Privacy Policy
This Privacy Policy explains what personal information QuantForges (“we”) collects when you use the services on quantforges.com and its subdomains (including qr.quantforges.com and mt.quantforges.com), how we use and protect it, and the rights you have. Please read it together with the Terms of Service.
In one sentence: we collect only the information needed to provide copy trading and trading services; exchange keys and account passwords are stored encrypted; we do not sell your personal information or use third-party advertising or analytics tracking; and your funds always stay in your own trading account, where we cannot move them.
1. Information we collect
| Category | What it includes | Source |
|---|---|---|
| Account information | Email address; sign-in password (only an irreversible hash is stored, and we cannot see the plain text); account roles (copier, lead trader and so on). | You provide it when registering |
| Jurisdiction information | The country or region you declare, and whether it was self-declared or confirmed by identity verification. | You provide it |
| Lead trader profile | Lead trader name, personal bio, region, and application and review records. A lead trader’s name and bio are shown publicly on the copy leaderboard. | You provide it when applying to become a lead trader |
| Trading venue credentials | Binance API Key and Secret; MT5 account number, server and trading password; your MetaApi access token. | You provide it when connecting an account |
| Trading data | The balance, equity, positions, orders, fills and deposit and withdrawal records of the accounts you connect, copy execution records and risk-limit trigger records. | Read from the trading venue with your authorisation, and generated when the Platform executes |
| Copy settings | The lead account you choose to follow, your capital allocation method and your risk parameters. | You set them |
| Bills and payments | Bill amounts and status, payment method, on-chain transaction hash and payment address. | Generated when you pay |
| Security logs | The time and result of sign-in attempts, IP address and browser identifier (User-Agent). | Generated automatically when you visit |
We do not collect your full card number, your trading venue sign-in password (Binance) or withdrawal permission, and we use no third-party advertising, analytics or behavioural tracking scripts on the website.
2. How we use this information
- Providing the service: identifying you; executing copying and trading in your account according to your settings; showing your accounts, positions, performance and bills.
- Applying regional rules: deciding from your jurisdiction whether copy trading is available, which fee model applies and the leverage cap.
- Billing: calculating fees from copy capital, the high-water mark and deposit and withdrawal records, issuing bills and confirming receipt.
- Showing lead performance: a lead account’s return, drawdown, running days, trade statistics and number of copiers are shown publicly to help copiers decide. We do not publish a lead trader’s account number, balance details, strategy code or parameters.
- Security and risk control: detecting unusual sign-ins, preventing fraud and abuse, troubleshooting faults and keeping the audit records that are needed.
- Notifications: sending service-related emails such as bills, free-period-ending notices, renewal reminders, risk-limit triggers and important announcements. We do not send third-party marketing email.
- Meeting legal obligations: complying with applicable law, regulatory requirements and lawful requests from judicial authorities.
3. How we protect this information
- Binance API Keys and Secrets, MT5 trading passwords and MetaApi access tokens are all stored encrypted and never in plain text; an MT5 trading password is kept only for as long as connecting the account needs it.
- Only a hash of your sign-in password is stored. Your signed-in state uses an HttpOnly cookie that web page scripts cannot read.
- We ask only for “Trading” permission on a Binance API Key and neither ask for nor should be given “Withdrawal” permission, so even if data were leaked, the credentials could not be used to move your assets out.
- Internal access follows the principle of least privilege, and administrators’ key actions leave audit records.
No system can be guaranteed absolutely secure. If a security incident that may affect you occurs, we will notify you promptly and explain the measures we are taking.
4. Who we share information with
We do not sell or rent your personal information. We share it only in the following necessary cases:
- Trading venues and brokers: to place orders in your account and read account data, we use your credentials to call the interfaces of Binance or your MT5 broker.
- MetaApi: MT5 copying connects to your broker account through a cloud terminal provided by MetaApi, which runs under your own MetaApi account.
- Payment services: on-chain payments are completed over the blockchain network and the transaction information is publicly visible on-chain; we use a blockchain explorer service to confirm receipt.
- Infrastructure providers: server hosting and email delivery providers, who process necessary information only to provide those services for us.
- Between lead traders and copiers: copiers can see a lead trader’s public profile and performance; a lead trader can see only the number of copiers and a summary of their own income, and cannot see a copier’s identity or account information.
- Legal requirements: to comply with laws and regulations, to cooperate with lawful requests from competent authorities, or to protect the lawful rights and interests of the Platform, users or the public.
5. Cookie
We use only the session cookie that is necessary to keep you signed in. This cookie is shared across the subdomains of quantforges.com so that you do not have to sign in again between the Copy Centre, the Trader Terminal and the MT5 Terminal. We do not use advertising or cross-site tracking cookies.
6. Retention
- Trading venue credentials: a Binance API Key is removed from the system once you delete it. An MT5 connection and MetaApi access token are, once you delete them, no longer used and are archived (still encrypted); you can write to ask for complete deletion, and they are deleted together when your account is closed.
- Trading, copy, billing and payment records: kept while your account exists; after your account is closed, kept for up to 5 years to meet financial reconciliation, dispute handling and legal requirements, and then deleted or anonymised.
- Security logs: kept for as long as is needed for security analysis and audit.
- A lead account’s public performance: no longer shown publicly once the lead account is delisted; to handle copiers’ disputes, the related records are kept for the period given above for trading records.
7. Your rights
Depending on the law where you live, you may have the following rights:
- Access and copy: to know what information we hold about you and to obtain a copy;
- Correction: to correct inaccurate or incomplete information;
- Deletion: to ask for your information to be deleted or your account closed, without affecting any legal retention obligation;
- Withdrawing authorisation: to remove a trading venue connection on the Platform at any time, or to revoke the API Key or change the MT5 password directly at the trading venue, ending our permission to place orders immediately;
- Objection and restriction: to object to particular processing or ask for it to be restricted.
To exercise these rights, write to [email protected], and we will reply within 30 days after verifying your identity. Before closing your account, please stop all copying and deal with the positions in your account.
8. Cross-border transfers
Our servers and some of our providers may be located outside your country or region, so your information may be transferred abroad for processing. We take reasonable measures to ensure it receives protection consistent with this policy.
9. Minors
The Service is for adults only. We do not knowingly collect personal information from minors; if we find we have collected it by mistake, we will delete it promptly.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified to you by an on-site announcement or email before they take effect. The date of the latest update is shown at the top of this page.
11. Contact us
If you have any questions about this policy or your personal information, write to [email protected].