1. Overview
MetaKit ("MetaKit", "we", "us", "our") provides an API and dashboard for connecting, monitoring and automating MetaTrader 5 ("MT5") trading accounts, including analytics and trade copying. This Privacy Policy applies to our website, dashboard, API and all related services (together, the "Services").
We are the data controller for the personal information described in this policy. By creating an account or using the Services, you acknowledge the practices described here. If you do not agree with this policy, please do not use the Services.
2. Information we collect
2.1 Information you provide directly
- Account information — name, email address, password hash, and (optionally) company name, country and billing address.
- Trading account credentials — the MT5 login number, server name, and account password (investor/read-only or master/full) that you supply so we can connect to your trading account on your behalf. See Section 4 for how these are handled.
- Configuration data — copier settings, symbol mappings, multipliers, risk limits, webhook endpoint URLs and API key metadata.
- Support communications — the contents of emails, tickets and other messages you send us, including any attachments.
2.2 Trading and account data
Once you connect an MT5 account, we collect and store data retrieved from that account in order to provide the Services. This includes open and historical positions and orders, tickets, symbols, volumes, entry and exit prices, stop-loss and take-profit levels, commissions, swaps, profit and loss, account balance, equity, margin, leverage, currency, and broker/server identifiers.
2.3 Information collected automatically
- Usage and device data — IP address, browser type and version, operating system, device type, referring URLs, pages viewed, timestamps and interactions with the dashboard.
- API telemetry — endpoints called, request volumes, response codes, latency, rate-limit consumption and error traces. We use this to operate, secure, debug and capacity-plan the Services.
- Cookies and similar technologies — used for authentication, preferences and analytics. See Section 8 and our Cookie Policy.
2.4 Payment information
Payments are processed by Stripe, Inc. using Stripe Custom Elements. Card details are entered directly into Stripe-hosted input fields embedded in our checkout — the card number, expiry, CVC and any related authentication data are transmitted directly to Stripe and are never received, processed or stored on MetaKit servers.
We receive from Stripe only limited billing metadata: a customer identifier, subscription and invoice records, the card brand, the last four digits, the expiry month/year, the billing country and postal code, and the outcome of each payment attempt.
Stripe processes your payment data as an independent controller for certain purposes, including fraud prevention and legal compliance. Your payment information is therefore also subject to Stripe's own privacy policy, which we encourage you to read at stripe.com/privacy. We are not responsible for Stripe's handling of data under its own controllership.
3. How we use your information
We use the information described above to:
- Create, authenticate and administer your account and API keys.
- Connect to your MT5 accounts, retrieve trade and account data, and execute the actions you instruct through the API or dashboard.
- Operate the trade copier, including replicating orders from a master account to a follower account according to your configuration.
- Compute and display analytics — equity curves, drawdown, win rate, R-multiples and related performance metrics.
- Deliver webhook events to endpoints you configure.
- Process subscription payments, issue invoices and handle refunds.
- Provide support, respond to enquiries and send service-related communications (including outage, security and billing notices).
- Monitor, secure and improve the Services — including detecting abuse, fraud, unauthorised access and violations of our Terms & Conditions.
- Understand aggregate usage patterns and improve product design, using analytics data.
- Comply with legal, tax, accounting and regulatory obligations.
We do not sell your personal information, and we do not use your trading data to trade, to build trading signals for third parties, or to advise any other user.
4. Trading account credentials
Connecting an MT5 account necessarily requires us to hold credentials capable of authenticating to that account. We treat these as our most sensitive data category.
- Encryption. Credentials are encrypted at rest using industry-standard authenticated encryption, with keys held in a managed key store separate from the application database. They are transmitted only over TLS.
- Access control. Credentials are not visible in the dashboard or returned by the API after submission, and are not printed to logs. Access by personnel is restricted, role-based and audited, and is undertaken only where necessary to operate or debug the Services.
- Scope of use. We use credentials solely to establish and maintain the connection to your trading account and to perform the operations you have configured. We do not use them for any other purpose.
- Read-only vs full. Where your use case only requires monitoring and analytics, we strongly recommend connecting with an investor/read-only password, which cannot place trades.
- Deletion. When you remove a trading account, the stored credentials for that account are deleted from active systems promptly and purged from encrypted backups on our standard backup rotation.
