Key points
CopierPilot processes personal data to create and secure accounts, connect supported trading accounts, operate Copy Routes, provide Account Protection and Analytics, administer private Peer Copy Relationships, process subscriptions, provide support and protect the Service.
Trading and account-state data may include account identifiers, balances, equity, margin, positions, orders, transactions, execution results and risk snapshots where required for the selected functionality.
A Master does not receive the Follower's broker credentials, balance, equity, margin, positions, trades, profit and loss, personal Analytics, sizing or protection settings.
Peer Copy shares only a CopierPilot display identifier, a masked account email where operationally needed, and limited operational Relationship information. The Master’s full associated email is used only as a private invite credential supplied outside CopierPilot and is not searchable or publicly displayed.
CopierPilot does not sell personal data, does not use private trading data to create public Master rankings or performance profiles, and launches without advertising or remarketing SDKs in the authenticated product.
Non-essential cookies or similar technologies will be governed by the Cookie and Tracking Policy and applicable consent controls.
Users may exercise applicable privacy rights through the contact channels made available by CopierPilot.
1. Who we are
This Privacy Policy explains how CopierPilot (“CopierPilot”, “we”, “us” or “our”), a Netherlands-based software service, processes personal data in connection with the CopierPilot website, user accounts, supported trading-account connections, copying features, Account Protection, Analytics, private Peer Copy, subscriptions, support, security and related services.
For the processing described in this Policy, CopierPilot is normally the controller. A broker, trading platform, account provider, payment provider or other independent service may process data under its own privacy information and responsibilities.
Current privacy and support contact channels are available through the Contact page.
3. Personal data we process
The exact fields depend on the features used and the selected connection method.
3.1 Account and identity data
We may process:
- name, display name and email address;
- country, language, time zone and account preferences;
- account identifier and user role;
- password hash and authentication status;
- multi-factor authentication and recovery information;
- sign-up, verification and account-status records;
- accepted legal-document versions and timestamps; and
- age or eligibility confirmation where required by the eligibility rules.
We do not intend to collect identity documents or sensitive verification data unless an approved eligibility, sanctions, payment or legal process requires them and an appropriate notice and control is in place.
3.2 Connected Account and connection data
Depending on the connection method, we may process:
- broker, platform, prop-firm or account-provider name;
- trading-account identifier, server and account type;
- Source or Destination role;
- platform, bridge, Expert Advisor, API or connection version;
- authentication token, encrypted credential material or connection secret where technically required;
- connection status, health, latency and error information;
- permissions and capabilities reported by the provider; and
- timestamps for connection, disconnection, reauthorisation, suspension or removal.
Connection credentials or tokens are handled according to the supported connection method and security controls in use. Users should never provide credentials through support messages or any channel not expressly designated for secure connection setup.
3.3 Trading, execution and account-state data
Where required to operate a selected feature, we may process:
- Source events and generated Copy Instructions;
- instrument, direction, size, price and timing information;
- positions, pending orders, transaction and execution history;
- fills, rejects, partial fills, slippage and provider responses;
- balance, equity, margin, free margin and account mode;
- realised and unrealised profit and loss;
- net and gross exposure information;
- risk snapshots, high-water marks and triggered rules;
- confirmation prompts, responses, timeouts and revalidation results;
- route status, pause, stop and termination events; and
- Analytics derived from account and execution data.
CopierPilot processes this information to provide the selected technical functionality. It does not make a user's private trading data public or use it to create a public Master-performance profile.
3.4 Copy Route and configuration data
We may process:
- Source and Destination selections;
- sizing method and parameters;
- symbol mapping, filters and execution settings;
- fixed platform risk limits;
- Account Protection settings and actions;
- route configuration versions or digests;
- route creation, change, pause, reactivation and termination history; and
- validation, error and outcome data.
3.5 Peer Copy data
For private Peer Copy, we may process:
- Master and Follower user identifiers;
- the Master's email address when entered by the intended Follower;
- Invite Key reference, status, rotation and revocation records;
- Source, Destination, Route and Relationship identifiers;
- minimal identity shown to the other party;
- Relationship status and operational connection health;
- Master availability, acceptance, refusal or activation events;
- Follower configuration-completion and submission events;
- no-consideration confirmations;
- agreement versions and acceptance references;
- capacity-check and eligibility results;
- reports of suspected commercialisation or misuse; and
- enforcement, review and outcome records.
