireland Limited | Persistence of the Google Analytics 4 session state | 13 months |
Data collected by Google Analytics 4 is retained for a maximum of 14 months and is automatically deleted upon expiry.
4.3 Operational cookies of the simulated trading platform (upon consent or legitimate interest)
For registered users accessing the participation platform for Performance Arena Event, additional technical operational cookies may be activated, managed by the infrastructure provider Volumetrica FX / Trade Tech Solutions, exclusively aimed at the operation of the simulated trading environment. These cookies qualify as technical and do not require additional consent beyond what is provided for in the acceptance of the Terms of Service.
5. Third-party cookies and transfers outside the EEA
Some cookies are installed by third parties acting as data processors or autonomous controllers. For third-party cookies, the user is invited to also consult the privacy policies of the respective providers, indicated below.
| Third party | Type | Privacy Policy | Data transfer |
|---|---|---|---|
| Google Ireland Limited (Google Analytics 4) | Analytics | https://policies.google.com/privacy | Data processed primarily in the EU; any transfers to the United States take place under the EU-U.S. Data Privacy Framework (DPF) |
In the event of future introduction of additional third-party services (e.g. support chat, social plugins, embedded videos), this table will be updated and the user will be asked for new consent where necessary.
For the safeguards applied to data transfers outside the European Economic Area, please refer to Section 9 of the Privacy Policy.
6. Legal basis and retention period
| Type | Legal basis | Retention |
|---|---|---|
| Technical cookies | Legitimate interest (Art. 6.1.f GDPR) and technical necessity (Art. 122 Italian Privacy Code) | Variable, from session duration to a maximum of 12 months |
| Analytics cookies | Consent (Art. 6.1.a GDPR; Art. 122 Italian Privacy Code) | Maximum 14 months |
| Profiling cookies | Consent (Art. 6.1.a GDPR) | Not used at present |
The consent given by the user in the cookie banner has a maximum duration of 6 months, in compliance with the Italian Authority’s Order. Once such period has elapsed, the banner will be presented again to the user for the renewed collection of consent.
The refusal of consent is also stored to prevent the banner from being presented again at each visit; in such case, the technical cookie tt_cookie_consent will record the user’s choice.
7. How to manage cookie preferences
The user can manage their cookie preferences at any time through the following tools:
7.1 Cookie banner
Upon first access to the site, a banner is presented allowing the user to:
- Accept all cookies (technical + analytics)
- Reject all cookies that are not strictly necessary (keeping only technical ones active)
- Customise preferences, choosing the individual categories to accept or reject
The reject button and the accept button have equal graphic prominence, in compliance with the Italian Authority’s indications.
7.2 Modify preferences at any time
The user can modify previously made choices at any time through:
- the “Manage cookie preferences” link available in the footer of every page of the site
- manual deletion of the
tt_cookie_consentcookie from the browser (in such case the banner will be presented again on the next access)
7.3 Storage of expressed choices
The choices expressed by the user in the banner are stored as a technical cookie for a period of 6 months. Once such term has elapsed, the banner will be presented again to allow the user to confirm or modify their preferences.
8. How to disable cookies from the browser
In addition to the tools made available by the site, the user can configure their browser to accept, reject or delete cookies at any time. Operating instructions vary from browser to browser; below are the links to the official support pages:
- Google Chrome: https://support.google.com/chrome/answer/95647
- Mozilla Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- Safari (desktop): https://support.apple.com/guide/safari/sfri11471/mac
- Safari (iOS): https://support.apple.com/HT201265
- Microsoft Edge: https://support.microsoft.com/microsoft-edge
- Opera: https://help.opera.com/en/latest/web-preferences/
To specifically disable Google Analytics cookies across all sites, the official browser add-on is available at: https://tools.google.com/dlpage/gaoptout
9. Consequences of refusal
The refusal of cookies has differentiated consequences depending on the type:
- Refusal of technical cookies: not possible, as technical cookies are strictly necessary for the operation of the site. Manual disabling through the browser may compromise or prevent navigation, access to the reserved area, use of the participation platform for Performance Arena Event
- Refusal of analytics cookies: no consequences on browsing. The Controller will not be able to collect aggregate statistics on the user’s use of the site
- Refusal of profiling cookies: not applicable (not currently used)
10. Changes to this Cookie Policy
The Controller reserves the right to modify this Cookie Policy at any time to adapt it to:
- regulatory developments
- introduction of new technical tools or third parties
- recommendations from the Italian Authority or other supervisory authorities
In case of substantial modifications, in particular the introduction of profiling cookies or new third-party cookies, the banner will be presented again to the user for the collection of updated consent.
The date of the last update is indicated at the beginning of this Policy.
11. Contacts
For any request concerning the processing of personal data through cookies, the user can write to:
legal@thethundertrader.com
For any matter not specifically governed by this Policy, please refer to the full Privacy Policy, available at the link in the footer of the site.
The user also has the right to lodge a complaint with the Italian Data Protection Authority – Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome, Italy; www.garanteprivacy.it) or with the supervisory authority of their EU Member State of residence.
Document drafted in compliance with Regulation (EU) 2016/679 (GDPR), Directive 2002/58/EC (ePrivacy) as amended by Directive 2009/136/EC, the Italian Data Protection Authority Order of 10 June 2021 “Guidelines on cookies and other tracking tools”.