Privacy Policy
This policy explains what personal data Norviq processes, why, who we share it with, and the rights you have under the GDPR.
Last updated: 23 August 2026
1. Data controller
Norviq, operator of norviqtrade.com, is the data controller for the personal data described in this policy.
Controller identity: NorviqTrade (enkeltmandsvirksomhed / sole proprietorship), CVR no. 46706218, VAT DK46706218, Gunderupvej 16, 9260 Gistrup, Denmark. Privacy contact: support@norviqtrade.com.
Norviq has not appointed a Data Protection Officer. We have assessed the criteria in Article 37 GDPR: Norviq is not a public authority, its core activity is not large-scale systematic monitoring of individuals, and it does not process special categories of data or criminal conviction data on a large scale. On that basis a DPO is not mandatory. Privacy questions go to support@norviqtrade.com, which is monitored by the business owner.
2. Scope
This policy covers personal data we process when you visit norviqtrade.com, create a Norviq account, and use the journal, analytics, broker synchronisation, growth tools, community, leaderboards and subscriptions.
3. Account and identity data
- Email address and, for email sign-up, a password stored hashed by our authentication provider.
- Where you sign in with Google: the identity information Google returns to the authentication provider (such as email address, name and profile picture) and the linked provider identity.
- Account identifiers, sign-up and sign-in timestamps and email confirmation state.
- Role assignment (standard user, staff, owner).
4. Profile and community data
- Username, display name, avatar and cover images, bio, country, trading style, broker, prop firm, years of experience, website, X/Twitter handle and Discord handle — all optional except the username.
- Visibility preferences: public activity, leaderboard visibility, country display.
- Posts, comments, reactions, poll votes, follows, karma and engagement counts.
- Notifications and activity feed entries generated by your use of the platform.
- Moderation state held in a separate, staff-only table, and staff actions recorded in an audit log.
5. Trading and journal data
- Trading accounts you create: name, broker, account login and server, account type, currency, balance and equity snapshots, verification status, captured starting balance and any challenge/funded-account rules you configure.
- Trades: instrument, direction, entry and exit prices, size, stop loss and take profit, commission, swap, profit and loss, open and close timestamps, and (for synced trades) the broker deal identifier and verification flag.
- Journal content you add: notes, tags and screenshots you upload.
- Growth data: goals, habits and habit logs, challenges, progress and achievements.
- Leaderboard snapshots and derived ranking statistics.
6. Broker connection data
If you connect a MetaTrader 4 or MetaTrader 5 account we store the provider, the broker server, the account login, the synchronisation state and error messages, an identifier for the synchronisation account created at MetaApi, and the broker credentials you supply.
Credentials are encrypted with AES-256-GCM before being stored and are never returned to the browser. They are used only to operate the synchronisation. We ask you to supply read-only (investor) credentials.
7. Subscription and payment data
We store your plan tier, subscription status, current period end and the Stripe customer and subscription identifiers. Card details and full billing details are collected and processed by Stripe on its own systems; Norviq does not receive or store card numbers.
8. Technical and usage data
- Standard server and infrastructure logs generated by our hosting and database providers, which can include IP address, timestamps, user agent and requested paths.
- Client-side error reports (technical error details and the page where they occurred) sent to our development platform so we can fix faults.
- Interface preferences stored locally in your browser, such as dashboard tile layout and filters.
We do not operate any third-party web analytics, advertising, behavioural tracking or profiling product. There is no Google Analytics, Google Tag Manager, Meta Pixel, PostHog, Mixpanel, Hotjar, Plausible or comparable tool in the application, and we do not plan to add one.
Web fonts are served from Norviq's own domain. Loading a page does not send a request to Google Fonts or any other font CDN.
9. Purposes and legal bases
- Providing the Service — accounts, journal, analytics, growth tools, community, notifications. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Broker synchronisation — connecting to and reading data from your trading account. Legal basis: contract, at your request.
