Privacy Policy
Stampede Ltd (Cyprus) · stampedeprop.com · last updated July 20, 2026
Section 01
Who we are and how to reach us
Stampede Ltd, a company registered in Cyprus under number HE 494949, with its registered office at Nikis 1, Anthoupoli, 2350 Nicosia, Cyprus, operates Stampede at stampedeprop.comand is the organisation responsible for personal data collected through it (the controller, in GDPR terms). We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) as implemented in Cyprus by Law 125(I)/2018 and, where they apply to you, the UK GDPR and US state privacy laws.
For privacy requests, including access, correction, and deletion, contact privacy@stampedeprop.com. That address reaches the person responsible for ensuring our compliance with the GDPR and Cyprus data protection law (Law 125(I)/2018).
Section 02
What this policy covers
This policy covers personal data collected through the Website and, from launch, the Stampede trading dashboard and evaluation service. It does not cover third party websites we link to, or LHFX, which is a separate brand and service with its own privacy policy. We have written this policy in two layers on purpose: what we collect today through the Website, and what will be collected from the day challenges go on sale. Launch-time provisions are marked and take effect at launch, not before.
Section 03
What we collect today
The Website today collects the analytics, marketing attribution, and device and log data described in the sections below. It does not run a signup form or ask you for an email address. Account, purchase, and identity data are collected in the Stampede dashboard from launch, as set out next. We do not buy, rent, or append personal data.
To understand which marketing channel brought you here, we record the campaign tags in the link you arrived on (the utm parameters), the website that referred you, and the page you first landed on, and we keep this in a first party cookie described in the cookies section. On its own it does not identify you. If you later create an account, it is associated with that account so we can see which channels bring real customers, for our own measurement only.
Section 04
What we will collect at launch
The following categories take effect when challenges go on sale, and this section will be updated to present tense at that point.
Account data
Name, email address, country of residence, password (stored hashed), and your dashboard settings.
Marketing attribution
The marketing source associated with your signup, resolved from the attribution cookie described above: for example the channel (such as a search engine or social platform), the campaign tags, the referring site, and the page you first landed on. We use it to measure which channels bring customers, not to build advertising profiles.
Purchase and payment data
The plan and size you purchase, the fee paid, and payment confirmation from our payment processor. Card numbers are collected and processed by the payment processor, not by us; we receive a token and the last four digits at most.
Identity verification (KYC) data
Collected before your first payout, not at checkout: government identity document, proof of address, date of birth, photograph or liveness check, and sanctions screening results. Processed through a specialist verification provider.
Trading activity on simulated accounts
Orders, positions, balances, and rule events (targets reached, loss limits breached) on your simulated accounts, generated through the trading platform. This is how the evaluation is scored, so it is inseparable from the service.
Payout data
The payout method you register, amounts requested and paid, and records we must keep under anti money laundering law.
Support and communications
Messages you send us and our replies.
Device and log data
IP address, browser and device information, and access logs, used for security, fraud prevention (including detection of account sharing and coordinated trading), and service operation.
Section 05
Why we use your data, and our legal bases
We collect, use, and disclose personal data only for the purposes set out below, each with a legal basis under the GDPR as implemented in Cyprus (Law 125(I)/2018). Where the UK GDPR or a US state law applies to you, the equivalent basis applies.
- Measuring website traffic and improving the site: analytics as described in the cookies section (GDPR: consent or legitimate interests, depending on your settings).
- Attributing which marketing channel a visit, and later a signup, came from, using the attribution cookie described in the cookies section: consent or legitimate interests, depending on your settings, balanced against your rights (GDPR: legitimate interests or consent).
- Providing the service you purchase, scoring evaluations, operating funded accounts, and paying you: performance of a contract (GDPR: contract).
- KYC, sanctions screening, and anti money laundering record keeping: legal obligation.
- Fraud prevention and enforcement of the prohibited practices rules, including cross-account analysis: legitimate interests, balanced against your rights (GDPR: legitimate interests).
- Service emails about your account, rule events, and payouts: performance of a contract. These are not marketing and do not carry an unsubscribe requirement.
- Marketing beyond launch updates, if we ever do it: only with consent, separately collected, never assumed.
We do not sell personal data, and we do not use it for automated decisions producing legal effects other than the mechanical scoring of evaluations against published rules, which is the service itself.
Section 08
International transfers
We are a Cyprus company and our processors operate in several countries, so personal data crosses borders. Under the GDPR we transfer personal data outside the European Economic Area only where the recipient is covered by an adequacy decision, standard contractual clauses, or another lawful transfer mechanism. US customer data may be processed in the United States by US-based processors.
Section 09
How long we keep data
- Account and trading data: for the life of your account and a limited period after closure for dispute resolution.
- KYC and payout records: the retention period required by anti money laundering law, typically five years from the end of the relationship.
- Support correspondence: for the period needed to handle the matter and any related dispute.
We anonymise or delete personal data when the purpose for which it was collected, and any legal retention obligation, has ended.
- Account and dashboard data: while your account is open, then two years.
- Purchase, payout, KYC, and sanctions screening records: five years after the relationship ends, the standard record keeping period under Cyprus and EU anti money laundering law.
- Trading activity on simulated accounts: five years, because it evidences evaluation outcomes, payouts, and rule enforcement.
- Support correspondence: two years after the ticket closes.
- Device and access logs: twelve months.
Where a live dispute or legal obligation requires longer retention, the affected records are kept until it ends.
Section 10
Your rights
Under the GDPR you may request access to the personal data we hold about you and information about how it has been used and disclosed, and request correction of errors. We respond within the timelines the GDPR sets, normally within one month, and access is provided free of charge except where a request is manifestly unfounded or excessive.
You also have the rights to:
- erasure of data we no longer need;
- restriction of processing while a dispute about it is resolved;
- portability of data you provided to us, in a machine readable format;
- object to processing based on legitimate interests; and
- withdraw consent at any time, without affecting prior processing.
Rights requests go to the privacy contact in Section 1. We will verify your identity before acting on a request, using no more data than verification needs.
Section 11
US state privacy rights
If you live in California, Colorado, Connecticut, Texas, Virginia, or another US state with a comprehensive privacy law, you may have rights to know, access, correct, and delete personal data, and to opt out of its sale or sharing for targeted advertising. Two facts make most of those opt-outs simple here: we do not sell personal data, and we do not share it for cross-context behavioural advertising. We honor browser Global Privacy Control signals where the law gives them effect. We will not discriminate against you for exercising a privacy right.
Section 12
Security
We protect personal data with measures appropriate to its sensitivity: encryption in transit, hashed credentials, access controls limiting staff access to what their role requires, and contractual security obligations on every processor. KYC documents are held by the verification provider, not on our web infrastructure. If a data breach creates a risk of significant harm, we will notify the Office of the Commissioner for Personal Data Protection in Cyprus and, where required, affected individuals, as the GDPR requires, and any other regulator whose law applies.
Section 13
Children
The service is for adults. We do not knowingly collect personal data from anyone under 18, and we delete it if we learn we have. KYC at the payout stage enforces this for every funded trader.
Section 14
Changes and complaints
We will update this policy as the service grows, and material changes will be announced to registered users before they take effect, with the launch-time sections of this policy activating at launch as described above. The current version always lives at this address with its date in the header.
If you have a complaint, contact us first and we will try to resolve it directly. You may also complain to the Office of the Commissioner for Personal Data Protection in Cyprus, to your local supervisory authority where GDPR applies, or to your state Attorney General in the United States.