Privacy Policy — Part-Time Quant (PTQ)
Version: 0.1 (draft) Last updated: 27 August 2026 Applies to: part-timequant.com, the PTQ hosted app, and the PTQ desktop OS licence service.
1. Who we are
Lewis Jackson Ventures Ltd (registered in England and Wales, company number 14843004) ("PTQ", "we", "us") operates Part-Time Quant.
- Registered company: Lewis Jackson Ventures Ltd (registered in England and Wales, company number 14843004)
- Registered address: 46 Priory Road, Reigate, Surrey, RH2 8JB, United Kingdom
- ICO registration: 00015214092
- VAT: VAT registered — GB472696843
- Contact for privacy matters: lewis@jackson.ventures
We are the data controller for the personal data described in this policy. We are a UK business and we comply with the UK GDPR and the Data Protection Act 2018.
2. What this policy covers
PTQ has three surfaces. Each handles data differently.
a) The marketing website (part-timequant.com). No accounts, no marketing cookies, no tracking pixels. We use Plausible Analytics in cookieless mode: it counts visits using aggregated, anonymised data and does not store identifiers on your device or build profiles of you. We do not run advertising or cross-site tracking on the site.
b) The hosted app. This is where personal data lives. Details in section 3.
c) The desktop OS (paid licence, runs on your machine). The desktop OS runs locally. Your broker API keys are entered on your machine, stay on your machine, and are never transmitted to us. Live trading happens only on your machine, with your keys, behind an arming step you control each session. We never hold broker credentials, never hold client money, and never execute trades on our servers. The desktop OS contacts our servers only to validate your licence key and device seats (see 3.6).
3. What we collect, and why
3.1 Account data
When you create an account we collect, via Clerk (our authentication provider):
- email address
- name (if you provide one)
- authentication data (password hash or social-login identifier — held by Clerk, not us)
- sign-in timestamps and session tokens
Purpose: creating and securing your account. Lawful basis: performance of a contract (UK GDPR Art. 6(1)(b)); legitimate interests for security logging (Art. 6(1)(f)).
3.2 Product data
While you use the hosted app we store, in our own database:
- strategies you create and their configuration
- risk profiles and settings
- paper trades (simulated fills — clearly labelled as simulated; no real orders)
- backtest and validation results
- usage log (which features you used and when, credit consumption)
- your jurisdiction and consent-gate acknowledgements (see 3.7)
Purpose: providing the product; enforcing credit limits; showing you your own history. Lawful basis: performance of a contract (Art. 6(1)(b)); legitimate interests for the usage log (service integrity, abuse prevention — Art. 6(1)(f)).
We do not store secrets in this database. It is a metadata-only vault: no broker keys, no API secrets, no card details.
3.3 Support conversations
If you open a support ticket or use in-app support chat, we store the conversation. Support messages may be processed by an AI assistant powered by Anthropic to draft or provide responses. The same applies to user-facing AI features inside the app (for example, AI help with building a strategy): your prompts and the app context needed to answer them are sent to Anthropic for processing.
What Anthropic receives: the text of your message and relevant product context. Do not put sensitive personal information into support messages or AI prompts; we do not need it and do not ask for it. Purpose: answering your questions; operating product features you invoke. Lawful basis: performance of a contract (Art. 6(1)(b)); legitimate interests in efficient support (Art. 6(1)(f)).
3.4 Payment data
Payments are handled by Stripe. Card numbers go directly to Stripe and never touch our servers. We receive and keep from Stripe: your name, email, the product purchased, amount, currency, country, and Stripe's identifiers for the customer and subscription.
Purpose: taking payment for the annual plan; managing your subscription; refunds; accounting. Lawful basis: performance of a contract (Art. 6(1)(b)); legal obligation for tax and accounting records (Art. 6(1)(c)).
3.5 Transactional email
We send account and service emails (receipts, licence keys, password resets, service notices) via Resend. We do not send marketing email unless you separately opt in. We do not operate a marketing mailing list. If that changes, this policy will be updated and consent captured separately.
Lawful basis: performance of a contract (Art. 6(1)(b)) for service email; consent (Art. 6(1)(a)) for any marketing email.
3.6 Desktop OS licence checks
The desktop OS validates your licence key with our servers. Each check sends: your licence key, a device identifier (to enforce the 2-device seat limit), app version, and timestamp. That is all. No trading activity, no broker data, no strategy contents, and no file contents from your machine are transmitted.
Purpose: enforcing the licence you bought (2 seats). Lawful basis: performance of a contract (Art. 6(1)(b)).
3.7 Jurisdiction and consent gate
Before using trading-related features you complete a consent gate. We record: the jurisdiction you declare, the acknowledgements you tick (that PTQ is education and tooling, not investment advice), and a timestamp. Checkout is blocked for unsupported jurisdictions, so we also use the declared jurisdiction to decide whether you can buy.
Purpose: compliance with our own terms and with regulatory constraints; evidencing your acknowledgement. Lawful basis: legitimate interests (Art. 6(1)(f)) and legal obligation to the extent applicable (Art. 6(1)(c)).
3.8 Internal operations alerts
Our internal ops alerts (e.g. "a new support ticket arrived") go to a private Telegram channel used by the team. Alerts are written to contain minimal personal data — typically an event type and a ticket or account reference, not message contents. Operator alerts are not metadata-only. If an email to you fails to send, the alert we receive contains your email address, the subject and the full message body so the failure can be put right. Telegram therefore processes personal data on our behalf and is listed as a processor below.
