Privacy Policy & Data Protection

Last updated: August 20, 2025

Our Commitment to Your Privacy

Forex Flow is committed to protecting your personal data and respecting your privacy rights. This policy explains how we collect, use, share, and protect your information when you interact with our educational platform and marketing campaigns. We work with leading advertising platforms including Google, Facebook, and Microsoft to deliver relevant content and measure the effectiveness of our educational offerings.

As a provider of forex trading education services, we process personal data to deliver our courses, communicate with students, and conduct marketing activities. We adhere to applicable data protection regulations including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other regional privacy laws.

Your trust is fundamental to our mission of providing quality education in currency trading. We maintain transparent practices about data collection and give you meaningful control over your personal information through privacy settings, opt-out mechanisms, and direct access to your data.

Data Collection by Advertising Platforms

Google Services Data Collection

Google Analytics Data Points:

Page views and session data, bounce rates and engagement metrics, user flow through educational content, device and browser information, geographic location (country/region level), traffic sources and referral websites.

Google Ads Information:

Conversion tracking for course enrollments and inquiries, remarketing audience creation for educational advertising, interest category analysis based on website behavior, click-through rates and advertising interaction data.

Cross-Device Tracking:

When signed into Google services, your activity may be linked across devices to provide consistent advertising experiences and measure cross-device conversions from educational content.

Data Retention Period:

Google Analytics data is retained for 26 months by default. Google Ads data retention varies by campaign type but typically ranges from 30 days to 24 months for conversion tracking.

Facebook/Meta Data Collection

Facebook Pixel Tracking:

Page views and content engagement on educational materials, button clicks and form interactions, scroll depth and time spent on course information, custom events for educational goal tracking.

Custom Audiences Creation:

Website visitor segments for forex education advertising, engagement-based audiences for course promotion, lookalike audiences to reach similar potential students, conversion-based audiences for optimization.

Cross-Platform Integration:

Data sharing across Facebook family of apps including Instagram, WhatsApp, and Messenger for comprehensive advertising reach and measurement.

Data Retention Period:

Facebook typically retains website visitor data for 180 days for remarketing purposes. Conversion data may be retained longer for attribution analysis and campaign optimization.

Microsoft/Bing Data Collection

UET Tag Data Collection:

Conversion tracking for educational goals and course inquiries, page view data and user journey mapping, engagement metrics for forex education content, goal completion and revenue attribution.

Remarketing and Audiences:

Website visitor remarketing lists for Bing Ads, custom audiences based on educational content engagement, demographic targeting for forex trading courses, search behavior analysis for relevant advertising.

Microsoft Account Integration:

If signed into Microsoft services, your activity may be linked across Microsoft's ecosystem including Bing, Outlook, and Office for enhanced advertising targeting.

Data Retention Period:

Microsoft advertising data is typically retained for up to 390 days, with some aggregated performance insights kept longer for reporting and optimization purposes.

How We Use Your Personal Data

Purposes of Data Processing

Service Delivery:

Processing course enrollment applications, delivering educational content and materials, providing customer support and technical assistance, maintaining learning progress and achievements.

Marketing Activities:

Creating and delivering targeted advertising campaigns, measuring marketing effectiveness and ROI, building custom audiences for relevant course promotion, analyzing user interest in trading education topics.

Analytics and Optimization:

Understanding website usage patterns and user behavior, optimizing educational content and user experience, measuring course completion rates and engagement, identifying popular learning topics.

Communication:

Responding to inquiries and course questions, sending important updates about our educational programs, providing customer support and technical assistance, sharing relevant trading education resources.

Legal Compliance:

Meeting regulatory requirements for educational service providers, maintaining records for tax and financial reporting, responding to legal requests and regulatory inquiries, protecting against fraud and abuse.

Security and Fraud Prevention:

Protecting our platform from unauthorized access, detecting and preventing fraudulent activities, maintaining system security and data integrity, ensuring compliance with information security standards.

Legal Basis for Data Processing

Consent (GDPR Article 6(1)(a))

For marketing communications, advertising cookies, personalized content delivery, and optional data processing activities. You can withdraw consent at any time.

Contract Performance (GDPR Article 6(1)(b))

For delivering educational services you've requested, processing course enrollments, providing customer support, and fulfilling our contractual obligations.

Legitimate Interest (GDPR Article 6(1)(f))

For website analytics, security monitoring, fraud prevention, business development, and improving our educational offerings when it doesn't override your privacy rights.

Legal Obligation (GDPR Article 6(1)(c))

For tax reporting, regulatory compliance, responding to legal requests, and meeting obligations under applicable laws and regulations.

