This Privacy Policy explains what Prop Firm Empires ("we," "us," the "Service") collects, why, and what you can do about it. Prop Firm Empires is operated by Prop Firm Empires, a sole proprietorship based in British Columbia, Canada.
If you take nothing else from this page: the site collects almost nothing today. No cookies, no analytics, no ad trackers. Read on for the specifics, including what changes once accounts and payments launch.
1.Scope
This policy covers:
- propfirmempires.com (the marketing site)
- The Forge (the Windows desktop app)
- Command (the web dashboard)
It does not cover third-party sites we link to (your broker, NinjaTrader, Kinetick, etc.) — their own privacy policies apply once you leave our site or connect through their login pages.
2.What we collect today
The website. propfirmempires.com sets zero cookies and runs zero analytics or advertising trackers. We don't use Google Analytics, Meta Pixel, or anything similar. There is no visitor tracking, no cross-site tracking, and no advertising profile built on you.
The one thing that's true of any hosted website: our hosting provider (Vercel) automatically logs standard connection information for every request — IP address, browser/user-agent string, timestamp, page requested — the way any web server does, for security and abuse-prevention purposes. We don't access this for analytics or marketing, and we don't combine it with anything else about you.
Fonts. Our pages load their typefaces from Google Fonts, so when a page loads your browser requests font files from Google's servers (fonts.googleapis.com and fonts.gstatic.com). That request carries your IP address and user-agent to Google, the way a request to any server does. It sets no cookie, sends nothing about you to us, and builds no advertising profile — but it is a third party seeing your IP on an ordinary visit, so we name it here rather than let "no trackers" quietly cover it. The claim above is scoped exactly as written: no analytics and no advertising trackers run on this site. A font request is neither, and it is the only third-party request a normal page view makes.
The feedback form (the "Tell us something" box on the FAQ page). If you use it, we receive the message you typed and, if you chose to include one, your email address. Today that's delivered one of two ways depending on what's live at the moment: either as an email to us via your own mail client (a mailto: link — nothing touches our servers) or, once our backend is live, stored directly in our database for us to read. Either way: it's private. It goes to us, not published anywhere, and we don't add you to any mailing list from it.
The Forge (desktop app). The Forge stores your data — trading session logs, discipline tracking, your local settings — on your own machine. Nothing is uploaded to us. If the app crashes, a crash log is written to your local disk only; we never see it or receive it automatically. If you choose to send us a crash log yourself (e.g., attaching it to a support email), that's on you and covered like any other message you send us.
Broker connection (OAuth). When you connect a broker (Tradovate today), you're sent to your broker's own login page and you type your password there — never into the Forge or Command. We never see, receive, or store your broker password. What comes back is an access token, which is encrypted and stored on your machine. Your broker credentials never touch our servers, in any phase of this product.
Command (web dashboard). Command has accounts now. You can create one at command.propfirmempires.com to hold your place while access opens in waves, and doing so gives us the account data described in §4 — which is live today, not planned. Your trading data still lives on your own machine: an account is an identity and a place in the queue, not a copy of your logs.
3.What we don't do
- We don't sell your data. We never have, and we don't plan to.
- We don't share data with data brokers or ad networks.
- We don't build advertising profiles.
- We don't have a mailing list you've been silently added to.
4.Accounts (live today) & payments (not yet)
Status, plainly: accounts are live; payments are not. You can create an account today, and when you do, Supabase processes your account data now — that half of this section is in effect, not planned. Everything about payments (via Stripe) is still the planned future state: there is nothing to buy yet, no card details are collected, and no payment data of yours exists. Each item below is flagged accordingly.
- Account data — live today. To create an account you provide an email address and a password, or you sign in with Google, an optional identity provider. This is handled by Supabase, our authentication and database provider. We store the account information needed to run the Service — email, account status, and settings you explicitly save to your account. If you choose Google sign-in, you authenticate on Google's own page, Google learns that you signed in to this Service, and we receive your email address and basic profile identifiers from Google — never your Google password. Signing up with an email address and a password instead keeps Google out of it entirely.
- Payment data — planned, not active. When payments launch they will be processed by Stripe. We will not receive or store your full card number — Stripe handles that directly and is itself a regulated payment processor (PCI-DSS compliant). We will receive and store what's needed to run your subscription: your billing email, subscription status/plan, and transaction history (amounts, dates, Stripe's transaction ID). None of this exists today.
