Key points

  • CopierPilot processes personal data to create and secure accounts, connect supported trading accounts, operate Copy Routes, provide Account Protection and Analytics, administer private Peer Copy Relationships, process subscriptions, provide support and protect the Service.

  • Trading and account-state data may include account identifiers, balances, equity, margin, positions, orders, transactions, execution results and risk snapshots where required for the selected functionality.

  • A Master does not receive the Follower's broker credentials, balance, equity, margin, positions, trades, profit and loss, personal Analytics, sizing or protection settings.

  • Peer Copy shares only a CopierPilot display identifier, a masked account email where operationally needed, and limited operational Relationship information. The Master’s full associated email is used only as a private invite credential supplied outside CopierPilot and is not searchable or publicly displayed.

  • CopierPilot does not sell personal data, does not use private trading data to create public Master rankings or performance profiles, and launches without advertising or remarketing SDKs in the authenticated product.

  • Non-essential cookies or similar technologies will be governed by the Cookie and Tracking Policy and applicable consent controls.

  • Users may exercise applicable privacy rights through the contact channels made available by CopierPilot.

1. Who we are

This Privacy Policy explains how CopierPilot (“CopierPilot”, “we”, “us” or “our”), a Netherlands-based software service, processes personal data in connection with the CopierPilot website, user accounts, supported trading-account connections, copying features, Account Protection, Analytics, private Peer Copy, subscriptions, support, security and related services.

For the processing described in this Policy, CopierPilot is normally the controller. A broker, trading platform, account provider, payment provider or other independent service may process data under its own privacy information and responsibilities.

Current privacy and support contact channels are available through the Contact page.

3. Personal data we process

The exact fields depend on the features used and the selected connection method.

3.1 Account and identity data

We may process:

  • name, display name and email address;
  • country, language, time zone and account preferences;
  • account identifier and user role;
  • password hash and authentication status;
  • multi-factor authentication and recovery information;
  • sign-up, verification and account-status records;
  • accepted legal-document versions and timestamps; and
  • age or eligibility confirmation where required by the eligibility rules.

We do not intend to collect identity documents or sensitive verification data unless an approved eligibility, sanctions, payment or legal process requires them and an appropriate notice and control is in place.

3.2 Connected Account and connection data

Depending on the connection method, we may process:

  • broker, platform, prop-firm or account-provider name;
  • trading-account identifier, server and account type;
  • Source or Destination role;
  • platform, bridge, Expert Advisor, API or connection version;
  • authentication token, encrypted credential material or connection secret where technically required;
  • connection status, health, latency and error information;
  • permissions and capabilities reported by the provider; and
  • timestamps for connection, disconnection, reauthorisation, suspension or removal.

Connection credentials or tokens are handled according to the supported connection method and security controls in use. Users should never provide credentials through support messages or any channel not expressly designated for secure connection setup.

3.3 Trading, execution and account-state data

Where required to operate a selected feature, we may process:

  • Source events and generated Copy Instructions;
  • instrument, direction, size, price and timing information;
  • positions, pending orders, transaction and execution history;
  • fills, rejects, partial fills, slippage and provider responses;
  • balance, equity, margin, free margin and account mode;
  • realised and unrealised profit and loss;
  • net and gross exposure information;
  • risk snapshots, high-water marks and triggered rules;
  • confirmation prompts, responses, timeouts and revalidation results;
  • route status, pause, stop and termination events; and
  • Analytics derived from account and execution data.

CopierPilot processes this information to provide the selected technical functionality. It does not make a user's private trading data public or use it to create a public Master-performance profile.

3.4 Copy Route and configuration data

We may process:

  • Source and Destination selections;
  • sizing method and parameters;
  • symbol mapping, filters and execution settings;
  • fixed platform risk limits;
  • Account Protection settings and actions;
  • route configuration versions or digests;
  • route creation, change, pause, reactivation and termination history; and
  • validation, error and outcome data.

3.5 Peer Copy data

For private Peer Copy, we may process:

  • Master and Follower user identifiers;
  • the Master's email address when entered by the intended Follower;
  • Invite Key reference, status, rotation and revocation records;
  • Source, Destination, Route and Relationship identifiers;
  • minimal identity shown to the other party;
  • Relationship status and operational connection health;
  • Master availability, acceptance, refusal or activation events;
  • Follower configuration-completion and submission events;
  • no-consideration confirmations;
  • agreement versions and acceptance references;
  • capacity-check and eligibility results;
  • reports of suspected commercialisation or misuse; and
  • enforcement, review and outcome records.

