Privacy Policy
Last updated: 15 September 2026
Karhu Capital Ltd, trading as OmenSyncer ("OmenSyncer", "we", "our"), operates the OmenSyncer trade-copy platform at app.omensyncer.com and the OmenSyncer Desktop application. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have over it.
This policy is written to comply with the UK GDPR, the EU GDPR, and the California Consumer Privacy Act (CCPA). If you are in another jurisdiction with stricter privacy laws, those laws apply to the extent they grant you additional rights.
1. Who we are
Karhu Capital Ltd is a private limited company registered in England and Wales, company no. 17281462, with its registered office at 49 Lily Close, Chelmsford, CM1 6YN, United Kingdom (trading as OmenSyncer). We act as the "data controller" for the personal information described in this policy. You can contact us at [email protected] for any privacy-related question.
2. What data we collect
We only collect what is needed to operate the service:
Account data
- Email address (used to sign in and verify your account)
- Password (stored as a salted bcrypt hash - we never see your plaintext password)
- Optional public username / handle
- Account creation date and email-verification timestamp
Billing data
- Stripe customer ID and subscription status (plan, renewal date, cancellation state)
- Invoice history (date, amount, paid / failed state)
- We do not store your card number, CVV, or full payment-method details. All payment information is held by Stripe under their own security and compliance regime.
Broker connection data
- Broker login credentials (username + password) encrypted at rest with AES-256, or OAuth access / refresh tokens encrypted the same way
- Tradovate / NinjaTrader / ProjectX account identifiers and configuration (multiplier, cross-order flag, follower assignment)
- Risk configuration (loss limits, profit targets, lockout schedules)
- Trade executions, order history, and journal entries belonging to your connected accounts
Technical data
- IP address, browser user-agent, and timestamps of dashboard sessions (used for security and abuse prevention; rotated out of logs after 30 days)
- Web-push subscription tokens if you opt in to push notifications
- A signed authentication token (JWT) stored in your browser's local storage to keep you logged in - sent as a bearer credential on each request, never set as a cookie
Waitlist data
If you join the waitlist for early access, we collect only what you type into that form, plus one thing we derive:
- Your name and email address, and your phone number if you choose to give one (the phone field is optional and the form works without it)
- Your answers to the short questionnaire - how many accounts you trade, how you copy trades today, what you want the product to do, and what you have already tried
- Your country, derived from your IP address at the moment you submit. We store the country only. The IP address itself is not saved against your entry.
We use this to decide what to build first and to tell you when your place opens. See section 6 for how long we keep it and section 7 for how to have it deleted.
We run no third-party analytics, advertising pixels, or behavioural tracking scripts anywhere in the dashboard or the desktop app. There is a single, narrow exception, and it only ever runs with your permission: on our waitlist page we use PostHog to measure which questions people give up on, so we can shorten the form. It is off until you press Accept on the banner that page shows, it is never used for advertising, and the page behaves identically whether you accept or decline. Section 9 describes exactly what it stores. We also use Sentry for error monitoring (crash and exception reports) so we can find and fix bugs; it is not analytics or advertising and does not track your activity. See section 4 for what both receive.
3. Why we collect it (legal bases)
4. Who we share data with
We share the minimum amount of data needed with these processors:
- Stripe, Inc. - payment processing. They receive your email, billing address (if provided), and card details directly from you. Stripe privacy policy.
- Tradovate, NinjaTrader, ProjectX (your broker) - we send orders and read account state on your behalf using the credentials or OAuth tokens you provided. Each broker has its own privacy policy.
- Oracle Cloud Infrastructure - hosts our database and backend servers in the United States (Chicago), located near the broker to minimise copy latency.
- Cloudflare - DNS and DDoS protection in front of the dashboard.
- Sentry (Functional Software, Inc.) - application error monitoring. Receives diagnostic crash / exception reports that may include your IP address, the page URL, and a technical stack trace. We scrub credentials, tokens, and secrets before sending, and we do not record your session or screen. Sentry privacy policy.
- PostHog (PostHog, Inc.), EU Cloud - product analytics on the waitlist page only, and only after you accept the banner there. Two things limit what it sees. Its data is held in the European Union, not the United States. And the events are sent through our own domain rather than to PostHog directly, so PostHog does not receive your IP address. If you decline, nothing is loaded and nothing is sent. PostHog privacy policy.
- Email delivery provider (currently Resend or equivalent) - sends transactional emails. They process your email address and the email body.
- Discord - only if you choose to join our community Discord server. We do not share your account data with Discord; we just link to a public invite.
We do not sell your personal data, ever. We do not share it with advertisers, data brokers, or analytics resellers.
5. International data transfers
Because the trade-copy engine runs near the broker (currently Chicago, IL), your account and trading data is stored and processed in the United States, as are our error-monitoring and payment providers. We use the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum with our US providers to safeguard these transfers.
Waitlist analytics is the exception: we chose PostHog's EU Cloud region, so that data stays inside the European Economic Area and leaves it at no point. Your waitlist entry itself is held in our own database in Chicago, under the same safeguards as the rest of this section.