The identity information shown between a Master and Follower is limited to what the Service makes available for the private Relationship. Private route settings and trading-account data remain separated as described in section 8.
3.6 Subscription and billing data
We may process:
- billing name, address, country and tax status;
- company name, tax number or business status where supplied;
- Subscription plan and Billable Connected Account count;
- prices, currency, tax, discounts, credits and renewal information;
- invoices, receipts, refunds and payment status;
- payment-provider customer, transaction or payment-method token;
- failed-payment, retry, cancellation and chargeback records; and
- checkout acceptance and order-confirmation evidence.
An independent payment provider may receive and process payment-card or bank details. Where payment details are handled directly by that provider, CopierPilot does not need to receive the full card details.
3.7 Website, app, device and log data
We may process:
- IP address and approximate location derived from it;
- browser, operating system, device and application information;
- session, login and authentication events;
- page, feature and navigation interactions;
- crash, diagnostics, performance and error logs;
- cookie, consent and preference records;
- security alerts and fraud or abuse indicators; and
- referral or campaign information where approved.
Non-essential analytics, advertising or similar tracking must not be activated before the applicable choice has been presented and recorded.
3.8 Communications and support data
We may process information contained in:
- support requests and responses;
- onboarding or service communications;
- billing or complaint correspondence;
- security and incident reports;
- user-submitted screenshots, logs or attachments;
- feedback, survey responses or research participation; and
- notices concerning Relationships, risk controls, enforcement or account status.
Users should redact unrelated personal or financial information and must not send broker passwords, authentication codes or unnecessary full financial records through support or reporting channels.
3.9 Commercialisation and integrity reports
Where a user reports suspected commercial use, impersonation, credential requests or another integrity concern, we may process:
- the reporting user's identity and contact information;
- the reported user or Relationship;
- submitted messages, screenshots, public links or payment evidence;
- relevant account, Relationship, Invite Key, session and security records;
- investigation notes, user responses and internal assessments; and
- protective, enforcement and review actions.
We seek to limit review to information relevant to the reported issue. A serious permanent action should be based on documented human review rather than a weak signal or automated score alone.
4. Where personal data comes from
We may receive personal data:
- directly from the user;
- from the user's device, application, bridge or Expert Advisor;
- from a broker, platform or account provider connected at the user's direction;
- from a Master or Follower involved in the same private Relationship;
- from a payment provider;
- from service providers that support authentication, hosting, communications, security or support;
- from public material submitted or reasonably reviewed for a specific integrity or security purpose; and
- from other users who submit a support, misuse or security report.
When information is received from another user, CopierPilot should provide any required notice without disclosing confidential reporter, security or investigation information.
5. Why we process personal data and our legal bases
| Purpose | Typical data | Intended legal basis |
|---|---|---|
| Create and administer a CopierPilot account | Account, identity, authentication and preference data | Performance of the user contract; steps requested before entering it |
| Connect and maintain supported trading accounts | Connected Account, credential or token, device and connection data | Performance of the user contract |
| Generate, evaluate and transmit Copy Instructions | Trading, execution, account-state, risk and route data | Performance of the user contract |
| Provide Account Protection, alerts and Analytics | Account-state, position, transaction, configuration and derived data | Performance of the user contract; legitimate interests for reliable service improvement where the processing is not strictly contractual |
| Create and administer private Peer Copy Relationships | Identity, Invite Key, Relationship, Route, agreement and operational data | Performance of the relevant user contracts; legitimate interests in secure and non-commercial feature operation |
| Record agreements, activation and material account events | Identity, document version, timestamp, session and technical evidence | Performance of the contract; legitimate interests in evidence, security and dispute handling; legal obligations where applicable |
| Process subscriptions and payments | Billing, tax, payment-provider and transaction data | Performance of the contract; legal obligations for financial and tax records |
| Provide support and service communications | Account, contact, support, diagnostic and service-status data | Performance of the contract; legitimate interests in support and service administration |
| Protect accounts, networks and the Service | Device, session, log, security, abuse and incident data | Legitimate interests in security, fraud prevention, integrity and availability; legal obligations where applicable |
| Investigate prohibited commercialisation or misuse | Reports, Relationship, audit, support and security data | Legitimate interests in enforcing the private non-commercial model, protecting users and defending legal claims |
| Comply with legal duties and respond to valid requests | Relevant account, transaction, communication and evidence data | Compliance with legal obligations; legitimate interests in legal claims |
| Send optional marketing or research communications | Contact, preference and campaign data | Consent where required; legitimate interests only where permitted and appropriately balanced |
| Use non-essential cookies or similar technologies | Device, browser, website and consent data | Consent where required; see the Cookie and Tracking Policy |
Where we rely on legitimate interests, we must assess the purpose, necessity and impact on users. Users may object where applicable. Where we rely on consent, consent may be withdrawn without affecting earlier lawful processing.