The identity information shown between a Master and Follower is limited to what the Service makes available for the private Relationship. Private route settings and trading-account data remain separated as described in section 8.

3.6 Subscription and billing data

We may process:

  • billing name, address, country and tax status;
  • company name, tax number or business status where supplied;
  • Subscription plan and Billable Connected Account count;
  • prices, currency, tax, discounts, credits and renewal information;
  • invoices, receipts, refunds and payment status;
  • payment-provider customer, transaction or payment-method token;
  • failed-payment, retry, cancellation and chargeback records; and
  • checkout acceptance and order-confirmation evidence.

An independent payment provider may receive and process payment-card or bank details. Where payment details are handled directly by that provider, CopierPilot does not need to receive the full card details.

3.7 Website, app, device and log data

We may process:

  • IP address and approximate location derived from it;
  • browser, operating system, device and application information;
  • session, login and authentication events;
  • page, feature and navigation interactions;
  • crash, diagnostics, performance and error logs;
  • cookie, consent and preference records;
  • security alerts and fraud or abuse indicators; and
  • referral or campaign information where approved.

Non-essential analytics, advertising or similar tracking must not be activated before the applicable choice has been presented and recorded.

3.8 Communications and support data

We may process information contained in:

  • support requests and responses;
  • onboarding or service communications;
  • billing or complaint correspondence;
  • security and incident reports;
  • user-submitted screenshots, logs or attachments;
  • feedback, survey responses or research participation; and
  • notices concerning Relationships, risk controls, enforcement or account status.

Users should redact unrelated personal or financial information and must not send broker passwords, authentication codes or unnecessary full financial records through support or reporting channels.

3.9 Commercialisation and integrity reports

Where a user reports suspected commercial use, impersonation, credential requests or another integrity concern, we may process:

  • the reporting user's identity and contact information;
  • the reported user or Relationship;
  • submitted messages, screenshots, public links or payment evidence;
  • relevant account, Relationship, Invite Key, session and security records;
  • investigation notes, user responses and internal assessments; and
  • protective, enforcement and review actions.

We seek to limit review to information relevant to the reported issue. A serious permanent action should be based on documented human review rather than a weak signal or automated score alone.

4. Where personal data comes from

We may receive personal data:

  • directly from the user;
  • from the user's device, application, bridge or Expert Advisor;
  • from a broker, platform or account provider connected at the user's direction;
  • from a Master or Follower involved in the same private Relationship;
  • from a payment provider;
  • from service providers that support authentication, hosting, communications, security or support;
  • from public material submitted or reasonably reviewed for a specific integrity or security purpose; and
  • from other users who submit a support, misuse or security report.

When information is received from another user, CopierPilot should provide any required notice without disclosing confidential reporter, security or investigation information.

6. Data needed to provide the Service

Some personal data is required to create an account, maintain security, connect a selected account, operate a route or process payment. If required data is not provided or is removed, the relevant feature may be unavailable, paused or terminated.

Optional fields and optional communications should be identified as such. CopierPilot must not make access conditional on consent to unrelated processing.

7. Automated technical processing

CopierPilot uses automated technical rules to operate the Service. Examples include:

  • transforming Source events according to the Follower's configuration;
  • calculating exposure and evaluating mandatory risk limits;
  • placing an instruction on hold for Follower confirmation;
  • refusing execution after timeout, failed account-state retrieval or failed revalidation;
  • pausing routes after configured Account Protection events;
  • detecting connection failures, duplicate events or security anomalies; and
  • generating operational alerts or case signals.

These processes can affect whether a Copy Instruction is sent, held or rejected, but they do not guarantee trading outcomes. The Follower selects and controls the Destination route and can manage the broker account directly.

Automated integrity signals may support triage, but a confirmed serious commercialisation finding or permanent Peer Copy block should require documented human review and the approved authorisation process.

Where automated processing is subject to specific legal safeguards, CopierPilot will provide the information and rights required by applicable law.