6. How long we keep data
- Account & broker data - for as long as your account is open. Deletion is immediate when you delete your account from the portal's General → Danger Zone.
- Trade execution & order history - same as the account it belongs to; deleted with the account.
- Invoices & billing records - kept for 7 years after the tax year they relate to, as required by UK tax law (HMRC), even after account deletion.
- Security & abuse logs - 30 days, then automatically purged.
- Email-verification & password-reset tokens - 24 hours and 1 hour respectively, then automatically purged.
- Waitlist entries - 12 months, or until early access opens to you, whichever comes first. Deleted sooner if you ask (see section 7). If you go on to create an account, your waitlist entry is still deleted on this schedule; it is not merged into your account.
- Waitlist analytics events - retained by PostHog for 12 months and then deleted. If you declined the banner there are no events to retain.
7. Your rights
Under UK GDPR / EU GDPR you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data (right to be forgotten). The portal's Delete Account button does this immediately for everything we're not legally required to retain.
- Restrict or object to processing.
- Data portability - receive your data in a machine-readable format.
- Withdraw consent for any processing based on consent, at any time.
- Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
California residents have parallel rights under CCPA, including the right to know, the right to delete, and the right to opt out of the sale of personal information. (Reminder: we do not sell personal information.)
To exercise any of these rights, email [email protected]. We respond within 30 days.
Waitlist entries are not tied to a dashboard account, so the Delete Account button cannot reach them. Email [email protected] from the address you signed up with and we will delete your entry and confirm when it is gone. You do not need an account to ask, and you do not have to give a reason. To withdraw consent for the waitlist page's analytics, clear that site's data in your browser and the banner will ask again on your next visit.
8. Security
The biggest privacy decision you make using OmenSyncer is handing us your broker credentials. We take that seriously. Here is how we protect them:
- Broker credentials & OAuth tokens are encrypted at rest with AES-256. The decryption key lives outside the database (in the engine's process environment), so a database dump alone is not enough to read your credentials.
- Passwords are hashed with bcrypt using a per-user salt. We never store, log, or transmit your plaintext password. Even we cannot recover it - that's why password reset works by emailing a single-use token.
- TLS everywhere. All traffic between your browser, the dashboard, and the engine is encrypted with HTTPS. The engine refuses non-TLS connections in production.
- Card data is held by Stripe, not by us. We never see your card number or CVV. Our database only stores Stripe's customer ID and subscription state.
- Least privilege. Only the engine processes that need to act on your broker can decrypt your credentials. The dashboard server, the database server, and our developer machines cannot.
- Session tokens are signed JWTs stored in your browser and sent as a bearer credential over HTTPS on every request - never placed in a URL, and scrubbed from our error logs. They are short-lived, and signing out clears them.
- Rate limiting on auth endpoints (10 requests/minute/IP on login + register) blocks credential-stuffing attacks at the front door.
- Email-verification and password-reset tokens are single-use and short-lived (24h and 1h respectively), then automatically purged.
No system is perfectly secure. If we ever suffer a personal-data breach that is likely to result in risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR.
Found a security issue? Email [email protected] with the word "security" in the subject. We respond same-day to credible reports.
9. Cookies & local storage
We do not use tracking cookies. To keep you logged in we store a single strictly-necessary item - your signed session token - in your browser's local storage, not in a cookie. Across the dashboard and the desktop app we use no analytics, advertising, or third-party tracking cookies or storage. Because that storage is strictly necessary to deliver a service you asked for, it falls under the "strictly necessary" exemption of the UK PECR / EU ePrivacy rules, so those pages show no cookie consent banner.
The waitlist page
Our waitlist page is the one place we use analytics, and we said in an earlier version of this policy that we would ask before adding any. So we ask. That page shows a banner with Accept and Decline offered equally, and nothing is stored or sent until you choose:
- Before you choose - nothing is loaded. No PostHog script, no cookie, no identifier, no events.
- If you decline - we store one item recording that you declined, so we do not ask again on every visit. Nothing else is stored and nothing is sent. That single item is what makes your refusal stick, which is why it is treated as strictly necessary.
- If you accept - PostHog stores a random identifier in your browser (local storage and a cookie) and records which steps of the form you reached. It is not linked to your name or email, it is not used for advertising, and session recording is switched off, so we never capture what you type.
You can change your mind at any time by clearing that site's data in your browser; the banner will then ask again. Declining costs you nothing: the page and the form behave exactly the same either way.
10. Children
OmenSyncer is not intended for users under 18, and futures trading is not legal for minors in most jurisdictions. We do not knowingly collect personal data from anyone under 18. If you believe a child has signed up, email us and we will delete the account.
11. Changes to this policy
We will update this policy when our practices change. The "Last updated" date at the top reflects the most recent revision. Material changes will be announced by email to your registered address.
12. Contact
Privacy questions, requests, or complaints: [email protected].