- Subscriptions and payments — billing, plan entitlement, invoicing records. Legal basis: contract and legal obligation (accounting law).
- Public profile, leaderboards and community posting — displaying what you choose to publish. Legal basis: contract, plus your choices in the visibility settings.
- Security, abuse prevention, moderation and audit logging. Legal basis: legitimate interests (Art. 6(1)(f)) in keeping the platform safe and statistics trustworthy.
- Aggregated platform statistics shown on our homepage — number of traders, number of trades journaled, combined verified volume/profit and loss, and number of countries. These are computed from our own database, are aggregate totals only, and expose no individual trader name, account balance, P&L, trade or broker. They are product statistics, not visitor analytics, and they are never used for advertising, profiling or third-party tracking. Legal basis: legitimate interests.
- Service and security emails (confirmation, password reset). Legal basis: contract.
We do not carry out automated decision-making with legal or similarly significant effects, and we do not sell personal data.
10. Processors and recipients
- Supabase (via Lovable Cloud) — database, authentication, file storage and transactional authentication emails.
- Lovable — application hosting (served from Cloudflare's edge network), deployment and client error reporting.
- Stripe — payment processing and subscription management, including its hosted checkout and customer billing portal. Stripe acts as an independent controller for parts of this processing.
- MetaApi (Agilium Trade) — MetaTrader account synchronisation; receives the broker credentials and account details needed to connect, and returns account and trade data.
- Google — only if you choose to sign in with Google, in which case Google processes your identity data for that sign-in. Fonts are self-hosted, so no request is made to Google Fonts.
Our Discord server is operated by Discord and is outside this Service; anything you share there is governed by Discord's own policies.
We may also disclose data where legally required, or to establish, exercise or defend legal claims.
Sub-processors. The complete list of sub-processors we use today is the list above: Supabase (database, authentication, file storage, provided through Lovable Cloud), Lovable and Cloudflare (application hosting and edge delivery), Stripe (payments, billing and tax calculation), MetaApi / Agilium Trade (MetaTrader 4 and 5 connectivity), our managed email-delivery provider (outgoing transactional and account emails, sent from noreply@notify.norviqtrade.com) and Google (only if you sign in with Google). We will update this list before adding a new sub-processor. Each of these providers publishes a standard data processing agreement that applies to our use of the service. [TO BE COMPLETED: written confirmation that each provider's DPA has been accepted or countersigned on the Norviq account]
11. Where data is processed and international transfers
Norviq is a global platform and our providers operate globally. We only state what we can actually verify from our own configuration:
- Database, authentication and file storage (Supabase via Lovable Cloud) — hosted in a single region inside the EU: AWS
eu-west-1(Ireland). Your journal, trades, account data and community content are stored there. - Application hosting (Lovable / Cloudflare edge) — requests are served from the edge location nearest to you, worldwide. Processing is therefore not limited to the EU/EEA.
- Stripe — a global payment processor; payment and billing data is processed in and outside the EU/EEA, including in the United States.
- MetaApi (Agilium Trade) — our MetaTrader synchronisation accounts are provisioned in MetaApi's
new-yorkregion (United States), so broker credentials and trade history pass through infrastructure in the United States. - Managed email delivery — sending account and transactional emails; processed in and outside the EU/EEA, including in the United States.
- Google — only for Google sign-in; a global service.
We do not claim that all data is stored in the EU. Your core account and trading data sits in the EU, but hosting, payments, email and MetaTrader connectivity involve processing outside the EU/EEA. Those transfers rely on the safeguards each provider offers, which are typically the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. [LEGAL REVIEW REQUIRED: confirm the transfer mechanism relied on by each provider before public launch]
12. Data retention
We keep the data you own for as long as your account exists, because the Service is built around a continuous performance history. When you delete your account, that data is deleted through the deletion flow described in the next section. Beyond that, the periods below are the ones we actually apply or that are imposed on us by law.