8. Peer Copy information boundaries

8.1 Information a Master may receive

A Master may receive only the approved minimum needed to administer the intended private Relationship, such as:

  • the Follower’s CopierPilot display identifier and, only where operationally needed, a masked account email;
  • configuring, ready, active, paused or ended status;
  • Source and Relationship context;
  • connection health and operational route status; and
  • activation, refusal, pause or termination notifications.

8.2 Information not shown to the Master

A Master must not receive the Follower's:

  • broker or platform credentials;
  • Destination account login details;
  • balance, equity, margin or free margin;
  • positions, orders, trade history or execution prices;
  • realised or unrealised profit and loss;
  • personal Analytics;
  • sizing, mapping or execution configuration;
  • fixed or configurable risk settings;
  • Account Protection rules or thresholds; or
  • internal IP, device, session, security or investigation evidence.

8.3 Information a Follower may receive

A Follower may receive only the approved minimum needed to identify and configure the intended private Relationship, such as:

  • the Master’s CopierPilot display identifier;
  • the Source label or masked identifier approved for display;
  • Source availability and Relationship status; and
  • operational notices relevant to the private connection.

The Master’s full associated email is a private invite credential supplied by the Master outside CopierPilot. It is used for targeted matching and is not searchable or publicly displayed. CopierPilot does not provide a public Master directory, ranking, verified-performance label or public performance page.

8.4 Invite Keys

Invite Keys are private access credentials for a specific Source. They expire after 7 days by default unless revoked or rotated earlier. Production storage must use a non-reversible hash or reference rather than retaining the full key where it is not operationally required, and logs/UI must mask the key. We may log creation, rotation, revocation, expiry, attempted use and successful resolution. Invite Keys must not be publicly indexed, sold or used as public promotional identifiers.

9. When we share personal data

We may share personal data only where reasonably necessary with:

  • service providers supporting hosting, cloud infrastructure, databases, authentication, communications, monitoring, support, security, analytics or document delivery;
  • payment providers processing subscriptions, payment methods, refunds, fraud checks or chargebacks;
  • brokers, platforms and account providers where data exchange is needed for a connection initiated by the user;
  • the relevant Master or Follower, limited to the approved Peer Copy information boundary;
  • professional advisers, auditors and insurers where reasonably necessary for advice, assurance, claims or risk management;
  • a purchaser or successor in a genuine corporate transaction, subject to appropriate confidentiality and data-protection measures; and
  • public bodies or other recipients where disclosure is legally required or necessary to establish, exercise or defend legal claims.

10. International data transfers

Some approved service providers may process data outside the European Economic Area or the user's country.

Where required, CopierPilot will use an applicable transfer mechanism, such as:

  • a recognised adequacy decision;
  • approved standard contractual clauses;
  • another legally permitted safeguard; or
  • a limited exception available under applicable law.

Where necessary, we use appropriate contractual, technical or organisational safeguards for international transfers and can provide further information through our contact channels where required.

11. Security

CopierPilot intends to use technical and organisational measures appropriate to the nature and risk of the processing, including where applicable:

  • encryption in transit and at rest;
  • secure credential or token storage;
  • role-based access and least-privilege controls;
  • environment separation;
  • multi-factor authentication for privileged access;
  • audit logging and monitoring;
  • secure development and change controls;
  • backup, recovery and availability controls;
  • vulnerability and incident management;
  • provider due diligence; and
  • staff confidentiality and access review.

No system is completely secure. Users must protect their CopierPilot credentials, use available security features, keep devices and connection components updated and report suspected compromise promptly.

12. Data retention

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected and for applicable security, dispute, accounting, tax or legal requirements.

Retention can differ by data category. Account and service data may be kept while an account is active; billing records may be retained for applicable financial-record periods; security and audit records may be retained for a period proportionate to integrity and dispute needs; and data scheduled for deletion may remain temporarily in protected backups until those backups rotate.

When data is no longer needed, we delete or anonymise it where reasonably practicable, subject to legal obligations and legitimate dispute or security needs.

13. User choices and rights

Subject to applicable law and relevant exceptions, users may have rights to:

  • receive information about processing;
  • access personal data;
  • correct inaccurate or incomplete data;
  • request deletion;
  • request restriction of processing;
  • receive certain data in a portable format;
  • object to processing based on legitimate interests or direct marketing;
  • withdraw consent where processing is based on consent;
  • request safeguards relating to applicable automated decision-making; and
  • lodge a complaint with the competent data protection authority.

