Privacy Policy — Part-Time Quant (PTQ)
Version: 1.0 — in force Effective date: 27 August 2026 Applies to: part-timequant.com, the PTQ hosted app, and the PTQ desktop OS licence service.
1. Who we are
Lewis Jackson Ventures Ltd (registered in England and Wales, company number 14843004) ("PTQ", "we", "us") operates Part-Time Quant.
- Registered company: Lewis Jackson Ventures Ltd (registered in England and Wales, company number 14843004)
- Registered address: 46 Priory Road, Reigate, Surrey, RH2 8JB, United Kingdom
- ICO registration: 00015214092
- VAT: VAT registered — GB472696843
- Contact for privacy matters: [email protected]
We are the data controller for the personal data described in this policy. We are a UK business and we comply with the UK GDPR and the Data Protection Act 2018.
2. What this policy covers
PTQ has three surfaces. Each handles data differently.
a) The marketing website (part-timequant.com). No accounts, no marketing cookies, no tracking pixels. We use Plausible Analytics in cookieless mode: it counts visits using aggregated, anonymised data and does not store identifiers on your device or build profiles of you. We do not run advertising or cross-site tracking on the site.
b) The hosted app. This is where personal data lives. Details in section 3.
c) The desktop OS (paid licence, runs on your machine). The desktop OS runs locally. Your broker API keys are entered on your machine, stay on your machine, and are never transmitted to us. Live trading happens only on your machine, with your keys, behind an arming step you control each session. We never hold broker credentials, never hold client money, and never execute trades on our servers. The desktop OS contacts our servers only to validate your licence key and device seats (see 3.6).
3. What we collect, and why
3.1 Account data
When you create an account we collect, via Clerk (our authentication provider):
- email address
- name (if you provide one)
- authentication data (password hash or social-login identifier — held by Clerk, not us)
- sign-in timestamps and session tokens
Purpose: creating and securing your account. Lawful basis: performance of a contract (UK GDPR Art. 6(1)(b)); legitimate interests for security logging (Art. 6(1)(f)).
3.2 Product data
While you use the hosted app we store, in our own database:
- strategies you create and their configuration
- risk profiles and settings
- paper trades (simulated fills — clearly labelled as simulated; no real orders)
- backtest and validation results
- usage log (which features you used and when, credit consumption)
- your jurisdiction and consent-gate acknowledgements (see 3.7)
Purpose: providing the product; enforcing credit limits; showing you your own history. Lawful basis: performance of a contract (Art. 6(1)(b)); legitimate interests for the usage log (service integrity, abuse prevention — Art. 6(1)(f)).
We do not store secrets in this database. It is a metadata-only vault: no broker keys, no API secrets, no card details.
3.3 Support conversations
If you open a support ticket or use in-app support chat, we store the conversation. Support messages may be processed by an AI assistant powered by Anthropic to draft or provide responses. The same applies to user-facing AI features inside the app (for example, AI help with building a strategy): your prompts and the app context needed to answer them are sent to Anthropic for processing.
What Anthropic receives: the text of your message and relevant product context. Do not put sensitive personal information into support messages or AI prompts; we do not need it and do not ask for it. Purpose: answering your questions; operating product features you invoke. Lawful basis: performance of a contract (Art. 6(1)(b)); legitimate interests in efficient support (Art. 6(1)(f)).
3.4 Payment data
Payments are handled by Stripe. Card numbers go directly to Stripe and never touch our servers. We receive and keep from Stripe: your name, email, the product purchased, amount, currency, country, and Stripe's identifiers for the customer and subscription.
Purpose: taking payment for the annual plan; managing your subscription; refunds; accounting. Lawful basis: performance of a contract (Art. 6(1)(b)); legal obligation for tax and accounting records (Art. 6(1)(c)).
3.5 Transactional email
We send account and service emails (receipts, licence keys, password resets, service notices) via Resend. We do not send marketing email unless you separately opt in. We do not operate a marketing mailing list. If that changes, this policy will be updated and consent captured separately.
Lawful basis: performance of a contract (Art. 6(1)(b)) for service email; consent (Art. 6(1)(a)) for any marketing email.
3.6 Desktop OS licence checks
The desktop OS validates your licence key with our servers. Each check sends: your licence key, a device identifier (to enforce the 2-device seat limit), app version, and timestamp. That is all. No trading activity, no broker data, no strategy contents, and no file contents from your machine are transmitted.
Purpose: enforcing the licence you bought (2 seats). Lawful basis: performance of a contract (Art. 6(1)(b)).
3.7 Jurisdiction and consent gate
Before using trading-related features you complete a consent gate. We record: the jurisdiction you declare, the acknowledgements you tick (that PTQ is education and tooling, not investment advice), and a timestamp. Checkout is blocked for unsupported jurisdictions, so we also use the declared jurisdiction to decide whether you can buy.
Purpose: compliance with our own terms and with regulatory constraints; evidencing your acknowledgement. Lawful basis: legitimate interests (Art. 6(1)(f)) and legal obligation to the extent applicable (Art. 6(1)(c)).
3.8 Internal operations alerts
Our internal operations alerts (for example "a new support ticket arrived") are sent by email to our own operators, through the same email provider listed below. They carry an event type and a ticket or account reference. Where an email to you fails to send, the alert names your email address and the subject line so the failure can be put right — it does not contain the message body. We do not use any third-party chat or messaging service for operational alerts.
3.9 Market data
Market prices shown in the product come from third-party market data sources (currently yfinance in development; Tiingo planned for production). Requests for market data do not include your personal data.
