Table of Contents
- 01 Introduction & Scope
- 02 Information We Collect
- 03 How We Use Your Information
- 04 Legal Bases for Processing
- 05 Data Sharing, Disclosure & Sub-Processors
- 06 Data Anonymization, Aggregation & Derived Data
- 07 Cross-Border Data Transfers
- 08 Data Retention
- 09 Data Security
- 10 Your Rights & Choices
- 11 Children's Privacy
- 12 Do Not Track & Global Privacy Controls
- 13 Changes to This Privacy Policy
- 14 Contact Information
- 15 Supplemental Disclosures
- 16 Governing Law
1. Introduction and Scope
1.1 Overview. This Privacy Policy ("Policy") describes how Tradecopia ("Tradecopia," "Company," "we," "us," or "our") collects, uses, processes, stores, shares, discloses, transfers, retains, and protects personal information and other data in connection with the Tradecopia Pro desktop software, Tradecopia Web cloud-hosted SaaS offering, website (tradecopia.com), and all related services (collectively, the "Service").
1.2 Applicability. This Policy applies to all users of the Service worldwide, including users of Tradecopia Pro (desktop application installed on a customer's local machine or VPS) and Tradecopia Web (cloud-hosted SaaS offering), visitors to tradecopia.com, trial users, and any other individuals whose personal data we process in connection with the Service. This Policy does not apply to third-party services, platforms, or websites that may be linked from or integrated with the Service, each of which is governed by its own privacy policy.
1.3 Product Configurations. Tradecopia Pro is locally installed, subscription-licensed desktop software operated within the customer's own local machine, VPS, operating system, network, broker, trading platform, and related third-party environment. Tradecopia Web is a cloud-hosted SaaS offering operated on infrastructure managed or arranged by Tradecopia and may be offered through subscription tiers such as Lite, Pro+, or other plans. The categories of personal information and operational data processed may differ depending on the product configuration, plan, connected broker or platform, account type, user settings, local environment, and integrations used.
1.4 Acceptance. By creating an account, subscribing to the Service, accessing the Service, or otherwise providing your information to us, you acknowledge that you have read, understood, and consent to the collection, use, processing, and disclosure of your information as described in this Policy. If you do not agree with the practices described herein, you must immediately discontinue use of the Service and contact us to request deletion of your data.
1.5 Data Controller. For purposes of applicable data protection laws (including the EU General Data Protection Regulation ("GDPR"), UK GDPR, and similar laws), Tradecopia is the data controller responsible for your personal data collected and processed in connection with the Service.
2. Information We Collect
We collect information from and about you through various means in connection with your use of the Service. The categories of information we collect are described below.
2.1 Account and Registration Information
When you create an account, register for the Service, or manage your subscription, we collect your full name, email address, username, hashed password (we do not store passwords in plaintext), country or region of residence, phone number (if provided), account preferences and configuration settings, and any other information you voluntarily provide during registration.
2.2 Billing and Payment Information
When you subscribe to the Service or make a payment, we collect and process your billing name and billing address, billing email address, payment method type (such as credit card or debit card), Stripe customer identifier and payment method identifiers (tokenized - Tradecopia does not store full payment card numbers, CVVs, or complete card details, as these are processed and stored by our payment processor, Stripe), and transaction history, subscription plan details, and billing cycle information.
2.3 Brokerage and Trading Platform Connection Data
When you connect third-party brokerage or trading platform accounts to the Service, we collect and store trading account identifiers and metadata, encrypted OAuth tokens and API credentials for connected platforms (such as Tradovate) stored encrypted at rest using AES-256-GCM encryption with encryption keys held separately from the database, trading account configuration parameters (such as copier settings, lot ratios, and risk parameters), trading account performance statistics and operational metadata, and connection status and synchronization state information. We do not access, store, or process your brokerage account passwords directly, as authentication with third-party platforms is handled through secure token-based mechanisms (such as OAuth 2.0).
2.4 Prop Firm, Evaluation Account, and Funded Account Metadata
If you choose to configure the Service for use with a proprietary trading firm, evaluation account, funded account, broker challenge program, or similar third-party account, we may process account identifiers, connection status, synchronization status, copier settings, operational telemetry, error logs, and related metadata necessary to provide, secure, support, troubleshoot, and improve the Service. Tradecopia does not use this information to guarantee, certify, or monitor your compliance with any third-party prop firm, broker, exchange, evaluation account, or funded account rules.