6. Data needed to provide the Service
Some personal data is required to create an account, maintain security, connect a selected account, operate a route or process payment. If required data is not provided or is removed, the relevant feature may be unavailable, paused or terminated.
Optional fields and optional communications should be identified as such. CopierPilot must not make access conditional on consent to unrelated processing.
7. Automated technical processing
CopierPilot uses automated technical rules to operate the Service. Examples include:
- transforming Source events according to the Follower's configuration;
- calculating exposure and evaluating mandatory risk limits;
- placing an instruction on hold for Follower confirmation;
- refusing execution after timeout, failed account-state retrieval or failed revalidation;
- pausing routes after configured Account Protection events;
- detecting connection failures, duplicate events or security anomalies; and
- generating operational alerts or case signals.
These processes can affect whether a Copy Instruction is sent, held or rejected, but they do not guarantee trading outcomes. The Follower selects and controls the Destination route and can manage the broker account directly.
Automated integrity signals may support triage, but a confirmed serious commercialisation finding or permanent Peer Copy block should require documented human review and the approved authorisation process.
Where automated processing is subject to specific legal safeguards, CopierPilot will provide the information and rights required by applicable law.
8. Peer Copy information boundaries
8.1 Information a Master may receive
A Master may receive only the approved minimum needed to administer the intended private Relationship, such as:
- the Follower’s CopierPilot display identifier and, only where operationally needed, a masked account email;
- configuring, ready, active, paused or ended status;
- Source and Relationship context;
- connection health and operational route status; and
- activation, refusal, pause or termination notifications.
8.2 Information not shown to the Master
A Master must not receive the Follower's:
- broker or platform credentials;
- Destination account login details;
- balance, equity, margin or free margin;
- positions, orders, trade history or execution prices;
- realised or unrealised profit and loss;
- personal Analytics;
- sizing, mapping or execution configuration;
- fixed or configurable risk settings;
- Account Protection rules or thresholds; or
- internal IP, device, session, security or investigation evidence.
8.3 Information a Follower may receive
A Follower may receive only the approved minimum needed to identify and configure the intended private Relationship, such as:
- the Master’s CopierPilot display identifier;
- the Source label or masked identifier approved for display;
- Source availability and Relationship status; and
- operational notices relevant to the private connection.
The Master’s full associated email is a private invite credential supplied by the Master outside CopierPilot. It is used for targeted matching and is not searchable or publicly displayed. CopierPilot does not provide a public Master directory, ranking, verified-performance label or public performance page.
8.4 Invite Keys
Invite Keys are private access credentials for a specific Source. They expire after 7 days by default unless revoked or rotated earlier. Production storage must use a non-reversible hash or reference rather than retaining the full key where it is not operationally required, and logs/UI must mask the key. We may log creation, rotation, revocation, expiry, attempted use and successful resolution. Invite Keys must not be publicly indexed, sold or used as public promotional identifiers.
10. International data transfers
Some approved service providers may process data outside the European Economic Area or the user's country.
Where required, CopierPilot will use an applicable transfer mechanism, such as:
- a recognised adequacy decision;
- approved standard contractual clauses;
- another legally permitted safeguard; or
- a limited exception available under applicable law.
Where necessary, we use appropriate contractual, technical or organisational safeguards for international transfers and can provide further information through our contact channels where required.
11. Security
CopierPilot intends to use technical and organisational measures appropriate to the nature and risk of the processing, including where applicable:
- encryption in transit and at rest;
- secure credential or token storage;
- role-based access and least-privilege controls;
- environment separation;
- multi-factor authentication for privileged access;
- audit logging and monitoring;
- secure development and change controls;
- backup, recovery and availability controls;
- vulnerability and incident management;
- provider due diligence; and
- staff confidentiality and access review.