3.10 What we do not collect
- Broker credentials or API keys — never transmitted to us
- Client money — we never hold funds
- Live trade executions — these happen only on your machine
- Special category data (health, politics, etc.) — we do not ask for it; do not send it to us
- Marketing cookies or advertising identifiers
4. Cookies
Marketing site: no cookies. Plausible runs cookieless. Hosted app: strictly necessary cookies only — set by Clerk to keep you signed in and secure the session, and potentially by Stripe (fraud prevention at checkout, if Stripe.js is embedded) and Cloudflare (bot protection). Because they are strictly necessary for a service you request, they do not require a consent banner under PECR. We do not use analytics or advertising cookies in the app. Our separate Cookie Policy lists every cookie and the full reasoning.
Webinar registration
If you register for a live event, WebinarJam collects the registration fields you submit and sends your personal joining link and reminders. We also send your name, email address and event registration status to Kit so we can manage communications about that event. The /live page embeds WebinarJam’s form. The confirmation page links to the separately paid Academy on Skool; registering for the webinar does not purchase Academy or software access.
5. Who processes your data (subprocessors)
We use these providers. Each acts as our processor (or, where marked, an independent controller) under contracts that include data-protection terms.
| Provider | Role | What they handle | Location | Notes |
|---|---|---|---|---|
| Clerk | Authentication | Email, name, credentials, sessions | US | Processor |
| Stripe | Payments | Payment and billing data | US / Ireland | Independent controller for payment processing |
| Anthropic | AI processing (support + in-app AI features) | Support messages, AI prompts, product context | US | Processor; API data-training opt-out confirmed |
| Railway | Hosting (app + Postgres database) | All hosted app data | the European Union (Amsterdam) | Processor |
| Cloudflare | DNS, CDN, security | IP addresses and request metadata in transit | Global (US company) | Processor |
| Resend | Transactional email | Email address, email contents | US | Processor |
| Plausible | Website analytics | Aggregated, anonymised visit data only | EU (Estonia/Germany) | No personal data profiles; cookieless |
| WebinarJam (Genesis Digital) | Webinar registration, event delivery and reminders | Registration fields and event attendance | US | See provider privacy terms |
| Kit | Event email list and follow-up | Name, email and event status | US | See provider privacy terms |
| Tiingo | Market data (planned) | No personal data sent | US | Not a personal-data processor if kept to market data only |
We will update this table before adding any new subprocessor that handles personal data.
6. International transfers
Several of our providers are in the United States (Clerk, Stripe, Anthropic, Cloudflare and Resend). Railway hosts our application and database in the European Union (Amsterdam), as shown in the table above. When your data goes to them, it leaves the UK.
We rely on, in order of preference:
- the UK–US Data Bridge (the UK extension to the EU–US Data Privacy Framework), where the provider is certified; and
- the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, built into each provider's data processing agreement, plus a transfer risk assessment.
7. How long we keep your data
| Category | Retention |
|---|---|
| Account data | While your account exists; deleted on account deletion |
| Product data (strategies, risk profiles, settings, paper trades) | While your account exists; deleted on account deletion |
| Support conversations | 24 months from the closure of the ticket, after which it is deleted |
| Usage log | 12 months on a rolling basis, after which it is deleted |
| Consent-gate records | Duration of the account, then 6 years — the record evidences the consent given at purchase |
| Licence/device-seat records | While the licence is active, then 12 months |
| Payment and accounting records (held in Stripe and our accounts) | 6 years from end of the relevant financial year, as required by UK tax law; retained even after account deletion |
| Website analytics | Aggregated and anonymised only; no personal data retained |
When you delete your account, we erase your account and product data (see section 8). Payment records survive because the law requires us to keep them.
8. Your rights
Under the UK GDPR you can:
- Access your data (Art. 15)
- Export it — the app has a built-in export that gives you your product data as JSON
- Correct inaccurate data (Art. 16)
- Delete your account and data (Art. 17) — the app has a built-in account deletion that erases your product data in full; Stripe payment records are retained for accounting as described above
- Restrict or object to processing based on legitimate interests (Arts. 18, 21)
- Port your data to another service (Art. 20)
- Withdraw consent at any time, where consent is the basis (e.g. marketing email, if any)
How to exercise them: use the in-app export and deletion controls, or email [email protected]. We respond within one month. We may ask you to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.
We do not make solely automated decisions with legal or similarly significant effects about you. The jurisdiction checkout block is applied from the jurisdiction you yourself declare, and you can contact us to query it.
9. Complaints
If you are unhappy with how we handle your data, contact us first at [email protected] and we will try to fix it.
You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 ico.org.uk/make-a-complaint
If you are outside the UK, you may also be able to complain to your local data protection authority.
10. Children
PTQ is for adults. You must be 18 or over to create an account. We do not knowingly collect data from anyone under 18. If we learn we hold data on someone under 18, we will delete it. If you believe a minor has an account, contact [email protected].
11. Security
- All traffic is encrypted in transit (TLS).
- Broker keys never reach our systems — the product is designed so they cannot.
- Our database stores no secrets; it is metadata only.
- Access to production systems is restricted to the team members who need it.
- Payment card data is handled entirely by Stripe (PCI-DSS compliant).
No system is perfectly secure. If a personal data breach occurs that risks your rights, we will notify the ICO within 72 hours where required, and notify you without undue delay where the risk to you is high.
12. Changes to this policy
We will post changes on this page and update the "Last updated" date. For material changes — new purposes, new categories of data, or new subprocessors handling personal data — we will notify account holders by email before the change takes effect. Continued use after the effective date means the new version applies.
13. Contact
Questions about this policy or your data:
Lewis Jackson Ventures Ltd (registered in England and Wales, company number 14843004) 46 Priory Road, Reigate, Surrey, RH2 8JB, United Kingdom Email: [email protected]