This Privacy Policy explains how CopierPilot ("we", "us", "our") collects, uses, stores and protects information when you use our website and services (the "Service"). We act as the data controller under the EU General Data Protection Regulation (GDPR).
0. Data controller
The data controller is Demir Engineering, KvK 85986585, VAT NL223717058B02, Duifkruid 46, 4007 SX Tiel, the Netherlands. For privacy questions or to exercise your rights, contact support@copierpilot.com.
1. Data we collect
- Account data: name, email address, country, phone number, hashed password.
- Trading account data: MT5 server, login number and credentials you choose to connect. Credentials are stored encrypted and are never exposed to the browser.
- Trading activity: open and closed trades, balances, equity and copier routes you configure.
- Technical data: IP address, browser type, device information, log files and cookies.
2. How we use your data
- To provide and operate the Service (account management, copy trading, analytics).
- To secure your account and prevent fraud or abuse.
- To communicate with you about your account, support requests and service updates.
- To comply with legal obligations.
3. Legal basis (GDPR)
We process your data on the basis of (a) performance of a contract, (b) your consent (e.g. analytics cookies), (c) our legitimate interests in running and securing the Service, and (d) legal obligations.
4. Sharing your data
We do not sell your personal data. We share data only with processors that help us deliver the Service, including:
- Supabase (Lovable Cloud) — hosting, database, authentication.
- Cloudflare — content delivery and DDoS protection.
- Mollie B.V. — payment processing (Keizersgracht 313, 1016 EE Amsterdam).
- MetaQuotes / MT5 brokers — connectivity to your trading accounts (only the credentials you choose to connect).
- Mailgun / Lovable Email — transactional email delivery.
All processors are bound by data-processing agreements.
5. Data retention
We retain account and trading data for as long as your account is active. After deletion, residual backups are removed within 30 days, subject to legal retention obligations.
6. Your rights
You have the right to access, rectify, erase, restrict or port your personal data, and to object to processing. You may withdraw consent at any time and lodge a complaint with your local data-protection authority.
7. Security
We apply industry-standard security measures including TLS in transit, encryption of sensitive credentials at rest, row-level security on user data, and access controls. No system is 100% secure; you are responsible for keeping your password confidential.
8. International transfers
Your data may be processed outside the EEA by our infrastructure providers. We rely on Standard Contractual Clauses or equivalent safeguards.
9. Changes
We may update this Policy from time to time. Material changes will be communicated by email or in-app notice.
Questions about this Privacy Policy or your data? Contact us via in-app chat or at privacy@copierpilot.com.