Requests may be submitted through the support or privacy channel available on our Contact page. We may need to verify identity before acting on a request. We will not request a broker password or authentication code for this purpose.

A request may be limited or refused where permitted, for example where retaining information is required for legal duties, security, fraud prevention, another person's rights or legal claims. Where appropriate, we will explain the outcome.

14. Account deletion and portability

You may request account closure or deletion through the account or support channels available to you, subject to applicable retention obligations.

Before deletion, the user should be warned that:

  • active Copy Routes and Relationships may need to be paused or ended;
  • deleting CopierPilot data does not close positions at a broker;
  • billing cancellation and account deletion may be separate actions;
  • some records may be retained under the approved retention schedule; and
  • exported data may not include confidential security logic, another user's data or information that cannot lawfully be disclosed.

15. Communications

We may send essential communications about:

  • account security and authentication;
  • connection or service status;
  • risk confirmations and operational alerts;
  • legal-document changes requiring acceptance;
  • subscriptions, invoices, failed payments and cancellation;
  • support requests;
  • Peer Copy activation, pause, termination or enforcement; and
  • material privacy or security incidents.

Essential service communications cannot always be opted out of while the relevant account or feature remains active.

Optional product news, marketing or research messages will provide the applicable choice or unsubscribe method. Time-sensitive trade confirmations are intended to use in-app notification rather than email.

16. Cookies and similar technologies

The website and applications may use cookies, local storage, SDKs, pixels or comparable technologies for:

  • authentication and security;
  • user preferences;
  • service operation and load balancing;
  • diagnostics and performance;
  • analytics; and
  • marketing technologies only if introduced in a future separately approved release.

Relevant names, providers, purposes, durations and consent categories are described in the Cookie and Tracking Policy or consent interface. Non-essential technologies remain disabled until the required choice has been recorded.

At initial launch, the authenticated product does not use advertising or remarketing SDKs. Product analytics may be introduced only from an approved event list after the relevant privacy and cookie controls are implemented, and private trading or Peer Copy data must remain outside general marketing payloads.

17. Children and eligibility

CopierPilot is for users aged 18 or older. Registration and eligibility controls are intended to reject users who are under 18. This is a product eligibility rule and is not presented as a statement that privacy law universally requires an age of 18.

We do not knowingly seek children's personal data. Where we learn that an ineligible person has created an account, we may restrict access and take appropriate deletion or preservation steps under this Policy and applicable law.

18. Sensitive personal data

CopierPilot does not intentionally require health information, biometric identifiers, political opinions, religious beliefs or similar sensitive personal data for its ordinary product functionality.

Users should not include such information in profile fields, support requests, reports or attachments unless it is strictly necessary and specifically requested through an approved process. Any future identity, sanctions or fraud-verification process involving additional sensitive or official-document data requires a separate data assessment and appropriate notice before launch.

Trading-account and financial information may be highly sensitive to users even where it is not legally classified as a special category. CopierPilot therefore applies the information boundaries and security controls described in this Policy.

20. Business customers and authorised users

Where an organisation provides access to authorised users, the organisation and CopierPilot must determine their respective responsibilities for the relevant data.

The organisation is responsible for:

  • having authority to provide authorised-user data;
  • giving any required internal notices;
  • managing user access and removal; and
  • not instructing CopierPilot to process data unlawfully.

Where CopierPilot acts as a processor for a specific Business User workflow, the required data-processing terms must be agreed. Where CopierPilot acts as a processor for a specific Business User workflow, appropriate data-processing terms may apply.

21. Changes to this Policy

We may update this Policy when the Service, processing activities, providers or legal requirements change.

The updated Policy will show a revised effective date. Where a change materially affects how personal data is processed or requires a new choice, we will provide appropriate notice and obtain renewed consent or acceptance where required.

A privacy-policy update does not by itself authorise a materially different use of data where another legal basis or user choice is required.

22. Contact and requests

Questions, requests or concerns about personal data may be submitted through the Contact page.

Please do not include broker passwords, authentication codes or unnecessary full account statements in a privacy request. We may need to verify your identity before completing certain requests.

Related legal documents

Terms · Privacy · Risk · Peer Copy · Subscription · Cookies