Privacy Policy
Last updated: October 2026. This policy explains how we collect, protect, and process your data.
1. Service Provider & Contact
SnapCopier ("the Service", "we", "us", or "our") is an independent cloud trade copier platform. For inquiries regarding this Privacy Policy, your personal data, or exercising your data subject rights under applicable data protection laws (such as GDPR), please contact us at:
2. Categories of Information We Collect
We collect only the data necessary to provide reliable, low-latency trade copying:
Your name, email address, the country our CDN derives from your IP address at sign-up, salted password hash, and Google OAuth profile identifier (if logging in with Google).
Broker server name, MT4/MT5 account login number, and encrypted trading/investor password required to connect to the trade server.
Order tickets, traded symbols, lot sizes, open/close prices, execution timestamps, copy latency, and broker round-trip measurements.
IP addresses recorded in login attempt logs to prevent brute-force attacks, User-Agent strings, and essential authentication session tokens.
3. How We Secure Your Trading Credentials
We adhere to defensive engineering principles to protect sensitive trading credentials:
- AES-256-GCM Encryption at Rest: All trading passwords are stored in the database exclusively as authenticated ciphertext (AES-256-GCM with individual IVs). The encryption key is isolated in runtime environment configuration and is not stored in database dumps.
- In-Memory Decryption: Passwords are only decrypted in volatile memory on the dedicated trading node assigned to hold that account’s active lease when initiating a connection to the broker.
- Strict Log Sanitization: Plaintext trading passwords are never written to server logs, trace outputs, or shared with third parties.
- Follower Invite Privacy: When you invite followers via private invite links, followers connect their own accounts directly. Signal providers never see follower trading credentials.
- No Fund Access: MetaTrader passwords only authenticate trade executions. They cannot be used to perform cash withdrawals or deposits.
4. Purposes and Legal Bases (GDPR Article 6)
| Purpose | Legal Basis (GDPR) |
|---|---|
| Account creation, authentication, and service delivery | Performance of Contract (Art. 6(1)(b)) |
| Connecting to brokers, copying orders, and live dashboards | Performance of Contract (Art. 6(1)(b)) |
| Brute-force protection, audit logs, and platform security | Legitimate Interests (Art. 6(1)(f)) |
| Measuring broker execution latency to optimize routing | Legitimate Interests (Art. 6(1)(f)) |
| Billing, accounting, and compliance (when applicable) | Legal Obligation (Art. 6(1)(c)) |
5. Data Retention & Automatic Pruning
- Account & Credentials: Stored as long as your account remains active. Removing a trading account deletes its encrypted password and configurations immediately. Deleting your user account purges all associated records.
- Trade Copy Records: Operational copy events are partitioned by month and automatically deleted after 90 days to protect user privacy and optimize system efficiency.
- Security Logs: Login attempt logs (IP address and timestamp) are periodically rotated and retained only as long as necessary to enforce brute-force rate limits.
6. Third-Party Service Providers
We may engage trusted third-party service providers (processors) under strict confidentiality agreements to assist in operating the platform:
- Cloud Infrastructure: Secure server hosting, database hosting, and networking providers located in compliant data centers.
- Transactional Email: Providers used solely to deliver account verification emails and password reset links.
- Payment Processors: When paid tiers are active, payment details are collected directly by PCI-compliant payment gateways (e.g. Stripe). We do not store or process payment card numbers.
7. Your Rights Under GDPR
Under the European General Data Protection Regulation (GDPR) and similar data protection laws, you possess the following rights regarding your personal information:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure ("Right to be Forgotten"): Request the permanent deletion of your account and personal data.
- Right to Restriction & Objection: Object to or request restriction of certain data processing activities.
- Right to Data Portability: Obtain your data in a structured, commonly used, machine-readable format.
- Right to Lodge a Complaint: You have the right to file a complaint with your local data protection supervisory authority if you believe our data processing violates applicable regulations.
To exercise any of these rights, contact us at [email protected].
8. Cookies & Local Storage
We use only strictly necessary first-party cookies and tokens required to maintain your authenticated session and defend against Cross-Site Request Forgery (CSRF). We do not use third-party advertising cookies, cross-site trackers, or marketing trackers.
9. Changes to this Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
For questions or concerns regarding our privacy practices, contact us at [email protected].