2.5 Application Telemetry and Analytics Data
In connection with the operation, maintenance, support, and improvement of the Service, Tradecopia automatically collects application telemetry and analytics data. This includes user interactions within the application (such as features accessed, buttons clicked, navigation paths, workflow sequences, feature adoption and engagement metrics, and user interface interaction patterns); trading activity metadata relevant to copier operations and diagnostics (such as order replication events including success, failure, and partial states, synchronization status between connected accounts, copy latency measurements, lot size calculations, execution timing data, error states, retry attempts, and copier health metrics); timestamps and event logs (such as login and logout events, session start and end times, session duration, feature usage timestamps, operational sequence data, and system clock synchronization events); system and application events for troubleshooting (such as error codes, exception logs, stack traces, crash reports, application state at time of failure, memory usage, CPU utilization, thread states, and diagnostic snapshots); performance metrics (such as application response times, API call latencies, throughput measurements, queue depths, processing times, and resource consumption data); and application version information, update status, and configuration state. Telemetry data focuses on operational and diagnostic metadata, and we do not use telemetry to capture the specific financial content of your trades (such as profit and loss amounts or account equity balances) beyond what is necessary for copier operational diagnostics.
2.6 Authentication and Security Telemetry
For security, fraud prevention, and account protection purposes, we collect IP addresses (IPv4 and IPv6), user-agent strings, device fingerprints and hardware identifiers, approximate geolocation derived from IP address, login attempt records (both successful and failed), session activity and session tokens, and anomalous activity indicators and security event flags.
2.7 Device and Technical Information
We automatically collect technical information about your device and environment, including operating system type and version, browser type and version (for the Cloud version), screen resolution and display characteristics, device type (desktop, laptop, or mobile), network connection type and quality indicators, time zone and language settings, and hardware identifiers relevant to software licensing.
2.8 Website and Application Analytics Data
When you visit tradecopia.com, we collect website analytics data through Google Analytics, subject to your cookie consent preferences (managed through our consent management platform, CookieYes), including pages visited and navigation patterns, referral URLs and traffic sources, time spent on pages, click patterns and scroll depth, browser and device information, and approximate geographic location. Google Analytics is used only for the tradecopia.com website and does not collect data from your use of the Tradecopia software. Separately, when you use the Tradecopia software (the Tradecopia Pro desktop application or Tradecopia Web), we collect in-product usage analytics through Umami, including features and screens accessed, usage patterns, browser and device information, and approximate geographic region. Umami is a privacy-focused analytics platform that does not use cookies for tracking and does not collect personally identifiable information by default.
2.9 Support and Communication Data
When you contact our support team or communicate with us, we collect support ticket content, subject matter, and correspondence; live chat transcripts and communication records; any screenshots, logs, or diagnostic data you voluntarily provide; satisfaction survey responses; and communication preferences and history.
2.10 User-Submitted Content
We collect content that you voluntarily submit through the Service, including free-text feedback, feature requests, and suggestions; reviews and testimonials; forum posts or community contributions (if applicable); and any other content you choose to submit.
2.11 Cookies and Similar Technologies
Our website and Cloud application may use cookies, local storage, session storage, web beacons, pixels, and similar technologies to maintain session state, authentication, and security; remember user preferences and settings; analyze website traffic and usage patterns; improve Service functionality and user experience; and support marketing attribution (where applicable). You may manage cookie preferences through your browser settings or through the cookie consent mechanism enabled by us, though disabling certain cookies may affect the functionality of the Service. Essential cookies necessary for the operation of the Service cannot be disabled while using the Service. For additional information, see our Cookie Policy.
3. How We Use Your Information
We use the information we collect for the following specific purposes:
3.1 Service Delivery and Operations
We use your information to create, maintain, and administer your account; to authenticate your identity and manage access to the Service; to provide and operate the trade copier functionality, including connecting to third-party platforms on your behalf; to process and manage your subscription, billing, and payments; to maintain synchronization between connected trading accounts; to deliver updates, patches, and new versions of the software; and to communicate with you regarding your account, subscription, and Service-related matters (such as service announcements, billing notifications, and security alerts).
