Legal

PRIVACY POLICY

Last updated: 11 April 2026

2GS Trading ("we", "us", or "our") is committed to protecting your personal information in accordance with the Protection of Personal Information Act, 4 of 2013 ("POPIA"). This Privacy Policy explains how we collect, use, share, and safeguard your personal information when you use our website at www.2gs-trading.com and related services (collectively, the "Platform").

By registering an account or using our Platform, you acknowledge that you have read and understood this Privacy Policy.

1. Responsible Party

Under POPIA, 2GS Trading is the "responsible party" — the entity that determines the purpose and means of processing your personal information.

2. Information We Collect

We collect personal information in the following circumstances:

a) Account Registration

  • Full name
  • Email address
  • Password (stored in hashed/encrypted form — never in plain text)
  • XM MT5 account number (optional, provided voluntarily during sign-up)

b) Contact Form

  • Name
  • Email address
  • Subject of enquiry
  • Message content

c) Seminar Registration

  • First name and last name
  • Email address
  • Trading experience level (beginner / some experience / intermediate / advanced)

d) Dashboard — XM Account Linking

  • XM MT4/MT5 login numbers (used to verify trading activity under our partner code)
  • Account nickname/label
  • Trading platform selection (MT4 or MT5)
  • Bot magic number configuration (for Gold Sentinel EA)
  • Account balance and equity data (retrieved from the XM API)
  • Trade history and volume statistics (retrieved from the XM API for reward calculations)

e) IRON2000 Indicator Access

  • TradingView username (provided to request access to the IRON2000 Pine Script indicator)

f) Automatically Collected Information

  • Session cookies: We use Supabase authentication session cookies to keep you logged in. These are functional cookies required for the Platform to operate and are not used for tracking.
  • Local storage: We store a single flag ("welcome modal seen") in your browser's local storage after your first login.
  • Page view analytics: We use Vercel Analytics and Vercel Speed Insights to collect anonymised page view and web performance data. These tools do not use tracking cookies and do not collect personally identifiable information.

3. Purpose of Processing

We process your personal information only for the following purposes (POPIA Section 13):

  • Creating and managing your account on the Platform
  • Verifying your XM trading account under our Introducing Broker partner code ("2GSGOLD") to unlock tool access and calculate cashback rewards
  • Providing access to our trading tools: Gold Sentinel EA, NAS Striker EA, IRON2000 TradingView indicator, and the Trading Journal
  • Sending transactional emails (registration confirmation, password resets)
  • Sending educational and marketing communications (seminar invitations, drip email campaigns) — only to users who have registered or subscribed
  • Responding to contact form enquiries
  • Managing seminar registrations and sending event-related emails
  • Monitoring and improving Platform performance and user experience
  • Complying with applicable laws and regulations

4. Legal Basis for Processing

We process your personal information on the following grounds (POPIA Section 11):

  • Consent: You provide consent when you register an account, submit a contact form, or sign up for a seminar.
  • Contractual necessity: Processing is necessary to provide the services you have requested (e.g., linking your XM account to receive tool access and cashback rewards).
  • Legitimate interest: We use anonymised analytics to improve the Platform. This does not override your privacy rights.
  • Legal obligation: We may process information where required by South African law.

5. Third-Party Data Sharing

We do not sell your personal information. We share your information only with the following third parties, and only to the extent necessary to provide our services:

Supabase

Our authentication and database provider. Your account data, XM account details, and usage data are stored on Supabase's infrastructure. Supabase processes data in accordance with applicable data protection laws.

Resend

Our transactional email delivery provider. When you submit a contact form or register for a seminar, your name and email address are added to a Resend audience list for email communication purposes.

XM (Trading Point of Financial Instruments Ltd)

When you link your XM trading account, your MT4/MT5 login numbers are sent to the XM Partner API to verify your account, retrieve trading statistics, and calculate cashback rewards. XM is independently regulated. We do not share your name, email, or password with XM — only trading account identifiers.

TradingView

When you request access to the IRON2000 indicator, your TradingView username is sent to TradingView's API so that we can grant you access to the private Pine Script.

Vercel

Our hosting and deployment provider. Vercel may process server logs including IP addresses as part of standard hosting operations. Vercel Analytics processes anonymised performance data.

SMTP Provider (mail.2gs-trading.com)

We operate our own mail server for sending CRM email campaigns to registered members. Your email address and name are used as recipient information.

Whop

If you purchase a Project G mentorship subscription, you are redirected to Whop's platform for payment processing. We do not receive your payment card details. Whop's own privacy policy governs data collected during checkout.

6. Cookies and Local Storage

We use a minimal set of cookies and browser storage:

NameTypePurpose
sb-*-auth-tokenSession CookieKeeps you authenticated. Required for the Platform to function.
2gs_welcome_seenLocal StorageRemembers that you have seen the welcome modal. No personal data.

We do not use advertising cookies, third-party tracking cookies, or any cookie that monitors your behaviour across other websites. Vercel Analytics is cookieless by design.

7. Data Retention

  • Account data is retained for as long as your account is active. You may request deletion at any time (see Section 8).
  • Contact form submissions are retained for up to 24 months to allow us to respond to follow-up enquiries.
  • Seminar registrations are retained for up to 12 months after the relevant seminar date.
  • XM trading data (balance, trade history) is synced periodically from XM's API and retained for the duration of your account.
  • Analytics data is subject to Vercel's own retention policies (typically 30–90 days).

8. Your Rights Under POPIA

Under POPIA Sections 23–25, you have the following rights regarding your personal information:

  • Right of access: Request a copy of the personal information we hold about you.
  • Right to correction: Request correction of inaccurate or incomplete information.
  • Right to deletion: Request deletion of your personal information, subject to any legal obligations we may have to retain it.
  • Right to object: Object to the processing of your personal information for direct marketing purposes.
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent. This does not affect the lawfulness of processing before withdrawal.
  • Right to lodge a complaint: If you believe your rights have been violated, you may lodge a complaint with the Information Regulator of South Africa at POPIAComplaints@inforegulator.org.za or visit www.justice.gov.za/inforeg/.

To exercise any of the above rights, email us at support@2gs-trading.com. We will respond within 30 days.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, or misuse:

  • All data is transmitted over HTTPS (TLS encryption)
  • Passwords are stored using industry-standard hashing — never in plain text
  • Database access is controlled by Supabase Row Level Security (RLS) policies
  • API keys and credentials are stored as environment variables, not in source code
  • Rate limiting is applied to all public-facing API endpoints to prevent abuse
  • All user-submitted input is sanitised before storage to prevent injection attacks

No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security.

10. Children's Privacy

Our Platform is not directed at persons under the age of 18. We do not knowingly collect personal information from children under 18. In compliance with POPIA Section 35, if we become aware that a child under 18 has provided us with personal information without verifiable parental consent, we will delete that information promptly. If you believe a minor has provided us with personal information, please contact us at support@2gs-trading.com.

11. International Data Transfers

Some of our third-party service providers (including Vercel, Supabase, and Resend) may process your personal information outside of South Africa, including in the United States and the European Union. Where such transfers occur, we ensure that adequate safeguards are in place through our service agreements with those providers. By using our Platform, you acknowledge and consent to such transfers where necessary for the provision of our services.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify registered users via email. Continued use of the Platform after any change constitutes your acceptance of the updated policy.

13. Contact Us

For any questions, requests, or complaints regarding this Privacy Policy or our data practices, please contact us:

You also have the right to lodge a complaint with the Information Regulator of South Africa — the supervisory authority for POPIA — at POPIAComplaints@inforegulator.org.za.