Privacy Policy

Last Updated: March 15, 2026

This Privacy Policy describes how CopyBridge ("we," "us," or "our") collects, uses, and protects your personal information when you use our trade copying infrastructure platform ("Service"). We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR).

1. Data Controller Information

CopyBridge acts as the data controller for personal information collected through our Service.

Contact Information:
Email: [email protected]

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address, name, password
  • Profile Information: Trading preferences, platform settings
  • Payment Information: Billing details (processed by Whop, our payment processor)
  • Communication Data: Messages sent through our support system

2.2 Information Automatically Collected

  • Usage Data: API calls, feature usage, login timestamps
  • Technical Data: IP address, browser type, device information
  • Trading Data: Signal metadata, follower connections, trade execution logs
  • Performance Data: System performance metrics, error logs

Note: We do not collect actual trading account credentials or broker login information. Our system uses secure API keys and subscriber IDs for trade copying.

3. How We Use Your Information

We use your personal information for the following purposes:

3.1 Service Provision

  • Providing and maintaining our trade copying platform
  • Facilitating connections between CopyProviders and followers
  • Processing API requests and executing trade signals
  • Managing your account and subscription

3.2 Communication

  • Sending service-related notifications
  • Responding to your inquiries and support requests
  • Providing important updates about our Service

3.3 Improvement and Analytics

  • Analyzing usage patterns to improve our Service
  • Monitoring system performance and reliability
  • Detecting and preventing security threats

3.4 Legal Compliance

  • Complying with applicable laws and regulations
  • Responding to legal requests and court orders
  • Protecting our rights and preventing misuse

4. Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal grounds:

  • Contract: Processing necessary to provide our Service
  • Legitimate Interest: Improving our Service and preventing fraud
  • Legal Obligation: Complying with applicable laws
  • Consent: Where you have provided explicit consent (e.g., marketing communications)

5. Data Storage and Security

5.1 Data Location

Your personal data is stored in our PostgreSQL database hosted by Hetzner in Helsinki, Finland (European Union). This ensures your data remains within the EU and is subject to GDPR protections.

5.2 Security Measures

  • Data encryption in transit and at rest
  • Secure API authentication and access controls
  • Regular security monitoring and updates
  • Limited access to personal data on a need-to-know basis
  • Secure backup and disaster recovery procedures

5.3 Data Retention

We retain your personal data only for as long as necessary to provide our Service and comply with legal obligations:

  • Account Data: Until account deletion or 3 years after last activity
  • Trading Data: 7 years for regulatory compliance
  • Support Communications: 3 years from last interaction
  • Usage Logs: 12 months for security and performance monitoring

6. Data Sharing and Disclosure

We never sell your personal data to third parties.

We may share your information only in the following limited circumstances:

6.1 Service Providers

  • Whop: Payment processing (as Merchant of Record)
  • Hetzner: Cloud hosting and infrastructure
  • Email Service: Transactional emails and notifications
  • Umami (self-hosted): Cookieless website analytics, hosted at analytics.steadyflowfx.com

All service providers are bound by data protection agreements and process data only as instructed.

6.2 Legal Requirements

We may disclose your information if required by:

  • Legal process or court order
  • Regulatory investigation or enforcement
  • Protection of our legal rights
  • Prevention of fraud or illegal activity

7. Your Rights Under GDPR

As a data subject, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of your personal data
  • Right of Rectification: Correct inaccurate or incomplete data
  • Right of Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restrict Processing: Limit how we process your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent for processing where applicable

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.

Right to Lodge a Complaint: You have the right to file a complaint with your local data protection authority if you believe we have not handled your data properly.

8. Cookies and Tracking

Our Service uses minimal tracking technologies:

8.1 Essential Cookies

  • Session management and authentication
  • Security and fraud prevention
  • Basic functionality and preferences

8.2 Analytics

We use Umami, a privacy-focused analytics tool we self-host at analytics.steadyflowfx.com, to understand how our Service is used and to identify areas for improvement. No personally identifiable information is shared with analytics providers.

This analytics is cookieless: it sets no cookies and stores nothing in your browser's localStorage or sessionStorage, which is why no cookie consent banner is required for it.

You can control cookies through your browser settings, though some features may not function properly if essential cookies are disabled.

9. Children's Privacy

Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately.

10. International Transfers

Your personal data is processed and stored within the European Union (Finland) and is not transferred to third countries outside the EU/EEA, ensuring full GDPR protection.

If international transfers become necessary in the future, we will implement appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of material changes by:

  • Email notification to your registered address
  • Prominent notice on our platform
  • Updating the "Last Updated" date at the top of this policy

Your continued use of our Service after changes take effect constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Email: [email protected]
Subject Line: Privacy Policy Inquiry

We are committed to resolving any privacy concerns promptly and transparently.

This Privacy Policy is part of our Terms of Service and should be read in conjunction with those terms. By using CopyBridge, you acknowledge that you have read and understood this Privacy Policy.