3.2 Support, Diagnostics, and Troubleshooting
We use your information to investigate and resolve customer-reported issues and support tickets; to diagnose operational problems, software defects, and system failures; to perform root-cause analysis of service disruptions; to reconstruct event sequences relevant to user-reported synchronization or execution issues; to verify the state of the system at the time of a reported issue; and to proactively identify and remediate potential issues before they affect users.
3.3 Product Improvement, Development, and Analytics
We use your information to understand product usage patterns, user behavior, and feature adoption; to identify areas for improvement and inform product development priorities and roadmap; to develop new features, functionality, and product offerings; to improve the reliability, stability, performance, and security of the Service; to conduct internal analytics and generate aggregated, de-identified usage statistics; to train, develop, test, and improve machine learning models and algorithms (using anonymized and aggregated data as described in Section 6); and to conduct A/B testing and feature experimentation.
3.4 Security, Fraud Prevention, and Compliance
We use your information to detect, prevent, investigate, and respond to fraud, unauthorized access, abuse, and security threats; to monitor for violations of our Terms of Service and Acceptable Use Policy; to enforce our contractual rights and policies; to protect the rights, property, and safety of Tradecopia, its users, and the public; to comply with applicable laws, regulations, legal processes, and governmental requests; and to cooperate with law enforcement and regulatory authorities as required by law.
3.5 Marketing and Communications
We use your information to send product update emails, feature announcements, and Service-related communications; to send promotional and marketing communications (where you have opted in or where permitted by applicable law); to administer customer retention campaigns and re-engagement communications; to solicit product reviews and user feedback; and to personalize your experience with the Service. You may opt out of promotional marketing communications at any time by following the unsubscribe link in any marketing email or by contacting us, though Service-related communications (such as billing notices, security alerts, and Terms updates) are not subject to opt-out as they are necessary for the provision of the Service.
3.6 Strategy Marketplace Data
If and when the Strategy Marketplace functionality is made available, Tradecopia may collect and process additional data in connection with your use of the Strategy Marketplace, including strategy performance metrics, signal sharing configurations, subscriber and follower data, and related operational metadata. Such data will be used to facilitate the operation of the Strategy Marketplace, calculate and distribute applicable revenue shares, monitor compliance with Strategy Marketplace terms, and provide performance transparency to marketplace participants.
4. Legal Bases for Processing
This Section applies primarily to users located in jurisdictions that require a legal basis for processing personal data (including the European Economic Area, United Kingdom, Switzerland, and similar jurisdictions).
4.1 Contract Performance (GDPR Art. 6(1)(b)). We process personal data where necessary for the performance of our contract with you, including providing the Service, managing your account and subscription, processing payments, connecting to third-party platforms on your behalf, delivering copier functionality, and communicating about Service-related matters.
4.2 Legitimate Interests (GDPR Art. 6(1)(f)). We process personal data where necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Our legitimate interests include improving and developing the Service, diagnosing and resolving issues, ensuring network and information security, detecting and preventing fraud, analytics and product intelligence, enforcing our Terms, and protecting our legal rights. For telemetry data specifically, our legitimate interests include maintaining service reliability, investigating customer-reported issues, and understanding usage patterns to inform product development.
4.3 Consent (GDPR Art. 6(1)(a)). We process personal data based on your freely-given, specific, informed, and unambiguous consent for optional marketing communications, non-essential cookies and analytics, and any other processing for which we specifically request your consent.
4.4 Legal Obligation (GDPR Art. 6(1)(c)). We process personal data where necessary for compliance with legal obligations to which we are subject, including tax and financial reporting obligations, responding to valid legal process (such as subpoenas and court orders), and regulatory compliance requirements.
4.5 Balancing Test for Telemetry. With respect to application telemetry and analytics data, we rely on legitimate interests where permitted by applicable law, including service reliability, customer support, and product improvement. We limit telemetry collection to operational metadata rather than sensitive personal information, use the data for necessary and proportionate operational purposes, and recognize that users retain the right to object to processing based on legitimate interests as described in Section 10.
5. Data Sharing, Disclosure, and Sub-Processors
We do not sell your personal information to third parties. We may share your information in the following circumstances and with the following categories of recipients.
