MONACO FUNDED

Privacy Policy - Monaco Funded

Last updated: 5 September 2026. Operated by Monaco Western Limited, trading as Monaco Funded, Trinidad and Tobago. Contact: .

What Monaco Funded is

Monaco Funded is a simulated US-equity trading evaluation platform. You trade a simulated account against real market prices; there is no real-money market exposure, no brokerage account, and no securities custody. This shapes what data we hold: trading records describe simulated activity on our own platform.

Data we collect

-
Account data: your email address and password (the password is held by our authentication provider in hashed form; we never see it in plain text). Optionally, a display handle if you choose to set one.
-
Evaluation and trading activity: your simulated orders, fills, positions, account stages, rule evaluations, and wallet ledger entries (fees paid, credits granted, amounts earned, withdrawals). Each wallet entry records which of your two balances it moved. This is core product data, generated by using the platform and held server-side in an append-only record.
-
Payment data: payments are processed by CuminPay. CuminPay's card form is rendered inside a Monaco Funded page rather than in a separate window, so the name on your card, your card number, its expiry date, its security code, and any billing address CuminPay asks for are typed on our page and sent from your browser directly to CuminPay. We never receive, transmit, or store your card number, its expiry date, or its security code, and we do not send the name on your card or your billing address to our servers and do not keep them. What reaches us is the payment confirmation, its reference, and the amount.
-
Bank details: if you save bank details for an Earnings withdrawal, we store your first and last name, the bank name, the account type, the account number, and the account currency. You can change them at any time in your account settings. We store them so that a withdrawal can be paid, and we use them for nothing else. We do not check that the account exists or that it belongs to you when you save it, and saving them is not identity verification; that happens separately, at payout stage, as set out below. Where the account is shown back to you, or to us, only the last four digits appear. When you request a withdrawal we attach a copy of the details as they stood at that moment to that request, so that a later change cannot alter a payment already under way. The full account number leaves our systems only in the payment instruction we use to make the payment, and every access to that instruction is recorded.
-
Identity verification data (at payout stage): before a payout is made we are required to verify your identity. We ask for government-issued photo identification, proof of address, and confirmation of the bank account in your name, and we use Didit, a specialist identity-verification provider, to check them. You complete the check on Didit's own verification page: the documents and images you provide go to Didit, not to us. What we receive and keep is the outcome of the verification and the name on the verified identity, which we compare against the name on your bank record; we do not receive or store copies of your documents. What we ask for and why is set out in the AML and Identity Verification Notice. Anti-money-laundering law may require verification records to be retained and certain matters to be reported to the Financial Intelligence Unit of Trinidad and Tobago.
-
Product analytics (web only, only with your consent): which screens are visited and which features are used, tied to a random first-party session identifier. Analytics events never include your name, email, or trading amounts, and they are sent only to our own servers. No third-party analytics service receives anything. On the mobile app, analytics is off.
-
Technical data: IP address, device and browser type, and similar connection data in our server logs, used for security and to operate the service.
-
Age confirmation: when you first open Afterhours, we record that you confirmed you are 18 or over, the wording you agreed to, and the date. We do not collect your date of birth for this purpose.
-
Location check: we check the country you are connecting from on every paid entry, and record the outcome (the resolved country and whether the entry was allowed or refused) because we offer the service only in the countries we support. We record the country, not your IP address, for this purpose.
-
Afterhours records: for each Afterhours evaluation, the session you were shown, the positions you took and when, your result, and what it returned. This is how the round is scored and settled, and how we can re-check a result if you query it.
-
Partner code: if you enter a partner code when you top up your account, we record which code you used and when. We use it to grant your Partner credit and to record what the partner who referred you has earned from your activity. The partner is never told who you are.
-
How you found us: when your account is created we record how you arrived, once: the campaign tags in the link you followed (its source, medium, campaign and content, where the link carried them) and the address of the page that linked you. We keep only the site and page of that address, never anything after it, so if you arrived from a link that carried your email address or a sign-in token in it, that part is discarded before anything is stored. We record this whether or not you accept analytics cookies, because it is a business record of how the account began rather than tracking: it tells us which of our own channels and partners bring people to us, and it is what decides what a partner who referred you has earned. It is written once, at sign-up, and never updated afterwards, so it does not follow what you do later. Most sign-ups record nothing here, and nothing is invented when there is nothing to record. We do not use it for advertising, we do not share it, and it is never used to recognise you on any website or app that is not ours.
-
Push notification token (mobile app only, only if you turn notifications on): if you allow notifications, your device gives us a token that identifies that install so a message can reach it. We store the token, which platform it came from, and when we last saw it. We use it for one purpose: to tell you about your own account -- that an evaluation passed, that an account reached its maximum drawdown, that a daily-loss lockout began, that a funded account is active, or that a withdrawal was accepted, sent or returned. We do not send promotional messages by push, and if you have asked us for a spending limit, a cooling-off period or a self-exclusion we would not send them to you even if we did. Turning notifications off in the app, or in your device settings, stops it: we retire the token and the messages stop. A token identifies an installation of the app, not you, and it is not used for advertising, not shared, and not used to recognise you anywhere else. It is separate from the device identifier described below, which we keep for a different purpose and would keep whether or not you use notifications.
-
Device identification: to enforce the terms of our offers, we identify the device you are using. In our mobile apps this is a random identifier we create once and keep on your device; on the web, where no such identifier exists, we derive a signature from your browser and device settings. We use it to enforce the terms of our offers, currently to limit a partner code to one account and one device. It raises the difficulty of abusing that offer; it does not by itself prevent it, and it is weaker on browsers that resist it. We do not use it for advertising, we do not share it, and we do not use it to recognise you on any website or app that is not ours.

