-
Account data: your email address and password (the password is held by our authentication provider in hashed form; we never see it in plain text). Optionally, a display handle if you choose to set one.
-
Evaluation and trading activity: your simulated orders, fills, positions, account stages, rule evaluations, and wallet ledger entries (fees paid, credits granted, amounts earned, withdrawals). Each wallet entry records which of your two balances it moved. This is core product data, generated by using the platform and held server-side in an append-only record.
-
Payment data: payments are processed by CuminPay. CuminPay's card form is rendered inside a Monaco Funded page rather than in a separate window, so the name on your card, your card number, its expiry date, its security code, and any billing address CuminPay asks for are typed on our page and sent from your browser directly to CuminPay. We never receive, transmit, or store your card number, its expiry date, or its security code, and we do not send the name on your card or your billing address to our servers and do not keep them. What reaches us is the payment confirmation, its reference, and the amount.
-
Bank details: if you save bank details for an Earnings withdrawal, we store your first and last name, the bank name, the account type, the account number, and the account currency. You can change them at any time in your account settings. We store them so that a withdrawal can be paid, and we use them for nothing else. We do not check that the account exists or that it belongs to you when you save it, and saving them is not identity verification; that happens separately, at payout stage, as set out below. Where the account is shown back to you, or to us, only the last four digits appear. When you request a withdrawal we attach a copy of the details as they stood at that moment to that request, so that a later change cannot alter a payment already under way. The full account number leaves our systems only in the payment instruction we use to make the payment, and every access to that instruction is recorded.
-
Identity verification data (at payout stage): before a payout is made we are required to verify your identity. We ask for government-issued photo identification, proof of address, and confirmation of the bank account in your name, and we use Didit, a specialist identity-verification provider, to check them. You complete the check on Didit's own verification page: the documents and images you provide go to Didit, not to us. What we receive and keep is the outcome of the verification and the name on the verified identity, which we compare against the name on your bank record; we do not receive or store copies of your documents. What we ask for and why is set out in the AML and Identity Verification Notice. Anti-money-laundering law may require verification records to be retained and certain matters to be reported to the Financial Intelligence Unit of Trinidad and Tobago.
-
Product analytics (web only, only with your consent): which screens are visited and which features are used, tied to a random first-party session identifier. Analytics events never include your name, email, or trading amounts, and they are sent only to our own servers. No third-party analytics service receives anything. On the mobile app, analytics is off.
-
Technical data: IP address, device and browser type, and similar connection data in our server logs, used for security and to operate the service.
-
Age confirmation: when you first open Afterhours, we record that you confirmed you are 18 or over, the wording you agreed to, and the date. We do not collect your date of birth for this purpose.
-
Location check: we check the country you are connecting from on every paid entry, and record the outcome (the resolved country and whether the entry was allowed or refused) because we offer the service only in the countries we support. We record the country, not your IP address, for this purpose.
-
Afterhours records: for each Afterhours evaluation, the session you were shown, the positions you took and when, your result, and what it returned. This is how the round is scored and settled, and how we can re-check a result if you query it.
-
Partner code: if you enter a partner code when you top up your account, we record which code you used and when. We use it to grant your Partner credit and to record what the partner who referred you has earned from your activity. The partner is never told who you are.
-
How you found us: when your account is created we record how you arrived, once: the campaign tags in the link you followed (its source, medium, campaign and content, where the link carried them) and the address of the page that linked you. We keep only the site and page of that address, never anything after it, so if you arrived from a link that carried your email address or a sign-in token in it, that part is discarded before anything is stored. We record this whether or not you accept analytics cookies, because it is a business record of how the account began rather than tracking: it tells us which of our own channels and partners bring people to us, and it is what decides what a partner who referred you has earned. It is written once, at sign-up, and never updated afterwards, so it does not follow what you do later. Most sign-ups record nothing here, and nothing is invented when there is nothing to record. We do not use it for advertising, we do not share it, and it is never used to recognise you on any website or app that is not ours.
-
Push notification token (mobile app only, only if you turn notifications on): if you allow notifications, your device gives us a token that identifies that install so a message can reach it. We store the token, which platform it came from, and when we last saw it. We use it for one purpose: to tell you about your own account -- that an evaluation passed, that an account reached its maximum drawdown, that a daily-loss lockout began, that a funded account is active, or that a withdrawal was accepted, sent or returned. We do not send promotional messages by push, and if you have asked us for a spending limit, a cooling-off period or a self-exclusion we would not send them to you even if we did. Turning notifications off in the app, or in your device settings, stops it: we retire the token and the messages stop. A token identifies an installation of the app, not you, and it is not used for advertising, not shared, and not used to recognise you anywhere else. It is separate from the device identifier described below, which we keep for a different purpose and would keep whether or not you use notifications.
-
Device identification: to enforce the terms of our offers, we identify the device you are using. In our mobile apps this is a random identifier we create once and keep on your device; on the web, where no such identifier exists, we derive a signature from your browser and device settings. We use it to enforce the terms of our offers, currently to limit a partner code to one account and one device. It raises the difficulty of abusing that offer; it does not by itself prevent it, and it is weaker on browsers that resist it. We do not use it for advertising, we do not share it, and we do not use it to recognise you on any website or app that is not ours.
-
Account data: kept while your account is active and for 7 years after closure.
-
Trading, evaluation, and wallet records: kept in an append-only ledger for platform integrity and, once real-money payments and payouts operate, for 7 years, the period financial-recordkeeping and anti-money-laundering law requires. These records may be retained even if you delete your account.
-
Age confirmations and location-check records: kept for as long as the account exists and for 7 years after, as evidence that we applied the age and territory restrictions the law requires of us.
-
Bank details and the payment instructions produced from them: kept while your account is active and for 7 years after closure, the period financial-recordkeeping and anti-money-laundering law requires of payment records.
-
Afterhours records: kept with the trading records above.
-
Partner code records: kept with the wallet records above.
-
Device identification records: kept with the partner code records above.
-
Marketing contact records (what we sent you and your choices about it): kept while your account is active and for 2 years after closure.
-
Analytics events: 24 months.
Copyright 2026 Monaco Western Limited. All rights reserved.