5.1 Sub-Processors and Service Providers
We engage third-party service providers ("Sub-Processors") to assist in delivering, operating, maintaining, and supporting the Service. These Sub-Processors process personal data on our behalf and under our instructions, subject to contractual obligations requiring them to protect the confidentiality and security of personal data and to use it only for the purposes for which it was disclosed. You hereby consent to Tradecopia sharing with its Sub-Processors such personal data and other information as is reasonably necessary for the provision, operation, maintenance, support, and improvement of the Service. Our current Sub-Processors are as follows:
- Fly.io, Inc. (United States - primary region: San Jose, California). Fly.io hosts Tradecopia's primary application servers and PostgreSQL database. Data processed by Fly.io includes account identifiers (name, email, username, hashed password, and country), authentication telemetry (IP addresses, user-agents, device fingerprints, geolocation, and session activity), encrypted third-party brokerage OAuth tokens (encrypted at rest with AES-256-GCM with encryption keys held outside the database), billing identifiers (name, email, address, and Stripe customer and payment-method IDs), trading account metadata and performance statistics, user-submitted free-text feedback, and copier configuration data.
- Stripe, Inc. (United States). Stripe serves as our payment processor for subscription billing, invoicing, and related payment services. Data processed by Stripe includes billing name, billing email, billing address, payment card details (stored by Stripe, not by Tradecopia), transaction records, Stripe customer and payment method identifiers, and subscription status.
- Google Cloud Platform (GCP) (United States and global regions). GCP hosts our operational and server-side logging infrastructure, including API logs, website logs, and observability tooling (Grafana stack). Data processed through GCP includes server-side application logs, API request and response metadata (including IP addresses and user-agents), error logs, performance metrics, and infrastructure health data.
- Amazon Web Services (AWS) (United States and global regions). AWS is used for client-side application log ingestion and storage. Data processed through AWS includes application-generated logs from the desktop software (Pro) and web application (Cloud), including telemetry events, diagnostic data, error reports, and operational event streams originating from the user's device or session.
- SendGrid (Twilio Inc.) (United States). SendGrid provides transactional email delivery services. Data processed by SendGrid includes email address, name, email content, delivery status, and engagement metrics for service-related communications (such as account verification, password reset, billing notifications, and support communications).
- GoHighLevel (United States). GoHighLevel is used for marketing communications, customer retention campaigns, product update emails, and review outreach. Data processed by GoHighLevel includes email address, name, subscription status, communication preferences, email engagement metrics, and campaign interaction data.
- Umami (self-hosted or cloud). Umami is a privacy-focused analytics provider used for in-product usage analytics for the Tradecopia Pro desktop application and Tradecopia Web. Data processed by Umami consists of anonymized usage data, feature and page views, referral sources, browser and device information, and geographic region. Umami does not use cookies and does not collect personally identifiable information by default.
- Intercom (Intercom, Inc.) (United States). Intercom powers the live-chat and support messaging functionality available to signed-in users. Data processed by Intercom includes name, email address, chat transcripts and message content, support conversation history, and related support metadata.
- CookieYes (CookieYes Limited). CookieYes provides cookie consent management for tradecopia.com. Data processed by CookieYes includes consent records and status, IP address, and browser and device information.
Tradecopia maintains data processing agreements with all Sub-Processors that contractually require them to process personal data only on Tradecopia's documented instructions, implement appropriate technical and organizational security measures, assist with data subject rights requests, notify Tradecopia of data breaches, and delete or return personal data upon termination of the relationship. Tradecopia reserves the right to add, remove, or change Sub-Processors from time to time, and material changes to Sub-Processors will be reflected in updates to this Privacy Policy. Where required by applicable law, we will provide advance notice of new Sub-Processors and an opportunity to object.
5.2 Legal and Compliance Disclosures
We may disclose your information where required or permitted by law, including in response to a valid subpoena, court order, search warrant, or other lawful legal process; to comply with applicable laws, regulations, or binding governmental requests; to cooperate with law enforcement investigations or regulatory inquiries; to enforce our Terms of Service, this Privacy Policy, or other agreements; to protect the rights, property, safety, or security of Tradecopia, its users, or the public; to investigate, prevent, or take action regarding suspected fraud, abuse, illegal activity, or violations of our Terms; and to establish, exercise, or defend legal claims.
5.3 Business Transfers
In connection with any merger, acquisition, reorganization, asset sale, financing, bankruptcy, or similar transaction, your information may be disclosed to prospective acquirers or their advisors during due diligence and transferred to the successor entity upon closing. We will provide notice of any such transfer and any choices you may have regarding your information, as required by applicable law.