What we do not collect

We do not use third-party advertising or tracking cookies, we do not run third-party analytics, we do not profile you across other sites or apps, and we do not sell personal data. Market data flows into the platform from our data vendors; no personal data flows out to them.

The leaderboard is pseudonymous by default

The weekly leaderboard displays every participant under an assigned pseudonym. Your real handle appears only if you explicitly opt in, and you can revert to the pseudonym at any time in your account settings.

Data stored on your device

-
Web: your signed-in session token, your cookie-consent choice, an analytics session identifier (only after you accept analytics), and interface preferences (for example theme, sound setting, chart layout, last viewed symbol). All first-party, stored in browser local storage. See the Cookie Policy.
-
Mobile app: your session token is stored in the operating system's encrypted store (iOS Keychain / Android Keystore). One-time flags (for example, that you have seen the welcome walkthrough) are stored on-device. Analytics is off on the app.

Who processes data for us

We share personal data only with service providers under contract who help us run the platform:
-
Supabase - authentication and database hosting Virginia, United States.
-
Railway - trading-engine hosting Virginia, United States.
-
Expo (EAS) - delivery of app updates to the mobile app.
-
Apple and Google - app distribution on their stores.
-
CuminPay - payment processing, once live.
-
Didit - identity verification before your first withdrawal. You provide your identity documents on Didit's own verification page; we receive the outcome and the name on the verified identity, and we do not receive or store copies of your documents.
-
Supabase - transactional email (account verification and password reset)
Our market-data vendors (Databento, CoinAPI) supply data to us and do not receive personal data. We may disclose personal data where required by law or a regulator.

International transfers

Our databases and trading engine are hosted in Virginia, in the United States. Your personal data is therefore processed outside Trinidad and Tobago. We transfer it because it is necessary to perform our contract with you, and we require our providers by contract to protect it to the standard described in this policy.

Retention

-
Account data: kept while your account is active and for 7 years after closure.
-
Trading, evaluation, and wallet records: kept in an append-only ledger for platform integrity and, once real-money payments and payouts operate, for 7 years, the period financial-recordkeeping and anti-money-laundering law requires. These records may be retained even if you delete your account.
-
Age confirmations and location-check records: kept for as long as the account exists and for 7 years after, as evidence that we applied the age and territory restrictions the law requires of us.
-
Bank details and the payment instructions produced from them: kept while your account is active and for 7 years after closure, the period financial-recordkeeping and anti-money-laundering law requires of payment records.
-
Afterhours records: kept with the trading records above.
-
Partner code records: kept with the wallet records above.
-
Device identification records: kept with the partner code records above.
-
Marketing contact records (what we sent you and your choices about it): kept while your account is active and for 2 years after closure.
-
Analytics events: 24 months.
-
Server logs: 90 days.

Marketing messages

We may send you promotional messages about Monaco Funded. This is a new purpose for data we already hold: your email address was collected so your account could work, and using it to tell you about offers, features or competitions is a different thing from using it to tell you about your own account.
-
Email. We may send promotional email to the address on your account. Every promotional email carries a way to stop it, and stopping it never affects your access to anything. Messages about your own account, such as a password reset, a receipt, or an evaluation result, are not promotional and continue either way.
-
SMS. We do not send promotional SMS unless you have asked us to, as a separate and explicit choice. Turning it on is an act you take; we do not read consent into a phone number you gave us for another reason.
-
Push. We do not send promotional push notifications. The notification token is used only to tell you about your own account, as described above.
Promotional messages respect your responsible-participation choices. If you have an active spending limit, a cooling-off period, or a self-exclusion, we do not send you promotional messages on any channel. That promise is in our Responsible Participation Policy and it applies to email and SMS exactly as it applies to push.
What we rely on. Promotional messaging is not necessary to provide the service, so it does not ride the contractual basis above. You can stop it at any time and keep everything else.

Your rights

Subject to the retention obligations above, you may request access to, correction of, or deletion of your personal data, and you may withdraw analytics consent at any time (Cookie settings on the web). Contact and we will respond within 30 days.
What we rely on to process your data. Most of what we hold is not based on your consent, and you should know that, because it affects what you can ask us to delete. We process your account, trading, wallet, age and location records because we need them to provide the service you contracted for, and we keep the financial and verification records because the law requires us to. Neither of those depends on consent, and neither can be withdrawn while the obligation lasts. Analytics is the only thing we ask consent for, and you can withdraw it at any time without affecting your access to anything.

Changes

We will update this policy as the product and the regulatory position evolve, and will post the date of the latest version here. Material changes will be announced in the app.
Copyright 2026 Monaco Western Limited. All rights reserved.