You remain responsible for the security of your MT5 credentials at your broker, including rotating passwords and revoking access if you suspect compromise.
5. Legal bases for processing
Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases:
- Performance of a contract — to provide the Services you have subscribed to, including account connection, copying, analytics and webhooks.
- Legitimate interests — to secure and improve the Services, prevent fraud and abuse, and communicate about the product, provided these interests are not overridden by your rights.
- Consent — for non-essential cookies and analytics technologies, and for optional marketing communications. You may withdraw consent at any time.
- Legal obligation — to meet tax, accounting, and lawful request requirements.
6. How we share information
We do not sell or rent your personal information. We share it only in the following circumstances:
- Service providers (processors). Cloud hosting and infrastructure, database and backup providers, error monitoring and logging, transactional email delivery, analytics, and customer support tooling. These providers act on our instructions under contract.
- Payment processing. Stripe, as described in Section 2.4.
- Brokers and MT5 servers. Connection and order data is necessarily transmitted to the broker/server you specify in order to operate your account.
- Webhook endpoints you configure. Where you supply an endpoint URL, we transmit event data to it at your instruction. You are responsible for the security of any destination you nominate.
- Legal and safety. Where required by law, court order, regulator, or to establish, exercise or defend legal claims, or to protect the rights, property or safety of MetaKit, our users or the public.
- Business transfers. In connection with a merger, acquisition, financing or sale of assets, subject to the acquirer honouring this policy or providing notice of any material change.
- Aggregated or de-identified data. We may publish or share statistics that cannot reasonably be used to identify you or your positions.
7. International transfers
We operate globally and may process and store information in countries other than your own, including the United States. Where personal information is transferred out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with supplementary technical measures including encryption in transit and at rest.
8. Cookies and analytics
We use cookies and similar technologies for authentication, to remember your preferences, and to understand how the site and dashboard are used. Analytics providers may set cookies that collect information such as pages viewed, session duration, referral source and approximate location derived from IP address.
Non-essential cookies — including analytics and any advertising measurement — are set only where you have consented, and you can change or withdraw your preferences at any time. For the full list of categories, named third-party cookies and instructions on managing them, see our Cookie Policy.
9. Data retention
- Account records — retained while your account is active and for up to 24 months after closure, to handle disputes and support requests.
- Trading account credentials — deleted promptly when the trading account is removed or the MetaKit account is closed.
- Trade and analytics data — retained while the account slot is active; deleted or de-identified within 90 days of account removal, unless you request earlier deletion.
- Billing and invoice records — retained for the period required by tax and accounting law, typically 7 years.
- Security and API logs — typically retained for 30–180 days.
10. Security
We use TLS for all data in transit, authenticated encryption for credentials at rest, role-based access control, network isolation, audit logging, and regular dependency and infrastructure patching. Access to production systems is limited to personnel who require it and is protected by multi-factor authentication.
No method of transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee absolute security, and you use the Services at your own risk. If we become aware of a breach affecting your personal information, we will notify you and any relevant regulator as required by law.
11. Your rights
Depending on your location, you may have the right to access, correct, delete, port, restrict or object to our processing of your personal information, and to withdraw consent where processing is based on consent. Residents of California may additionally have rights to know, delete, correct, and to opt out of the "sale" or "sharing" of personal information — we do not sell or share personal information as those terms are defined under the CCPA/CPRA.
Many of these actions can be performed directly in the dashboard. Otherwise, contact us at [email protected]. We will respond within the period required by applicable law (generally 30 days) and may need to verify your identity first. You also have the right to lodge a complaint with your local supervisory authority.
12. Children
The Services are not directed to individuals under 18, and we do not knowingly collect personal information from them. If you believe a minor has provided us with information, contact us and we will delete it.
13. Third-party sites
The Services may link to third-party websites, brokers or tools that we do not control. This policy does not apply to them, and we are not responsible for their content or privacy practices. Review their policies before providing information.
14. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above, and for material changes we will provide additional notice by email or through the dashboard before the change takes effect. Your continued use of the Services after the effective date constitutes acceptance of the revised policy.
15. Contact us
Questions, requests or complaints about this policy or your personal information can be sent to [email protected].