LAUNCH OFFER50% off every plan for your first 3 monthsSee pricing

Legal

Privacy Policy

Version 2026-09-29 · Effective 29 September 2026

1. Who we are and what this policy covers

This Privacy Policy explains how Aayush Kafle, sole trader (ABN 49 827 024 712) (“Aayush Kafle, sole trader”, “we”, “us”, “our”) collects, uses, stores, discloses and protects personal information when you use our website and copy-trading software at https://futurescopytrader.com (the “Service”). It applies to visitors, account holders and people who contact us.

The Service lets you place trades yourself on one trading account and have those trades mirrored to other trading accounts that you own or are lawfully authorised to operate. To do that, we connect to your broker or prop-firm platform through the credentials you give us.

Our Privacy Officer can be contacted at privacy@futurescopytrader.com or by post at 1/44A William Street, Jesmond NSW 2299, Australia.

By creating an account or using the Service you acknowledge this policy. If you do not agree with it, please do not use the Service.

2. The privacy laws we follow

We handle personal information in line with the following, whether or not we are strictly required to by law:

  • Australia: the Privacy Act 1988 (Cth) including the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, and the Spam Act 2003 (Cth).
  • United States: the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), other US state consumer-privacy laws (for example those of Virginia, Colorado, Connecticut, Utah and Texas), the CAN-SPAM Act, the Children’s Online Privacy Protection Act (COPPA), state data-breach notification laws, and Section 5 of the FTC Act.
  • Where you are located elsewhere (including the EEA and the UK), we apply the protections described in this policy to you as well, and you may contact us to exercise the rights described in section 12.

3. The information we collect

CategoryExamplesWhy we need it
Account informationEmail address, name (optional), password (stored only as a salted, peppered one-way hash), sign-up date, referral code used.To create and secure your account and contact you about it.
Two-factor authentication dataAn encrypted authenticator secret and hashed single-use recovery codes, if you turn on two-factor authentication.To protect your account.
Broker credentialsThe username and API key you give us for your trading platform (stored encrypted).To read your account state and place the mirrored orders you have asked for.
Trading-account dataAccount names and numbers, balances, open positions, orders and fills, retrieved from your broker through its API while you use the Service.To detect your trades, copy them, apply your risk limits and show you analytics.
Copy activity recordsA journal of each mirrored action (time, account, instrument, side, size, outcome).To show you what happened and to investigate problems.
Settings and configurationYour copy groups, follower settings, risk limits, time zone and preferences.To run the Service the way you configured it.
Billing informationPlan, invoices, payment status, and the card brand, last four digits and expiry of a payment method. Full card numbers are handled by our payment processor and never reach our servers.To charge for and administer your subscription.
Support communicationsMessages you send us and our replies.To help you and improve support.
Technical and security dataIP address, browser type, session identifiers, timestamps of sign-ins and security events (recorded in a tamper-evident audit log).To keep the Service and your account secure and to detect abuse.
Affiliate dataReferral link visits (counted, not tied to a person) and the sign-ups and payments attributed to a referrer.To operate the referral programme and pay commissions.

We do not knowingly collect government identification, health information, biometric data, precise location, or information about your race, religion, politics or sexuality, and we do not need any of these to provide the Service. Your trading and account data is financial information and we treat it with the highest level of care described in section 9.

4. How we collect information

  • Directly from you, when you register, sign in, configure the Service, contact support or subscribe.
  • Automatically, when you use the website (technical and security data, and the essential cookie described in section 14).
  • From your broker or prop-firm platform, but only through the credentials you provide and only to the extent needed to deliver the Service. We do not obtain information about you from data brokers.

5. How we use your information

  • To provide, operate and secure the Service, including detecting your trades and placing mirrored orders you have configured.
  • To authenticate you, prevent fraud and abuse, and protect the integrity of our systems and other users.
  • To process payments, issue invoices and administer subscriptions and referral commissions.
  • To communicate with you about the Service: verification and security emails, service and billing notices, and replies to your requests. These are not marketing and you cannot opt out of essential security messages while you have an account.
  • To send marketing about our products only if you have opted in; you can withdraw consent at any time (section 13).
  • To comply with our legal obligations and enforce our terms; and, using aggregated or de-identified data only, to understand and improve the Service.

We use your information only for the purposes above, or for a directly related purpose you would reasonably expect, or with your consent, or where the law requires or authorises it (APP 6).

6. Who we share information with

We do not sell your personal information and we do not share it for cross-context behavioural advertising. We disclose it only as follows:

  • Your broker or prop-firm platform, at your direction, when we place the orders and requests you have configured. Their handling of your data is governed by their own terms and privacy policy.
  • Cloud hosting and infrastructure (United States (Hetzner Online, Ashburn, Virginia)): stores the encrypted database and application — your account data, encrypted broker credentials and everything else described in section 3.
  • Stripe, Inc. (payment processing, United States): when you subscribe, your name, email address and payment details are sent directly to Stripe's own hosted Checkout and Customer Portal pages — we never receive or store your card number. Stripe sends us back only your subscription status, plan, renewal date and invoice history.
  • Cloudflare, Inc. (Turnstile bot-protection, global network with US-based infrastructure): when you sign up, sign in after a failed attempt, reset your password or submit a contact form, your browser sends Cloudflare a challenge token; Cloudflare tells us only whether it passed, not who you are.
  • Our email-delivery provider: your email address and the content of transactional emails we send you (verification, password reset, security alerts, invoices).
  • Professional advisers (lawyers, accountants, auditors, insurers) bound by confidentiality.
  • Regulators, courts and law-enforcement bodies where we are required or authorised by law, or where necessary to protect rights, property or safety.
  • A successor, if we are involved in a merger, acquisition or sale of assets; we will notify you and this policy will continue to apply to your information.

