Skip to main content
COT-Reports
COT-Reports.com
COT-Reports

Privacy Policy

This Privacy Policy explains how COT-Reports collects, uses and protects information when you visit COT-Reports.com. We keep this document short and plain so you know exactly what happens.

Last updated: 2026-05-22

1. Who we are

COT-Reports ("we", "us") operates COT-Reports.com, a free website that publishes the U.S. Commodity Futures Trading Commission (CFTC) Commitments of Traders reports along with related analytical tools and a live economic calendar. The site is operated by an individual; we do not have a physical office and we do not collect more data than we need to run the site.

2. What data we collect

Technical data on every visit: IP address, user agent, referring page, screen size, and locale preference. With your explicit consent, Google Analytics 4 records aggregated usage stats (pages viewed, session duration, approximate country derived from anonymised IP). When you create an account, we collect your email address and a salted-hash of your password (the password itself is never stored or transmitted to us in plain text — Supabase Auth handles authentication). When you subscribe to COT-Reports Premium, our payment processor Stripe handles your card details on its own infrastructure and we never see, store or transmit them; we receive and store only a Stripe customer ID, subscription ID, billing period, status, and the timestamp of the next billing cycle. When you subscribe to the newsletter, release alerts (CFTC publication notifications), or the weekly extreme-positioning digest, we store your email address, locale, the source of the signup and a salted SHA-256 hash of your IP for anti-spam rate limiting. If you tick the optional cross-promo checkbox, we also record your consent so our sister product TradeLog can send you product updates — this is opt-in only and you can unsubscribe at any time from the link in every email. When you submit a contact form, we store your name, email, message, IP-hash and user-agent so we can reply and detect abuse. When you submit an Ultima Markets bonus request, we store your name, email, country and (optional) UM account ID for processing — see §5.

3. How we use the data

Technical data operates and secures the site (rate limiting, abuse prevention, error diagnostics). Aggregated analytics tells us which pages are useful and where visitors get stuck. Account data lets you sign in and receive transactional emails (welcome, password reset, subscription receipts, account deletion confirmation). Subscription data lets us grant Premium access to the right account and renew or cancel billing through Stripe. Newsletter, release-alert and digest data lets us deliver the emails you opted into. Contact-form data lets us answer your message. We never sell personal data, we never use it for advertising profiles, and we do not engage in cross-site behavioural tracking. Stripe applies its own anti-fraud and tax-compliance processing on payment data — see Stripe's privacy policy at stripe.com/privacy for details.

5. Who we share data with

We share the minimum data needed with the vendors that run our infrastructure, each acting as a data processor under our instructions: Vercel (hosting), Supabase (database, authentication, file storage), Stripe (payment processing for Premium subscriptions and Marketplace purchases — Stripe is a controller for cardholder data and a processor for everything else, see stripe.com/privacy), Resend (transactional and digest email delivery), and Google Analytics 4 (anonymised analytics, only after consent). We also fetch public data from government agencies (CFTC, BLS, BEA, Federal Reserve, ECB, Eurostat, ONS, Bank of England) — these are one-way calls that do not share your data. When you submit an Ultima Markets bonus request through the Brokers section, the form data (name, email, country, UM account ID if provided) is sent to the Ultima Markets VIP Bonus Desk so they can process your upgrade — this is the entire purpose of that form, and Ultima Markets becomes a separate data controller from that point. Click and impression events on broker and prop-firm banners are stored in our own Supabase analytics tables in aggregated form, hashed by IP, and never shared with third parties. We never sell your data and we never share it for advertising or profiling.

6. International data transfers

Several of our processors are based in the United States — Vercel (hosting), Stripe (payments), Google (Analytics) and Resend (email infrastructure). Where personal data leaves the European Economic Area, we rely on GDPR Chapter V transfer mechanisms: the European Commission's Standard Contractual Clauses (SCCs, Decision 2021/914/EU) and the EU-U.S. Data Privacy Framework adequacy decision (Decision 2023/1795). Stripe, Google and Resend are certified under the EU-U.S. DPF; Vercel processes under SCCs and offers EU-region hosting which we use by default. Supabase processes our user and account data inside the EU (Frankfurt region). You can request the specific transfer mechanism applicable to your data for any of our vendors by emailing us.

7. Data retention

Server access logs are kept for up to 30 days for security purposes and then deleted. Analytics data is retained for up to 14 months. Any message you send to contact@cot-reports.com is kept only as long as needed to handle your request and is then archived or deleted.

8. Your rights

You have the right to access, correct, delete or export your personal data, and to object to or restrict its processing. You can exercise these rights at any time by emailing contact@cot-reports.com. We will respond within 30 days. If you believe we have not handled your request properly, you have the right to lodge a complaint with your local data protection authority.

9. Cookies

We use a minimal set of cookies: a session cookie to remember your language and theme preference, and optional Google Analytics cookies that only fire after you click Accept on our banner. Full details are in our Cookie Policy.

10. Data products & API

When you purchase the COT Data Dump or subscribe to the COT Data Spreadsheet, we store your order record (Stripe customer ID, subscription ID where applicable, product slug, amount, status, completed-at timestamp, and how many times you have re-downloaded the file). We do not store the archive itself in association with your account; the file in our private Storage bucket is delivered to you via short-lived signed URLs and is not personalized. When you subscribe to the COT Data API, we generate a bearer token, store its SHA-256 hash, the last four characters for UI identification, an optional label, the linked Stripe subscription ID, and per-request usage counters; the raw token itself is shown to you exactly once and never written to our servers. Every API request is logged with a salted SHA-256 hash of the originating IP, the user-agent, the referer, the endpoint, and the response status; raw IP addresses are never persisted. API request logs are retained for 7 days and then deleted by an automatic prune job. You can revoke any token at any time from /account/api; revocation hits the API on the very next request, with no grace period.

11. Intended audience

COT-Reports.com is intended for users aged 18 or over. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us with data, please contact us so we can remove it.

12. Marketing emails

We send two optional email updates: a weekly COT recap and extreme positioning alerts. If you create a free account you receive them only if you opt in, via an unticked checkbox shown at sign-up. If you purchase a product or subscription, we may send you these same updates as a customer, as permitted by the 'soft opt-in' under applicable e-privacy law — we tell you so at the time of purchase. Either way, every marketing email carries a one-click unsubscribe link, and you can turn these emails on or off anytime under Email alerts in your account settings. We never sell or share your email address.

13. Support chatbot conversations

When you use the support chatbot on the site, we store the conversation — the messages you send and the assistant's replies — so our team can review it and improve the support we provide. If you are signed in to an account, your account email address is stored together with the conversation; if you are not signed in, no email address is stored. We never store your raw IP address, only a salted, irreversible hash of it. The lawful basis for this processing is our legitimate interest in operating and improving customer support. Conversations are automatically deleted 12 months after the last message, and they are deleted immediately if you delete your account. You can also ask us to delete a conversation sooner by emailing contact@cot-reports.com.

14. Changes to this policy

We may update this Privacy Policy from time to time, for example when we add a new tool or change a vendor. Significant changes will be announced on the homepage. The "Last updated" date at the top of this page always reflects the current version.

Questions or data requests?

Email us for privacy questions, data subject requests or any concerns about this policy.

contact@cot-reports.com