Legal
Privacy policy
Last updated: 2026-05-24
BloxTrade (“we”, “us”) provides a Roblox trade calculator and portfolio tracker. This policy explains what data we collect, how we use it, and your rights. A plain-language summary for younger users lives at /kids-privacy.
Data we collect
- Account info: email, password hash, optional display name, birth year, country/region.
- Roblox connection (optional): Roblox user ID and username, profile image, and an encrypted refresh token. Inventory data (limited items you own).
- Product activity: trades you save, listings you create, alert preferences.
- Operational logs: request metadata, error reports (with PII scrubbed).
Purposes
- Operate the calculator, portfolio sync, and listings.
- Authenticate you and protect your account.
- Comply with COPPA, GDPR-K, and the UK Children's Code.
- Diagnose problems and improve the product (analytics with under-13 profiling disabled).
Children (COPPA, GDPR-K, UK Children's Code)
We require a verifiable parental consent step for users under 13. We hold the account inactive until a parent approves. Under-13 users see no behavioural advertising, no retargeting, no third-party profiling pixels. Parents may revoke consent at any time by emailing privacy@bloxtrade.com; we will close the account and delete data within 30 days.
Sharing
We do not sell personal data. Subprocessors used to operate the product: Convex (database), Vercel (hosting), Resend (email), Sentry (errors). Future ad providers, when introduced, will be limited to contextual-only networks for under-13 traffic.
Retention
Account data is retained while your account is active. After deletion, data is purged within 30 days. Encrypted refresh tokens are deleted when you disconnect Roblox or close the account.
Your rights
- Access — download your data from Settings.
- Deletion — delete your account from Settings.
- Correction — email privacy@bloxtrade.com.
- Object/restrict — contact us; we comply with applicable law.
Roblox disclaimer
BloxTrade is not affiliated with, endorsed, or sponsored by Roblox Corporation. We use Roblox's Open Cloud OAuth 2.0 with read-only scopes you approve.