7. Overseas disclosure (APP 8)

Our hosting is located in United States (Hetzner Online, Ashburn, Virginia). That is outside Australia, so the personal information you give us (your email address, account details, settings and the trading-platform credentials you store with us, which are encrypted) is stored and processed there.

Other recipients that may handle information outside Australia: our email-delivery provider, Cloudflare (Turnstile bot-protection), Stripe (payment processing, based in the United States), and your broker or prop-firm platform (for example TopstepX / ProjectX), which we contact at your direction. These may store or access information in the United States and other countries.

Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, generally through contractual safeguards and by choosing providers with strong security practices. By using the Service you understand that such disclosure may occur.

8. Third-party market data and news

The home page shows public market quotes and news headlines retrieved by our servers from third-party sources. Your personal information is not sent to those sources; requests to them come from our servers, not your browser. Links to news articles open third-party websites that have their own privacy practices.

9. How we protect your information (APP 11)

We take reasonable steps, and use industry-standard measures, to protect information from misuse, interference, loss and unauthorised access, modification or disclosure. These include:

  • Encryption in transit: all traffic uses TLS 1.2 or higher, with HTTP Strict Transport Security.
  • Encryption at rest: broker API keys, authenticator secrets and support messages are encrypted with authenticated encryption (AES with HMAC) using keys held separately from the database and rotatable without downtime.
  • Password protection: passwords are never stored; only a salted, memory-hard scrypt hash further protected by a server-side secret. Passwords are checked against lists of common and breached passwords.
  • Account security: optional (and, for administrators, mandatory) two-factor authentication, single-use recovery codes, email verification, rate limiting and lockouts against guessing, short session lifetimes, sign-out of all devices on password change, and CSRF protection.
  • Application security: strict content-security policy, input validation, per-user data isolation, least-privilege access and a tamper-evident audit log.
  • Operational security: access restricted to authorised personnel, logging and monitoring, and encrypted backups.

No system is completely secure. You can help by using a unique password, turning on two-factor authentication, giving us an API key you can revoke, and revoking it at your broker if you stop using the Service or suspect misuse.

10. Data breaches

If we become aware of an eligible data breach, we will investigate promptly, take steps to contain it, and notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme, and notify affected individuals and regulators in the United States as required by applicable state breach-notification laws, without unreasonable delay.

11. How long we keep information

InformationRetention
Account, settings, copy groups and copy journalWhile your account is open. Deleted within 30 days after you delete your account.
Broker API keys and authenticator secretsDeleted immediately when you remove the login, turn off two-factor authentication, or delete your account.
Support ticketsUp to 24 months after the ticket is closed, or until you delete your account.
Security and audit logs (IP, timestamps, events)Up to 12 months, then deleted. Entries about a deleted account are kept for this period only to investigate abuse and comply with law.
Billing and tax records7 years, as required by Australian and US tax and corporate law.
Encrypted backupsOverwritten on a rolling schedule of up to 35 days.

When information is no longer needed for any purpose for which it may be used, we securely delete it or de-identify it (APP 11.2).

12. Your rights and how to exercise them

You can access, correct and delete much of your information yourself: Profile lets you download all your data, edit your details and delete your account (which deletes your saved logins, groups and journal). To use any right by email, contact privacy@futurescopytrader.com. We will verify your identity (by replying from your registered email or signing in) and respond within 30 days (or 45 days, extendable once by a further 45, for California requests).

Australia (APPs 12 and 13). You may request access to the personal information we hold about you and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. We may refuse in limited circumstances allowed by law and, if so, will explain why.

United States. Depending on where you live, you may have the right to: know what personal information we collect, use, disclose and retain; access a portable copy; correct inaccurate information; delete personal information; opt out of the sale or sharing of personal information and of targeted advertising (we do neither, so there is nothing to opt out of); limit the use of sensitive personal information (we do not use it beyond providing the Service); and not be discriminated against for exercising these rights. You may use an authorised agent, and if we decline a request you may appeal by replying to our decision and asking for review.

California “Shine the Light”: we do not disclose personal information to third parties for their own direct marketing. We do not respond differently to “Do Not Track” signals because we do not track you across websites; we treat a Global Privacy Control signal as an opt-out request, although no sale or sharing takes place.

13. Marketing communications

We send marketing email only with your consent (Spam Act 2003 and CAN-SPAM). Every marketing message identifies us and contains a working unsubscribe link, and you can also turn marketing off in Settings. We will action an unsubscribe request within 5 business days. Service, billing and security emails are not marketing.

14. Cookies and similar technologies

We use only the cookies that are strictly necessary to run the Service (keeping you signed in securely, and remembering a referral code for 30 days if you arrived through an affiliate link). We do not use advertising, analytics or cross-site tracking cookies. Details are in our Cookie Notice.

15. Children

The Service is for people aged 18 and over and is not directed to children. We do not knowingly collect personal information from anyone under 18 (and in particular under 13, or under 16 in California). If you believe a child has given us information, contact us and we will delete it.

17. Changes to this policy

We may update this policy from time to time. The current version is 2026-09-29, effective 29 September 2026. For material changes we will notify you in the Service or by email and, where required, ask you to accept the updated policy before you continue.

18. Questions and complaints

If you have a question or concern about our handling of your information, contact our Privacy Officer at privacy@futurescopytrader.com or 1/44A William Street, Jesmond NSW 2299, Australia. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.

If you are not satisfied, in Australia you may complain to the Office of the Australian Information Commissioner (www.oaic.gov.au, 1300 363 992, GPO Box 5288, Sydney NSW 2001). In the United States you may contact your state Attorney General or the Federal Trade Commission (www.ftc.gov); California residents may also contact the California Privacy Protection Agency (cppa.ca.gov).

Last updated: 29 September 2026.