Data Sharing with Third Parties

Advertising Platform Partners

Google Ecosystem

  • • Google Analytics & Tag Manager
  • • Google Ads & Display Network
  • • YouTube advertising platform
  • • Google Marketing Platform

Meta/Facebook Services

  • • Facebook Pixel & Conversions API
  • • Instagram advertising
  • • Facebook Audience Network
  • • WhatsApp Business Platform

Microsoft Advertising

  • • Bing Ads & UET tracking
  • • Microsoft Clarity analytics
  • • LinkedIn advertising platform
  • • Microsoft Audience Network

Service Providers & Processors

Web Hosting and Infrastructure: Cloud hosting providers, content delivery networks (CDNs), domain and DNS management services, website security and monitoring tools.

Communication Services: Email service providers for course communications, customer support platforms, video conferencing tools for live education sessions, SMS messaging services (if applicable).

Payment Processing: Payment gateways and processors for course fees, fraud detection and prevention services, accounting and financial reporting tools, tax compliance services.

Educational Technology: Learning management systems, course delivery platforms, student progress tracking tools, educational content management systems.

International Data Transfers

Transfer Safeguards: We ensure adequate protection for international data transfers through EU-US Data Privacy Framework participation, Standard Contractual Clauses (SCCs) approved by the European Commission, and adequacy decisions for certain countries.

Service Provider Locations: Our primary service providers are located in the European Union, United States, and other countries with adequate data protection standards. We maintain contracts requiring appropriate safeguards for personal data protection.

Legal Requirements: We may disclose personal data if required by law, regulation, legal process, or governmental request. We will notify you of such requirements unless legally prohibited from doing so.

Your Privacy Rights & How to Exercise Them

GDPR Rights (EU/UK Residents)

Right to Access (Article 15)

Request a copy of your personal data we're processing, including information about processing purposes, data categories, and recipients.

Right to Rectification (Article 16)

Request correction of inaccurate personal data and completion of incomplete information we hold about you.

Right to Erasure (Article 17)

Request deletion of your personal data when it's no longer necessary, consent is withdrawn, or processing is unlawful.

Right to Data Portability (Article 20)

Receive your personal data in a machine-readable format and transmit it to another data controller.

Right to Object (Article 21)

Object to processing based on legitimate interests, direct marketing, or scientific research purposes.

Right to Restrict Processing (Article 18)

Request limitation of processing when accuracy is contested, processing is unlawful, or for legal claims.

CCPA Rights (California Residents)

Right to Know: Request information about the personal information we collect, use, disclose, and sell, including specific pieces of information and categories of sources.

Right to Delete: Request deletion of personal information we collected about you, subject to certain exceptions for business operations and legal requirements.

Right to Opt-Out: Opt-out of the sale or sharing of your personal information for cross-context behavioral advertising purposes.

Right to Correct: Request correction of inaccurate personal information we maintain about you.

Right to Non-Discrimination: Receive equal service and pricing even if you exercise your privacy rights, though we may offer incentives for data collection.

Direct Privacy Controls

Data Retention & Deletion

Data Retention Periods

Data Type Retention Period Reason
Contact Form Submissions 3 years from last interaction Customer support and course inquiry follow-up
Website Analytics Data 26 months (Google Analytics default) Understanding user behavior and content optimization
Marketing and Advertising Data Until consent withdrawn or 2 years inactive Targeted advertising and campaign measurement
Financial and Legal Records 5-7 years as required by law Tax compliance and regulatory obligations
Security and Access Logs 90 days Security monitoring and incident investigation

Data Deletion Procedures

Automatic Deletion: Most data is automatically deleted after its retention period expires through automated processes. We regularly review and purge expired data according to our retention schedule.

User-Requested Deletion: You can request immediate deletion of your personal data through our contact form. We will process deletion requests within 30 days, subject to legal obligations and legitimate business purposes.

Anonymization Alternative: In some cases, we may anonymize your data instead of complete deletion, removing all personally identifiable information while preserving statistical insights for educational improvements.

Third-Party Coordination: We coordinate with advertising partners (Google, Facebook, Microsoft) to ensure your data is also removed from their systems when you request deletion or withdraw consent.

Backup Systems: Deleted data may remain in backup systems for up to 90 days before being permanently purged. Backup data is not accessible for normal business operations.

Legal Exceptions to Data Deletion

Legal Obligations: We may retain data when required by law, regulation, or court order, such as tax records, financial transaction data, or information subject to legal hold.

Legitimate Business Purposes: Data may be retained for fraud prevention, security monitoring, enforcement of terms of service, or protection of legal rights and interests.

Public Interest: Information may be retained for scientific research, statistical analysis, or public health and safety purposes when properly anonymized.

Freedom of Expression: Content related to public discourse, educational materials, or freedom of expression may be retained even after deletion requests in certain circumstances.