- Why we collect it. To create and secure your account, provide customer support, prevent fraud, and — once payments launch — process payment and comply with tax/accounting obligations.
- Who it's shared with. Only the service providers who need it to do their job — Supabase (hosting your account data, today), Google (only if you choose Google sign-in), and Stripe (processing payment, once payments launch). We don't sell it, and we don't hand it to anyone else. See §3.
5.How we use what we collect
- To provide and operate the Service.
- To respond to feedback, support requests, and questions.
- To detect, prevent, and respond to fraud, abuse, or security issues.
- To meet legal and tax obligations (post-launch, for payment records).
We do not use anything we collect to build advertising profiles, and we don't run targeted ads.
6.Data retention
- Feedback messages are kept as long as reasonably needed to act on them, then deleted or archived.
- Standard hosting logs (§2) are retained on whatever short rolling window our hosting provider (Vercel) uses by default — we don't export or separately archive them.
- Account data is retained for as long as your account is active, and deleted on request under §7. Billing data, once payments launch, is retained for as long as your account is active plus whatever period is needed for tax/accounting recordkeeping after that (typically several years — final number to be set when payments launch).
7.Your rights and choices
- Delete your data. Email us at support@propfirmempires.com and we'll delete what we hold about you, other than what we're legally required to keep (e.g., completed transaction/tax records post-launch).
- Correct your data. Same address — tell us what's wrong and we'll fix it.
- Opt out of anything. There's currently nothing to opt out of — no marketing emails are sent, no tracking runs. If that changes, this section will be updated with a real opt-out method before it happens.
8.Privacy law — where we honestly stand (Canada, California, EU)
We operate from British Columbia, Canada, so Canadian privacy law is our baseline — and we're not going to paste in generic boilerplate that doesn't reflect this business. Here's the plain version:
- Canada (PIPEDA and BC PIPA). As a BC-based business engaged in commercial activity, our obligations come from Canada's federal Personal Information Protection and Electronic Documents Act and British Columbia's own Personal Information Protection Act. The practices described above are how we meet them: we collect almost nothing, we tell you exactly what we collect and why, we use it only for those stated purposes, and the correct/delete contact in §7 works without any formal process. If you ever want to escalate beyond us, the Office of the Privacy Commissioner of Canada and BC's Office of the Information and Privacy Commissioner both accept complaints.
- California (CCPA). California's privacy law generally applies to businesses that cross one of three thresholds: roughly $26.6M+ in annual revenue, buying/selling/sharing the personal information of 100,000+ California consumers or households, or deriving over half of revenue from selling personal data. A small, pre-launch, no-ad-tech operation like this one does not meet any of those thresholds today. If that changes — meaningful scale, or data practices that involve selling/sharing personal information — this section gets a real legal review, not just an edit.
- GDPR. The EU's GDPR generally reaches a business outside the EU — ours is Canadian — when it actively offers goods/services to people in the EU or monitors their behavior — not simply because an EU visitor can load the site. We don't price in euros, target EU audiences, or run behavioral tracking of any kind, so GDPR's extraterritorial "targeting" trigger does not currently apply. If you're in the EU and use the Service anyway, we still won't sell your data or track you — the practical protections above apply to everyone regardless of location.
Either way: contact §7 above works for anyone, anywhere, who wants their data corrected or deleted.
9.Children's privacy
The Service is not directed at children, and we don't knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we'll remove it.
10.Security
We take reasonable measures to protect what limited data we do hold — encrypted broker tokens stored locally on your machine, no server-side storage of broker credentials, and reliance on the security infrastructure of established providers rather than building our own — Supabase for account data today, Stripe for payment data once payments launch. No method of storage or transmission is 100% secure, and we can't guarantee absolute security.
11.Changes to this policy
We may update this policy as the product changes — most recently on August 28, 2026, when accounts went live and §4's account half moved from "planned" to "in effect." The next such change is payments. We'll update the "Last updated" date at the top. Material changes will be called out on the site rather than buried in a silent edit.
12.Contact
Questions, deletion requests, or anything else: support@propfirmempires.com