Privacy Policy
On this page
1. Data controller
The data controller for information collected through navigatoralgo.com and our MT5 EAs is Navigator Trading Systems ("Navigator Algo", "we", "us"), based in Sri Lanka. Contact: privacy@navigatoralgo.com.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account | Email address, display name, Firebase UID, sign-in provider (Google / password) | You, via Firebase Authentication |
| Profile (optional) | Phone, country, private notes you write in the Profile page | You |
| Provider metadata | provider_id (e.g. NAV-ADQ5Y), owner_uid, provider display name, license codes you mint |
Generated when you are bound to a provider |
| MT5 trading data | MT5 account number (login), trade signals you broadcast or receive (symbol, type, lots, prices, ticket), EA version, poll timestamps | Our EAs running on your MT5 terminal |
| Billing | MQL5 order reference and purchase date for products you buy through MQL5 Market. Not collected by us: card number, CVV, billing address — these go directly to MQL5 and its processors. | MQL5 Market order exports / support tickets |
| Operational logs | Request timestamps, IP address, user agent, license code used, HTTP status codes, error messages | Firebase Cloud Functions, Cloud Logging |
| Support | Any message you send via @Navigatoralgo_bot or email | You |
3. Why we process it
- Run the service. Relay signals between provider and receivers, enforce license state, check MT5-account binding, rate-limit abuse.
- Authenticate you. Confirm you own the account / provider / license you claim.
- Fulfil your purchase. Match your MQL5 order to the license codes (
REC-, provider subscription) you’re entitled to. - Support. Respond to your questions and diagnose issues you report.
- Security & abuse prevention. Detect license sharing, rate-limit excess traffic, investigate fraud or chargebacks.
- Product improvement. Aggregated operational stats (active providers, signal rate, EA versions in use) to help us prioritize fixes. No raw individual data is used for this.
- Legal compliance. Respond to lawful government requests and retain accounting records.
4. Legal basis (GDPR & similar)
- Contract performance — running the service for you once you sign in or pay (Art. 6(1)(b) GDPR).
- Legitimate interests — detecting abuse of licenses, rate-limiting, fraud prevention, basic product analytics (Art. 6(1)(f)).
- Consent — optional profile fields you voluntarily provide, marketing emails (if any; none currently) (Art. 6(1)(a)).
- Legal obligation — retaining billing records for tax/accounting (Art. 6(1)(c)).
5. Who we share with
We only share data with processors that help us run the service, and only to the extent necessary.
| Processor | Purpose | Location |
|---|---|---|
| Google Firebase (Auth, Realtime Database, Cloud Functions, Hosting) | Authentication, data storage, API hosting | US (us-central1) |
| MetaQuotes Ltd. (MQL5 Market) | Payment processor for Provider and Pro Receiver purchases; matches order references to licenses | Global (seller order panel accessed from our side) |
| Cloudflare | DNS and DDoS protection for navigatoralgo.com | Global anycast |
| GitHub Pages | Static site hosting | US |
| Telegram | Voluntary support / announcements channel (only if you message us) | Global |
We do not sell your data. We do not share it with advertisers. We do not use it to train any AI or ML system beyond routine security anomaly detection.
We may disclose data in response to a lawful request from a government or court with jurisdiction over us, and we will inform you unless legally prohibited.
6. International transfers
Your data is stored on Firebase servers in the United States. If you are in the EEA, UK, or another jurisdiction with data-export restrictions, transfers are made under Google's Standard Contractual Clauses. MQL5 order data is handled under MetaQuotes’ own privacy terms.
7. Retention
- Account & profile: while your account exists, plus 30 days after deletion for accidental-recovery grace.
- License codes: while active, plus 2 years after revocation for anti-abuse audit.
- Trade signals: 7 days rolling (automatically pruned by the
pruneOldSignalsscheduled job). - Operational logs: 30 days.
- Billing / order records: at least 7 years, as required by tax and accounting law.
- Support messages: 2 years, then deleted.
8. Your rights
Subject to applicable law (including GDPR, UK GDPR, CCPA), you may:
- Access the data we hold about you — request a copy by email.
- Rectify inaccurate data — edit directly on the Profile / Dashboard, or email us.
- Delete your data — use the "Delete account" button on the Profile page, or email us. Certain billing records are retained under legal obligation.
- Restrict / object to processing based on legitimate interests.
- Portability — request a machine-readable export of your provider-level data.
- Withdraw consent for anything processed on consent.
- Lodge a complaint with your local data-protection authority.
Email privacy@navigatoralgo.com to exercise any of these. We respond within 30 days.
9. Security
- All traffic to navigatoralgo.com and Firebase is TLS-encrypted (HTTPS).
- Authentication is via Firebase Authentication; passwords are hashed by Google — we never see them.
- RTDB access is enforced by Firebase Security Rules: providers can only read/write their own data; admins have elevated access and are a closed set.
- Cloud Function secrets (admin bootstrap token and any future payment-processor keys) are stored in Google Secret Manager, not in source.
- All code changes go through pull-request review before deploy. Rules changes are validated in the Firebase Rules Playground.
- Rate limiting (50 requests per 10 seconds per license) protects against abuse and credential stuffing.
No system is 100% secure. If we suffer a breach affecting your personal data, we will notify you and the relevant authority within 72 hours, as required by GDPR Art. 33-34.
10. Cookies & local storage
We use a small number of cookies and local-storage items:
- Firebase Auth session — required for sign-in persistence. Cannot be disabled without breaking the site.
- Dashboard preferences — remember your last-used panel / dismissed banner. Stored in browser localStorage.
We do not use Google Analytics, Facebook Pixel, TikTok Pixel, or any advertising / tracking cookies.
11. Children
Navigator Algo is not directed at children under 18. We do not knowingly collect data from minors. If you believe a minor has signed up, please email privacy@navigatoralgo.com and we will delete the account.
12. Changes to this policy
We may update this policy. Material changes will be posted on the dashboard maintenance banner and, if we have your email, sent via email at least 7 days before taking effect.
13. Contact
Navigator Trading Systems
Sri Lanka
Privacy inquiries: privacy@navigatoralgo.com
General support: support@navigatoralgo.com / @Navigatoralgo_bot