No system is completely secure. Users must protect their CopierPilot credentials, use available security features, keep devices and connection components updated and report suspected compromise promptly.
12. Data retention
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected and for applicable security, dispute, accounting, tax or legal requirements.
Retention can differ by data category. Account and service data may be kept while an account is active; billing records may be retained for applicable financial-record periods; security and audit records may be retained for a period proportionate to integrity and dispute needs; and data scheduled for deletion may remain temporarily in protected backups until those backups rotate.
When data is no longer needed, we delete or anonymise it where reasonably practicable, subject to legal obligations and legitimate dispute or security needs.
13. User choices and rights
Subject to applicable law and relevant exceptions, users may have rights to:
- receive information about processing;
- access personal data;
- correct inaccurate or incomplete data;
- request deletion;
- request restriction of processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent where processing is based on consent;
- request safeguards relating to applicable automated decision-making; and
- lodge a complaint with the competent data protection authority.
Requests may be submitted through the support or privacy channel available on our Contact page. We may need to verify identity before acting on a request. We will not request a broker password or authentication code for this purpose.
A request may be limited or refused where permitted, for example where retaining information is required for legal duties, security, fraud prevention, another person's rights or legal claims. Where appropriate, we will explain the outcome.
14. Account deletion and portability
You may request account closure or deletion through the account or support channels available to you, subject to applicable retention obligations.
Before deletion, the user should be warned that:
- active Copy Routes and Relationships may need to be paused or ended;
- deleting CopierPilot data does not close positions at a broker;
- billing cancellation and account deletion may be separate actions;
- some records may be retained under the approved retention schedule; and
- exported data may not include confidential security logic, another user's data or information that cannot lawfully be disclosed.
15. Communications
We may send essential communications about:
- account security and authentication;
- connection or service status;
- risk confirmations and operational alerts;
- legal-document changes requiring acceptance;
- subscriptions, invoices, failed payments and cancellation;
- support requests;
- Peer Copy activation, pause, termination or enforcement; and
- material privacy or security incidents.
Essential service communications cannot always be opted out of while the relevant account or feature remains active.
Optional product news, marketing or research messages will provide the applicable choice or unsubscribe method. Time-sensitive trade confirmations are intended to use in-app notification rather than email.
17. Children and eligibility
CopierPilot is for users aged 18 or older. Registration and eligibility controls are intended to reject users who are under 18. This is a product eligibility rule and is not presented as a statement that privacy law universally requires an age of 18.
We do not knowingly seek children's personal data. Where we learn that an ineligible person has created an account, we may restrict access and take appropriate deletion or preservation steps under this Policy and applicable law.
18. Sensitive personal data
CopierPilot does not intentionally require health information, biometric identifiers, political opinions, religious beliefs or similar sensitive personal data for its ordinary product functionality.
Users should not include such information in profile fields, support requests, reports or attachments unless it is strictly necessary and specifically requested through an approved process. Any future identity, sanctions or fraud-verification process involving additional sensitive or official-document data requires a separate data assessment and appropriate notice before launch.
Trading-account and financial information may be highly sensitive to users even where it is not legally classified as a special category. CopierPilot therefore applies the information boundaries and security controls described in this Policy.
19. Third-party services and links
The Service may connect or link to independent brokers, platforms, prop firms, payment providers, communication providers or other services. Their privacy practices are governed by their own notices.
CopierPilot is not responsible for an independent third party's processing merely because its service is technically compatible or linked. Users should review the relevant third-party information before connecting an account or submitting data.
21. Changes to this Policy
We may update this Policy when the Service, processing activities, providers or legal requirements change.
The updated Policy will show a revised effective date. Where a change materially affects how personal data is processed or requires a new choice, we will provide appropriate notice and obtain renewed consent or acceptance where required.
A privacy-policy update does not by itself authorise a materially different use of data where another legal basis or user choice is required.
22. Contact and requests
Questions, requests or concerns about personal data may be submitted through the Contact page.
Please do not include broker passwords, authentication codes or unnecessary full account statements in a privacy request. We may need to verify your identity before completing certain requests.