5.4 With Your Consent
We may share your information with third parties when you have provided explicit consent for such sharing.
5.5 Aggregated and De-Identified Data
We may share aggregated, de-identified, or anonymized data that cannot reasonably be used to identify you with third parties for any lawful purpose, including research, analytics, benchmarking, and industry reporting. Such data is not subject to the restrictions in this Policy applicable to personal data.
6. Data Anonymization, Aggregation, and Derived Data
6.1 Right to Anonymize and Aggregate. Tradecopia retains the perpetual, irrevocable right to anonymize, de-identify, and aggregate data collected through the Service - including telemetry data, usage data, performance data, operational data, and metadata - such that it can no longer reasonably be used to identify you or any individual user, household, or device.
6.2 Nature of Anonymized Data. Once data has been anonymized and aggregated in accordance with applicable standards (including, where relevant, the GDPR's standard of data that cannot be reasonably linked back to an identified or identifiable natural person, and the CCPA/CPRA's deidentification standards), such data shall no longer constitute "personal data," "personal information," or "personally identifiable information" under applicable law and is not subject to the provisions of this Policy governing personal data.
6.3 Permitted Uses of Anonymized and Aggregated Data. Tradecopia may use anonymized and aggregated data for any lawful purpose without restriction, obligation, or compensation to you. Permitted uses include, without limitation, internal research, analytics, and statistical analysis; product development, improvement, and optimization; machine learning and artificial intelligence model training, development, testing, validation, and improvement; algorithm development, calibration, and enhancement; automated system training and performance optimization; benchmarking, performance comparison, and industry analysis; generating aggregated insights, reports, and publications; marketing and promotional purposes (in aggregate form only, never identifying individual users); improving the accuracy and effectiveness of trade copier algorithms and execution logic; developing predictive models for system reliability and performance; and any other lawful commercial or academic purpose.
6.4 Survival. Tradecopia's rights under this Section 6 survive the termination or expiration of your subscription, your account closure, and the deletion of your personal data. Anonymized and aggregated data is not subject to data deletion requests, access requests, portability requests, or any other individual data rights, as it does not constitute personal data.
6.5 Technical Safeguards. Tradecopia implements appropriate technical measures designed to support effective anonymization, including removal of direct identifiers, generalization of quasi-identifiers, statistical noise injection where appropriate, and measures intended to reduce re-identification risk.
7. Cross-Border Data Transfers
7.1 International Processing. Tradecopia operates from and processes data primarily in the United States. Your personal data may be processed in countries other than your country of residence, including countries that may not provide the same level of data protection as your home jurisdiction. Specifically, core customer and account data is stored in the United States (Fly.io, San Jose, California); billing and payment data is processed in the United States (Stripe); server-side operational logs are processed through Google Cloud Platform (United States and global regions); client application logs are processed through Amazon Web Services (United States and global regions); transactional emails are processed through SendGrid in the United States; and marketing communications are processed through GoHighLevel in the United States.
7.2 Transfer Safeguards (EEA/UK/Switzerland). Where we transfer personal data from the European Economic Area ("EEA"), United Kingdom, or Switzerland to a country not recognized as providing an adequate level of data protection (including the United States), we rely on one or more of the following appropriate safeguards: Standard Contractual Clauses ("SCCs") adopted by the European Commission (Commission Implementing Decision (EU) 2021/914); the UK International Data Transfer Agreement ("IDTA") or UK Addendum to the EU SCCs issued by the UK Information Commissioner's Office; Swiss-appropriate safeguards recognized by the Swiss Federal Data Protection and Information Commissioner; data processing agreements with Sub-Processors incorporating equivalent protections and security requirements; EU-U.S. Data Privacy Framework certification of the receiving entity (where applicable); and any other lawful transfer mechanism recognized under applicable data protection law. Where required, supplementary measures (including encryption, pseudonymization, and access controls) are implemented to provide additional protection for transferred data.
7.3 Cross-Border Transfer Safeguards. Tradecopia uses cross-border data transfer mechanisms as required under applicable data protection law, taking into account the nature of the personal data, the destination country, the recipient, and the contractual, technical, and organizational safeguards applied to the transfer. You may request further information about the specific safeguards applied to transfers of your data by contacting us at the address set forth in Section 14.