- Account, journal, trades, analytics, community content — kept until you delete the item, the trading account, or your Norviq account. Deletion runs immediately and is permanent.
- Trading account deletion — immediately and permanently deletes its broker connection, baseline ledger, leaderboard snapshots and all of its trades, including verified ones.
- Broker credentials — held encrypted only while the connection exists, and deleted with the connection.
- Payment, invoice and accounting records — retained by Stripe and by us for 5 years from the end of the financial year, as required by the Danish Bookkeeping Act (bogføringsloven).
- Moderation and abuse records — kept while needed to enforce the community rules and to defend legal claims, and reviewed at least yearly.
- Database backups — held by our hosting provider on a short rolling window and overwritten automatically; deleted data disappears from backups when that window rolls over.
- Infrastructure, security and error logs — held by our hosting, database and error-reporting providers under their own default log-retention windows. We do not control those windows and do not use these logs to rebuild a deleted account.
No automated purge job runs inside the product itself: deletion is event-driven and happens when you delete something. [TO BE COMPLETED: the exact backup window and provider log-retention periods, to be confirmed with each provider and stated here]
13. Account deletion
You can delete your entire Norviq account yourself, from Settings → Your data. The deletion runs immediately and covers:
- Your login, profile, username, avatar and cover images.
- All trading accounts, trades, journal notes, tags and uploaded screenshots, together with baseline ledger entries and leaderboard snapshots.
- Broker connections: the synchronisation account is undeployed and deleted at MetaApi and the encrypted credentials are destroyed.
- All of your community data — posts, comments, reactions, poll votes, follows and bookmarks are deleted outright. We do not keep anonymised "deleted user" placeholders in their place.
- Goals, habits, challenges, achievements, notifications and activity entries.
- Files stored in our storage buckets.
- Any active subscription is cancelled at Stripe so no further charges are made. Deletion does not refund an already-paid period; see the Terms.
Your username is released on deletion and may later be registered by someone else. We do not keep a record of deleted accounts for anti-abuse purposes.
You can also delete individual trading accounts and individual pieces of community content at any time. Backups held by our providers and records Stripe must keep for accounting purposes may persist for a limited period after erasure.
14. Access and data export
You can download a copy of your data yourself, from Settings → Your data. The export is a structured, machine-readable JSON file covering your profile, trading accounts, trades, journal entries, goals, habits, challenges, achievements, community content, notifications, preferences and subscription identifiers, plus a separate CSV of your trades.
For security, the export deliberately excludes secrets: it contains no password, no session or authentication token and no broker credentials.
15. Your rights
Under the GDPR you have the right to:
- Access your personal data and receive a copy.
- Have inaccurate data corrected — most profile and journal data is editable in the Service.
- Have your data erased.
- Restrict or object to processing based on legitimate interests.
- Data portability.
- Withdraw any consent you have given, without affecting prior processing.
We respond to requests within one month, as required by the GDPR. We may need to verify your identity first.
16. Security
- All traffic is served over HTTPS.
- Database access is protected by row-level security policies scoped to the signed-in user.
- Broker credentials are encrypted with AES-256-GCM and never exposed to the browser.
- Privileged operations run server-side; administrative actions are logged.
- Payment card data is handled solely by Stripe.
No system is perfectly secure. Please use a strong, unique password and only ever supply read-only broker credentials.
17. Children
The Service is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a minor has created an account, contact us and we will remove it.
18. Complaints
If you believe we have handled your data unlawfully you can lodge a complaint with your local supervisory authority. In Denmark this is Datatilsynet (the Danish Data Protection Agency), Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk. We would appreciate the chance to address your concern first.
19. Changes to this policy
We update this policy as the Service evolves. The date at the top shows the current version, and we will notify you of material changes through the Service or by email.
20. Contact
Privacy requests and any other question about this policy: support@norviqtrade.com. The same address is used for support and legal notices. General contact details are on the Contact page.