3.9 Market data
Market prices shown in the product come from third-party market data sources (currently yfinance in development; Tiingo planned for production). Requests for market data do not include your personal data.
3.10 What we do not collect
- Broker credentials or API keys — never transmitted to us
- Client money — we never hold funds
- Live trade executions — these happen only on your machine
- Special category data (health, politics, etc.) — we do not ask for it; do not send it to us
- Marketing cookies or advertising identifiers
4. Cookies
Marketing site: no cookies. Plausible runs cookieless. Hosted app: strictly necessary cookies only — set by Clerk to keep you signed in and secure the session, and potentially by Stripe (fraud prevention at checkout, if Stripe.js is embedded) and Cloudflare (bot protection). Because they are strictly necessary for a service you request, they do not require a consent banner under PECR. We do not use analytics or advertising cookies in the app. Our separate Cookie Policy lists every cookie and the full reasoning.
5. Who processes your data (subprocessors)
We use these providers. Each acts as our processor (or, where marked, an independent controller) under contracts that include data-protection terms.
| Provider | Role | What they handle | Location | Notes |
|---|---|---|---|---|
| Clerk | Authentication | Email, name, credentials, sessions | US | Processor |
| Stripe | Payments | Payment and billing data | US / Ireland | Independent controller for payment processing |
| Anthropic | AI processing (support + in-app AI features) | Support messages, AI prompts, product context | US | Processor; API data-training opt-out confirmed |
| Railway | Hosting (app + Postgres database) | All hosted app data | the European Union (Amsterdam) | Processor |
| Cloudflare | DNS, CDN, security | IP addresses and request metadata in transit | Global (US company) | Processor |
| Resend | Transactional email | Email address, email contents | US | Processor; integration pending confirmed |
| Plausible | Website analytics | Aggregated, anonymised visit data only | EU (Estonia/Germany) | No personal data profiles; cookieless |
| Telegram | Internal ops alerts | Minimal event metadata (see 3.8) | Dubai/global | Internal only; no user-facing processing not metadata-only — see the note on failed email delivery above |
| Tiingo | Market data (planned) | No personal data sent | US | Not a personal-data processor if kept to market data only |
We will update this table before adding any new subprocessor that handles personal data.
6. International transfers
Several of our providers are in the United States (Clerk, Stripe, Anthropic, Cloudflare, Resend, and possibly Railway). When your data goes to them, it leaves the UK.
We rely on, in order of preference:
- the UK–US Data Bridge (the UK extension to the EU–US Data Privacy Framework), where the provider is certified; and
- the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, built into each provider's data processing agreement, plus a transfer risk assessment.
7. How long we keep your data
| Category | Retention |
|---|---|
| Account data | While your account exists; deleted on account deletion |
| Product data (strategies, risk profiles, settings, paper trades) | While your account exists; deleted on account deletion |
| Support conversations | 24 months from the closure of the ticket, after which it is deleted |
| Usage log | 12 months on a rolling basis, after which it is deleted |
| Consent-gate records | Duration of account plus |
| Licence/device-seat records | While the licence is active, then 12 months |
| Payment and accounting records (held in Stripe and our accounts) | 6 years from end of the relevant financial year, as required by UK tax law; retained even after account deletion |
| Website analytics | Aggregated and anonymised only; no personal data retained |
When you delete your account, we erase your account and product data (see section 8). Payment records survive because the law requires us to keep them.
8. Your rights
Under the UK GDPR you can:
- Access your data (Art. 15)
- Export it — the app has a built-in export that gives you your product data as JSON
- Correct inaccurate data (Art. 16)
- Delete your account and data (Art. 17) — the app has a built-in account deletion that erases your product data in full; Stripe payment records are retained for accounting as described above
- Restrict or object to processing based on legitimate interests (Arts. 18, 21)
- Port your data to another service (Art. 20)
- Withdraw consent at any time, where consent is the basis (e.g. marketing email, if any)
How to exercise them: use the in-app export and deletion controls, or email lewis@jackson.ventures. We respond within one month. We may ask you to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.
We do not make solely automated decisions with legal or similarly significant effects about you. The jurisdiction checkout block is applied from the jurisdiction you yourself declare, and you can contact us to query it.
9. Complaints
If you are unhappy with how we handle your data, contact us first at lewis@jackson.ventures and we will try to fix it.
You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 ico.org.uk/make-a-complaint
If you are outside the UK, you may also be able to complain to your local data protection authority.
10. Children
PTQ is for adults. You must be 18 or over to create an account. We do not knowingly collect data from anyone under 18. If we learn we hold data on someone under 18, we will delete it. If you believe a minor has an account, contact lewis@jackson.ventures.
11. Security
- All traffic is encrypted in transit (TLS).
- Broker keys never reach our systems — the product is designed so they cannot.
- Our database stores no secrets; it is metadata only.
- Access to production systems is restricted to the team members who need it.
- Payment card data is handled entirely by Stripe (PCI-DSS compliant).
No system is perfectly secure. If a personal data breach occurs that risks your rights, we will notify the ICO within 72 hours where required, and notify you without undue delay where the risk to you is high.
12. Changes to this policy
We will post changes on this page and update the "Last updated" date. For material changes — new purposes, new categories of data, or new subprocessors handling personal data — we will notify account holders by email before the change takes effect. Continued use after the effective date means the new version applies.
13. Contact
Questions about this policy or your data:
Lewis Jackson Ventures Ltd (registered in England and Wales, company number 14843004) 46 Priory Road, Reigate, Surrey, RH2 8JB, United Kingdom Email: lewis@jackson.ventures