7.4 Consent to Transfer. By using the Service, you expressly consent to the transfer of your personal data to the United States and other jurisdictions as described in this Section, and acknowledge that such jurisdictions may have different data protection standards than your country of residence.
8. Data Retention
We retain your personal information for the periods necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are as follows:
| Data category | Retention period |
|---|---|
| Account and Registration Data | Account and registration data is retained for the duration of your active subscription and for thirty-six (36) months following account closure or subscription termination, to comply with legal obligations, facilitate account reactivation, resolve disputes, and enforce our agreements. After this period, account data may be securely deleted or anonymized. |
| Billing and Transaction Records | Billing and transaction records are retained for seven (7) years following the transaction date, as required by applicable tax, accounting, financial reporting, and anti-money laundering laws and regulations. |
| Application Telemetry and Analytics Data | Application telemetry and analytics data is retained in identifiable form for up to twelve (12) months from the date of collection for operational, diagnostic, and support purposes. After this period, telemetry data is either securely deleted or anonymized and aggregated for product improvement and statistical analysis purposes (in which form it may be retained indefinitely pursuant to Section 6). |
| Authentication and Security Logs | Authentication and security logs are retained for up to ninety (90) days in identifiable form for active security monitoring and troubleshooting. Security event logs related to investigated incidents may be retained for up to twenty-four (24) months. |
| Support Communications | Support communications are retained for twenty-four (24) months following resolution of the applicable support request for quality assurance, training, and dispute resolution purposes. |
| Marketing and Communication Data | Marketing and communication data is retained until you unsubscribe from marketing communications, plus a suppression list entry retained indefinitely to ensure we honour your opt-out preference. |
| Brokerage Connection Data | Encrypted OAuth tokens and API credentials are retained only for the duration of the active connection and are securely deleted within seven (7) days of disconnection or account termination. |
| Website and Application Analytics | Analytics data collected through Umami and Google Analytics is retained in anonymized form for up to twenty-four (24) months. |
| Backup Archives | Residual copies of personal data may persist in encrypted backup archives on a rolling basis following deletion or anonymization in production systems, after which they are overwritten in the ordinary course. Backup copies are not used for active processing and remain subject to the security measures described in this Policy. |
Deletion and Anonymization. Upon expiration of the applicable retention period, personal data is either securely deleted using industry-standard methods or irreversibly anonymized. Aggregated, de-identified data that cannot reasonably be used to identify an individual may be retained indefinitely pursuant to Section 6.
9. Data Security
9.1 Security Measures. We implement and maintain appropriate technical and organizational measures designed to protect your personal information against unauthorized access, alteration, disclosure, destruction, loss, and misuse. These measures include encryption of data in transit using TLS 1.2 or higher and SSL; encryption of sensitive data at rest (including AES-256-GCM encryption for OAuth tokens with encryption keys stored separately from the database); secure hashing of passwords (passwords are never stored in plaintext); role-based access controls and the principle of least privilege; multi-factor authentication for internal administrative access; code reviews and vulnerability scanning; network segmentation and firewall protections; security event logging and monitoring; incident response plans and procedures; employee security awareness training; and security diligence for Sub-Processors.
9.2 Limitations. No method of transmission over the internet and no method of electronic storage is completely secure. While we implement commercially reasonable measures to protect your personal information, we cannot guarantee absolute security. You acknowledge that you transmit information to us at your own risk and that security breaches may occur despite our best efforts.
9.3 Breach Notification. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority in accordance with applicable data protection law (including within 72 hours where required by applicable law).
9.4 Your Security Responsibilities. You are responsible for maintaining the security of your own account credentials, devices, and network connections. You should use strong, unique passwords, enable available security features (such as two-factor authentication), and promptly report any suspected unauthorized access.
10. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights regarding your personal data. We are committed to honouring your rights to the extent required by applicable law.
10.1 Rights Available to All Users
All users of the Service may exercise the following rights: the right to request confirmation of whether we process your personal data and to obtain a copy of such data; the right to request correction or update of inaccurate, incomplete, or outdated personal data; the right to request deletion or erasure of your personal data, subject to our legal retention obligations and legitimate interests; the right to request a copy of your personal data in a structured, commonly used, machine-readable format (data portability); the right to opt out of promotional marketing communications at any time via the unsubscribe link or by contacting us; the right to withdraw consent at any time where processing is based on consent (without affecting the lawfulness of processing prior to withdrawal); and the right to receive clear and transparent information about how your data is processed.
