What this policy covers
This policy explains what TradeMirror collects, why, how long it is kept, and how you can remove it. It applies to the TradeMirror website, application, and API.
TradeMirror is trade-copying infrastructure. It does not select trades, provide signals, or take custody of your funds - your money stays with your broker throughout.
What we collect
Account details: your name, email address, and a hashed password. Passwords are never stored in a form we can read.
Trading account credentials: the login, server, and password for each MetaTrader account you connect. These are encrypted at rest, and are used only to establish and maintain the copy route you configure.
Configuration and activity: your copy strategies, sizing rules, risk limits, and a record of copy executions so you can audit what the platform did on your behalf.
Operational data: connection events, error records, and security events such as failed sign-in attempts, which exist to keep the service working and to detect abuse.
Why we hold trading credentials
A copy platform cannot place a trade on a follower account without being able to sign in to it. Credentials are used for exactly that and nothing else: testing the connection you asked for, maintaining the session, and sending the copy instructions your strategy defines.
They are encrypted at rest and are never returned to the browser after saving. TradeMirror does not sell, rent, or share them.
Who else sees your data
Your broker, because that is where your accounts and trades live.
Infrastructure providers used to run the service: hosting, the database, and the email provider that delivers verification and alert messages.
The cryptocurrency payment provider, if you choose a paid plan. TradeMirror never sees or stores card details.
Our analytics provider, DataFast, which measures how the site is used and which marketing channel a signup came from. It sets a cookie named datafast_visitor_id in your browser to recognise return visits. Once you are signed in, your account's internal database id is linked to that visitor record so a visit and a signup can be joined up - your name and email address are never sent. When a payment completes, the amount, currency and that same opaque id are reported so the sale can be attributed.
No advertising networks and no data brokers. Your trading credentials, positions, strategies and execution history are never sent to the analytics provider or to any other third party.
Cookies
A session cookie keeps you signed in. It is strictly necessary - the application cannot work without it - and it is removed when you sign out.
The analytics cookie described above (datafast_visitor_id) recognises return visits and attributes signups to a marketing channel. Blocking it in your browser does not affect any part of the product: copying, payments and every account function work exactly the same.
No advertising or cross-site tracking cookies are set.
How long it is kept
Account and configuration data is kept while your account exists.
Execution history is kept so you can audit what was copied on your behalf, and is removed with your account.
Operational logs are short-lived and exist to diagnose faults.
Deleting your account and your data
You can permanently delete your account from Settings at any time. It asks for your password, because deletion cannot be undone.
Deleting removes your profile, connected trading accounts and their stored credentials, copy strategies, execution history, subscription record, and alerts.
It does NOT close positions already open at your broker. Those are your trades, with your money, at your broker - TradeMirror will not make a market decision on your behalf on the way out. Close them in your trading platform if that is what you want.
Any running copy strategy is stopped before deletion, so nothing continues to trade afterwards.
Your rights
You can access and correct your details in the application, and delete everything as described above.
For any other request, including a copy of your data, contact support@trademirror.io.
Security
Passwords are hashed, trading credentials are encrypted at rest, and sessions expire and rotate. Repeated failed sign-in attempts temporarily lock the account.
No system is perfectly secure. Use a unique password, enable two-factor authentication, and prefer an investor or trading credential over a master password where your broker offers one.