Privacy Policy
Last updated: 28 August 2026
This policy explains which personal data we process, why we use it, who receives it, and which choices and rights you have.
1. Controller and scope
Nextproptrader LLC is responsible for the processing described in this policy. It applies to our website, dashboard, simulated trading services, purchases, payouts, support, newsletter, affiliate attribution, and appointment booking where offered.
Our services are intended for adults. They concern simulated trading accounts and do not give us authority to execute trades with a user's real money.
2. Data we process
The data depends on the feature you use. We collect data you provide, data generated when the service is used, and limited data received from payment, trading, market-data, calendar, and communications providers.
- Account and contact data, billing address, country, language, and communication preferences
- Orders, invoices, payment status, payout amount, payout method, and recipient details
- Identity data and documents when a payout recipient must be verified
- Simulated account, order, trade, performance, rule, and rule-breach data
- Support messages, attachments, newsletter status, consent records, and affiliate attribution
- Full IP address, user agent, session, device, and security-event data where required for security and fraud prevention
- Optional analytics and Meta marketing data only after the relevant consent
3. Purposes and legal bases
We process data to provide and administer the requested service, create and secure accounts, complete orders and payouts, verify payout recipients, enforce the published rules for simulated accounts, provide support, meet accounting and legal duties, and defend legal claims.
Depending on the purpose, we rely on performance of a contract (Article 6(1)(b) GDPR), compliance with legal obligations (Article 6(1)(c)), our legitimate interests in service operation, security, fraud prevention, referral administration, and legal defence (Article 6(1)(f)), or consent for optional analytics, marketing, and newsletters (Article 6(1)(a)). Consent can be withdrawn at any time for the future.
4. Cookies, analytics, Meta, and referrals
Necessary storage is used to run the site, maintain sessions, remember privacy choices, and protect the service. First-party analytics remains off until analytics consent is granted. Meta Pixel and server-side Meta Conversions API marketing events remain off until marketing consent is granted.
When enabled, analytics may record sanitised page paths, selected interactions, technical signals, campaign parameters, and business events. Meta may receive selected page, product, checkout, registration, and purchase events with matching identifiers. We do not intentionally send passwords, payment-card details, or form field values through these integrations.
If a user opens a partner link, first-party referral attribution is used to apply partner benefits and allocate commission. It operates independently of optional analytics and marketing consent and is not used to enrich Meta or analytics profiles without the relevant consent.
5. Payouts and identity verification
Identity verification is requested only when needed to confirm the recipient of a payout. We use identity details and documents to compare the recipient information, prevent fraud, and document the result. Access is restricted to personnel and providers who need it for that purpose.
Payout method and transaction data is used to process the requested payout, handle queries or disputes, and meet accounting and record-keeping duties. Depending on the selected method, data may be processed by Stripe, PayPal, a banking provider, or another displayed payout provider.
6. Automated evaluation of simulated trading
Published trading rules are evaluated automatically against the data of the simulated account. A detected rule breach can end or fail the affected simulated trading account and can affect eligibility to progress or request a payout associated with that account. It does not close the user's general account or cause transactions with the user's real money.
The decision record includes the applicable rule, account data, and relevant time. If a user believes that incorrect data, timing, account assignment, or rule configuration caused the result, they may contact Support and request a technical review. A confirmed technical error can be corrected.
7. Recipients and international transfers
We use service providers only where needed for the relevant feature. Current categories include AWS for infrastructure, Stripe and PayPal for payments, Google Maps for optional address suggestions, Meta for consented advertising measurement, Microsoft for calendar events and Microsoft 365 support-mail ingestion, and Rithmic and dxFeed for trading or market-data services.
Some recipients process data outside the EEA. Where GDPR transfer rules apply, we use an applicable adequacy decision, contractual safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism. Provider involvement depends on the service selected and the production configuration.
8. Security
We use technical and organisational measures selected according to the relevant risk. These include role-based access restrictions, authentication controls, logging, data separation, secret management, transport protection, backups, and incident handling where appropriate.
Full IP addresses may be retained in restricted security and authentication records to detect account takeover, abuse, and fraud. They are not reused for optional analytics or marketing without the required consent. No internet service can promise absolute security.
9. Retention and account closure
We keep personal data only for as long as it is needed for the stated purpose, an applicable legal retention duty, fraud prevention, dispute handling, or legal claims. Different periods apply to account, security, consent, support, trading, identity, and financial records. We review and delete or anonymise data according to the applicable retention schedule.
After account closure, ordinary profile and contact data is deleted or irreversibly anonymised when it is no longer needed. Invoices, transaction evidence, legal holds, and a minimal fraud-prevention record may remain for the relevant period. Data in backups is removed through the normal backup rotation.
10. Your rights
Subject to the conditions of applicable law, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing.
You may also lodge a complaint with the competent data protection authority. We normally answer verified requests within one month. We may request only the additional information reasonably needed to confirm identity.
11. Minors
The service is not intended for people under 18. If we learn that a minor supplied personal data contrary to this restriction, we will investigate and delete it where required.
12. Changes to this policy
We update this policy when processing activities or legal requirements change. The current version and date are published here. If a change materially affects consent-based processing, we request a new choice instead of treating continued use as consent.
Contact
For privacy questions or to exercise your rights, contact:
Nextproptrader LLC
Business Center 1, M Floor
Meydan Grand Stand
Dubai, United Arab Emirates
Email: support@nextproptrader.com
Please use a subject such as “Privacy request” so the request can be routed correctly.