10.2 Additional Rights for EEA/UK/Swiss Residents
If you are located in the EEA, UK, or Switzerland, you additionally have the right to object to processing based on legitimate interests (including profiling), after which we will cease processing unless we demonstrate compelling legitimate grounds; the right to request restriction of processing in certain circumstances (such as while we verify the accuracy of your data); the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal effects or similarly significantly affect you; and the right to lodge a complaint with your local data protection supervisory authority (such as the supervisory authority in your country of habitual residence, place of work, or place of alleged infringement).
10.3 California Residents - CCPA/CPRA Rights
If you are a California resident, you have the following rights under the California Consumer Privacy Act and California Privacy Rights Act (as amended): the right to know what categories and specific pieces of personal information are collected, the purposes of collection, the categories of sources, and the categories of third parties with whom information is shared; the right to delete your personal information, subject to statutory exceptions; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information (Tradecopia does not sell personal information as defined under the CCPA/CPRA); the right to limit the use and disclosure of sensitive personal information to purposes permitted by the CCPA/CPRA; and the right to exercise your rights without facing discriminatory treatment in the quality or pricing of the Service. Under California's "Shine the Light" law, California residents may also request information regarding our disclosure of personal information to third parties for direct marketing purposes; we do not share personal information with third parties for their own direct marketing purposes.
10.4 Other Jurisdictions
Residents of other jurisdictions (including Canada, Australia, and Brazil) may have additional rights under their local data protection laws. We will respond to rights requests in accordance with the applicable law of your jurisdiction.
10.5 Exercising Your Rights
To exercise any of the rights described above, please submit a verifiable request to us at privacy@tradecopia.com or through our data request form at tradecopia.com/legal/request-data. We will respond to verified requests within the timeframes required by applicable law: within one (1) month for GDPR and UK GDPR requests (extendable by two additional months for complex requests); within forty-five (45) days for CCPA/CPRA requests (extendable by an additional forty-five days with notice); and within the timeframe specified by applicable law for other jurisdictions. We may require verification of your identity before processing data rights requests, and for requests that are manifestly unfounded or excessive (particularly if repetitive), we may charge a reasonable fee or decline to act, as permitted by applicable law.
10.6 Limitations on Rights
Your data rights are not absolute. We may decline or limit a request where permitted by applicable law, including where the request would adversely affect the rights and freedoms of others, where we are required to retain data for legal compliance purposes, where the data has been anonymized and can no longer identify you, where the request is manifestly unfounded or excessive, or where an applicable statutory exception applies.
11. Children's Privacy
The Service is not directed to, designed for, or intended for use by individuals under the age of eighteen (18) or the applicable age of majority in their jurisdiction (whichever is higher). We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will take prompt steps to delete such information from our systems. If you believe a child under 18 has provided us with personal information, please contact us immediately at privacy@tradecopia.com.
12. Do Not Track and Global Privacy Controls
12.1 Do Not Track. Some web browsers transmit "Do Not Track" ("DNT") signals. There is currently no universally accepted standard for how companies should respond to DNT signals, and accordingly, the Service does not currently alter its data collection or processing practices in response to DNT signals. We will update this Policy if and when a uniform standard for DNT is established.
12.2 Global Privacy Control. We honour Global Privacy Control ("GPC") signals where required by applicable law (including as an opt-out of "sale" or "sharing" under the CCPA/CPRA). If your browser or device sends a GPC signal, we will treat it as a valid opt-out request for the applicable jurisdiction.
13. Changes to This Privacy Policy
13.1 Right to Update. We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, regulatory guidance, or other operational factors. The "Last Updated" date at the top of this Policy indicates when the most recent revision was published.
13.2 Notice of Material Changes. For material changes to this Policy (such as new categories of data collection, new purposes of processing, new Sub-Processors, or changes to cross-border transfer mechanisms), we will provide notice through one or more of the following means: email notification to the address associated with your account, prominent notice within the Service, or posting the revised Policy on tradecopia.com with a highlighted summary of changes.
13.3 Acceptance of Changes. Your continued use of the Service following the posting of or notification about changes constitutes your acceptance of such changes. Where required by applicable law (such as GDPR), we will obtain your consent before implementing material changes to processing activities that require consent as a legal basis.
