Privacy Policy
This policy explains what personal data we collect when you use ai-smc.trade, why we collect it, and the choices you have.
Last updated: 16 September 2026
1. Who we are
Ai SMC operates the website ai-smc.trade and supplies the Ai SMC indicator for MetaTrader 4. For questions about this policy or your data, contact contact@ai-smc.trade.
2. Data we collect
Information you give us
- Email address — used to create your account, verify it, deliver your licence and send service messages.
- Password — stored only as a salted cryptographic hash. We never store or have access to your plain-text password.
- MetaTrader 4 account number — supplied at checkout and used solely to compile a licence that runs on that account. It is an identifier only: it gives us no access to your trading account, your broker, your funds or your positions.
Information created by using the service
- Purchase and licence records — which plan you bought, transaction and subscription identifiers from our payment provider, licence issue and expiry dates.
- Technical logs — standard server logs such as IP address, timestamps and request details, kept for security and troubleshooting.
Payment information
Payments are processed by Paddle.com, our merchant of record. Card numbers and billing details are collected and held by Paddle, not by us. We receive only the transaction outcome and limited order metadata needed to issue your licence.
3. Why we use your data
- To create and secure your account, and to verify your email address.
- To generate, deliver and renew the licence you purchased (this is the core of the contract between us).
- To send transactional email such as verification codes, licence delivery and cancellation confirmations.
- To provide customer support when you contact us.
- To detect, prevent and investigate misuse, fraud or licence sharing.
- To meet our legal, tax and accounting obligations.
We do not sell your personal data, and we do not use it for third-party advertising. We only send marketing email if you have asked us to.
4. Legal bases (UK/EU users)
Where the UK GDPR or EU GDPR applies, we rely on: performance of a contract (creating your account and delivering your licence); legitimate interests (service security, fraud prevention, and improving the product); and legal obligation (tax and accounting records).
5. Service providers we share data with
We use a small number of processors, each receiving only the data they need:
- Paddle — payment processing, billing, tax and subscription management.
- Resend — delivery of transactional email (verification codes, licence files, cancellation notices).
- Neon — managed database hosting for account and licence records.
- Cloudflare — DNS, network security and protection against abuse.
- Vercel — hosting for this website.
We may also disclose data where required by law, or to establish, exercise or defend legal claims.
6. International transfers
Our providers may process data in countries other than your own. Where data leaves the UK or EEA, we rely on our providers' safeguards such as Standard Contractual Clauses or an applicable adequacy decision.
7. How long we keep data
- Account data — for as long as your account exists.
- Licence and purchase records — normally up to seven years, to meet tax and accounting requirements.
- Verification codes — minutes; they expire shortly after being issued.
- Technical logs — a short period for security and diagnostics.
8. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to how we use it, receive a copy in a portable format, or withdraw consent where we relied on it.
To exercise any of these rights, email contact@ai-smc.trade. We will respond within the time limits set by applicable law. Note that deleting your account may end your ability to access licences you have purchased, and we may need to retain certain records to comply with tax law. If you are in the UK or EEA, you also have the right to complain to your local data protection authority.
9. Cookies and local storage
We do not use advertising or third-party tracking cookies. After you sign in, we store an authentication token in your browser's local storage so that you stay signed in; clearing your browser data or signing out removes it. Our payment provider and network security provider may set cookies that are strictly necessary for checkout and for protecting the site against abuse.
10. Security
All traffic to this site and our API is encrypted in transit. Passwords are stored as salted hashes, licence downloads are protected by unique unguessable links, and access to our infrastructure is restricted. No system can be guaranteed completely secure, but we take reasonable technical and organisational measures to protect your data.
11. Children
This service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. The “last updated” date above shows the most recent revision, and material changes will be communicated by email where reasonably practicable.