14. Contact Information
For questions, concerns, complaints, or requests regarding this Privacy Policy or our data practices, please contact:
- Tradecopia - Privacy Inquiries: Tradecopia Solutions Inc., 233 - 1433 Lonsdale Avenue, North Vancouver, BC V7M 2H9, Canada
- Email: privacy@tradecopia.com
- Website: tradecopia.com
For EEA/UK residents, if you are unsatisfied with our response to a privacy inquiry or believe we have processed your data unlawfully, you have the right to lodge a complaint with the data protection supervisory authority in your country of habitual residence, place of work, or place of the alleged infringement.
15. Supplemental Disclosures
15.1 Data Architecture Summary
For transparency, the following summarizes Tradecopia's primary data flows: core customer and account data is stored in a PostgreSQL database on Fly.io (United States, San Jose, California region); billing and payment information is processed and stored by Stripe (United States); API, server, and website operational logs are processed through Google Cloud Platform (Grafana observability stack); client application and customer-side application logs are ingested and stored through Amazon Web Services; transactional email is delivered through SendGrid; marketing communications are managed through GoHighLevel; website analytics for tradecopia.com are collected through Google Analytics (subject to cookie consent managed through CookieYes); in-product usage analytics for the Tradecopia Pro and Tradecopia Web applications are collected through Umami; and signed-in live-chat support is provided through Intercom.
15.2 Cloud Environment
For Tradecopia Cloud (web version) subscribers, each user operates in a logically isolated environment. Your trading configuration data, copier settings, and operational state are isolated from other users' environments, and telemetry and operational data collected from your environment is subject to the same privacy protections described throughout this Policy.
15.3 Desktop Application Data Collection
For Tradecopia Pro (desktop version) users, telemetry data is transmitted from the locally-installed application to Tradecopia's servers (via AWS log ingestion infrastructure) over encrypted connections (TLS). The desktop application does not access, scan, or index files or applications on your device unrelated to the Service; does not capture screenshots, keystrokes, or screen content; does not access your microphone, camera, or other peripheral devices; does not install background services or processes beyond what is required for the Service to function; and does not transmit data when the application is not actively running (unless a background service is required for copier operation and you have been informed of such).
15.4 Sensitive Data
Tradecopia does not intentionally collect sensitive personal data (also known as "special categories" under GDPR), including data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation. If we inadvertently receive such data (for example, in free-text feedback), we will delete it upon identification unless retention is required by law.
15.5 Automated Decision-Making
Tradecopia does not make automated decisions about you that produce legal effects or similarly significantly affect you based on your personal data. The Service's copier functionality executes trades based on user-configured rules, not on profiling of individual users. Security measures (such as suspicious login detection) may involve automated processing but do not produce effects beyond temporary access restrictions pending verification.
15.6 California Categories of Personal Information
For California residents, the following CCPA categories of personal information may be collected: identifiers (name, email, username, IP address, and device identifiers); customer records (billing information, address, and payment records); internet and electronic network activity (browsing history, interaction with the Service, and telemetry); geolocation data (approximate, derived from IP address); professional or employment information (only if voluntarily provided); and inferences drawn from the above (usage patterns and preferences). We do not collect biometric information, protected classification characteristics, sensory data, or education information.
16. Governing Law
16.1 Governing Law. This Privacy Policy shall be governed by and construed in accordance with the laws of the Province of British Columbia and the federal laws of Canada applicable therein, without regard to any conflict of laws principles that would require the application of the laws of any other jurisdiction.
16.2 Exclusive Jurisdiction. Any dispute arising out of or relating to this Privacy Policy or our data processing practices that is not otherwise subject to the exclusive jurisdiction of a data protection supervisory authority shall be resolved exclusively in the courts of competent jurisdiction located in the City of Vancouver, Province of British Columbia, Canada, and you irrevocably consent to the exclusive personal and subject matter jurisdiction of such courts.
16.3 Relationship to Terms of Service. This Privacy Policy is incorporated into and forms part of the Tradecopia Terms of Service. In the event of any conflict between this Privacy Policy and the Terms of Service with respect to data processing practices, this Privacy Policy shall prevail.
© 2026 Tradecopia Solutions Inc. All rights reserved.
