Privacy Policy
Privacy Policy
- Effective Date
- 2026-09-09
- Last Updated
- 2026-09-09
- Version
- v1.3
This Privacy Policy explains how Camovia Tray ("the App") collects, uses, stores, and protects your personal information, and the rights you have. We follow data minimization by design - we only collect the minimum data necessary for licensing and software updates, and do not collect your market data, trading data, or browsing habits.
1. Data Controller
This App is developed and operated by the Camovia Tray developer, who is the data controller of your personal information (under GDPR Article 4(7) and CCPA definitions).
- Controller: Camovia Tray Developer
- Contact: [email protected]
Under GDPR Article 27(2), the data processed by this App is ordinary personal data (email, device fingerprint hash, etc.), does not involve special categories under Article 9, and is not large-scale processing, so it is exempt from appointing an EU representative. If you are in the EU, you can contact us directly via the email above.
2. Scope
This Policy applies when you install and use the desktop client of this App, and when you access this website (www.camovia.com). The App reads market data and open positions from your locally running MetaTrader 4/5 terminal and provides actions on your positions (for example, closing them); all trading operations are submitted by the MetaTrader terminal to your own broker account. The App itself does not upload your market data or position data; trade instructions are sent directly by the MetaTrader terminal to your broker. In MT4 mode, the App installs and attaches a bridge component (CamoviaBridge EA) in your local MetaTrader 4 terminal; this component runs only within your local terminal, only performs actions you initiate in the App, and does not transmit any market, position, or trading data to the Developer or any third party.
3. Information We Collect
To provide license activation, device binding, referral rewards, and software update features, we collect the following information:
3.1 You Actively Provide
- Email address - for registration, license key recovery, and remote unbind verification.
- License key - 4 segments of 6 characters, your account credential.
- Referral code (optional) - a 6-character referrer code you may enter at registration to earn referral rewards.
- Redemption code (optional) - a card key used to extend duration.
3.2 Automatically Generated
- Device fingerprint hash -
SHA256(MachineGuid + SystemUUID + SystemSerialNumber), used for device binding and account management. We only transmit and store this hash, not the raw hardware identifiers. - Device name and model - computer name (e.g., DESKTOP-XXX) and motherboard/system model, submitted with activation, used to identify bound devices in your device management list.
- Your exclusive referral code - a 6-character code auto-generated when your account is created.
- Client version number - used for version validation to prevent incompatible or deprecated versions.
3.3 Generated During Operation
- IP address - when you communicate with our servers, Cloudflare edge nodes log the access IP for service operation and security audits.
- Account feature status - records of feature usage states (e.g., trial granted, referral reward triggered) for account management and service operation. Only states and counts are stored, not content.
- Timestamps - account creation, activation, expiry, and device binding times.
4. Purposes and Legal Basis
Under GDPR Article 6, our processing of personal data is based on the following legal grounds:
Performance of a License Contract (GDPR Article 6(1)(b))
Email, device fingerprint hash, license key, and bound device list are used for license activation, renewal, heartbeat verification, and device binding management.
Legitimate Interests (GDPR Article 6(1)(f))
IP logs and account feature status are used for account management, rate-limiting/abuse prevention, and service security/stability. This legitimate interest does not override your rights and freedoms.
Consent (GDPR Article 6(1)(a))
The referral code is optional; entering a referrer code means you consent to rewards being granted accordingly. You may choose not to enter it.
Legal Obligation (GDPR Article 6(1)(c))
Data required to be retained by law is kept for the duration and scope required by law.
5. Third-Party Processors and Recipients
We entrust the following third parties as data processors to provide services. Relevant data is shared only as necessary:
-
Cloudflare, Inc. (USA) - Backend and Storage
Provides API backend (Cloudflare Workers) and data storage (Cloudflare KV), records access logs. The website's anonymous, aggregate traffic analytics are also provided by Cloudflare Web Analytics (cookieless, no personal information collected). See Cloudflare Privacy Policy.
-
Resend, Inc. (USA) - Email Delivery
Only sends license key and remote unbind verification code emails. Email content contains only the above credentials. See Resend Privacy Policy.
-
Microsoft (USA) - Store and In-App Purchase (if applicable)
If you obtain the App via Microsoft Store or purchase in-app, the store and payment services are provided by Microsoft. See Microsoft Privacy Statement.
-
Multi-source Time Services - System Time Calibration
To calibrate system time, the client sends time-only HEAD requests to apple.com, cloudflare.com, and baidu.com, with no identity information.
MetaTrader 4/5 is provided by MetaQuotes Software Corp. and is a third-party terminal you install locally. This App reads its local market data and open positions and may issue operations on your positions (for example, closing them); it does not transmit any information to MetaQuotes, and has no affiliation or authorization relationship with it (see the "Trademarks and Affiliation" section of the EULA).
6. International Data Transfers
Your data is processed by Cloudflare and Resend, located in the United States. If you are outside the United States, your data will be transferred cross-border to the United States.
We ensure cross-border transfer compliance through the following mechanisms:
- GDPR Standard Contractual Clauses (SCC): Our data processing relationships with Cloudflare and Resend are based on Standard Contractual Clauses adopted by the European Commission.
- Adequacy Decision: If the data recipient participates in an adequacy framework recognized by the European Commission (e.g., EU-US Data Privacy Framework), we rely on that decision for transfers.
- Data Processing Agreement (DPA): We establish委托 processing relationships with each processor in writing, limiting processing purposes and security obligations.
For CCPA/CPRA purposes, we do not sell your personal information, do not share it for cross-context behavioral advertising, and do not "sell or share" personal information for money or other consideration.
If your jurisdiction's laws impose specific requirements on cross-border transfer of personal information (e.g., security assessment, SCC filing, or separate consent), please be aware of the above cross-border transfer arrangements before using the App; for questions, contact us via Section 16.
7. Data Retention
- Account data (email, key, bound devices, referral code): retained during the account's validity; deleted or anonymized within 30 days after you request deletion.
- Account feature status: auto-expires via Cloudflare KV TTL, retained for days to tens of days.
- Access logs (including IP): handled per Cloudflare edge log retention policy, for service operation, security audits, and abuse prevention.
- Legal obligations: if a longer retention period is required by law, deleted after that period expires.
8. Data Storage and Security
- Cloud: License data is stored in Cloudflare KV; client-server communication is encrypted via HTTPS/TLS; license payloads are RSA-signed, and the client verifies signatures to ensure integrity and prevent tampering.
- Local config: Your settings (symbols, colors, hotkeys, icons, etc.) are encrypted with AES-256-GCM and stored in the local AppData directory as
config.dat; the key is derived from app constants and your MachineGuid - copying to another computer cannot be decrypted. - Local credentials: The license token is stored in
license.dat, also encrypted. - Crash logs: If the App crashes unexpectedly, crash info may be written to the local
panic.logfor diagnosis only, not auto-uploaded.
We do not own, access, or share your market data, position data, and configuration data - these always remain on your computer.
9. Your Rights (GDPR · EU/EEA Users)
If you are in the EU or European Economic Area (EEA), under GDPR you have the following rights:
- Access (Article 15) - know whether we process your data and its contents.
- Rectification (Article 16) - correct inaccurate data.
- Erasure (Article 17, "right to be forgotten") - request deletion of your data in specific circumstances. For records necessary to prevent abuse, fraud, or violations, we may retain or anonymize them under GDPR Article 17(3) (no longer identifying you) to prevent future violations.
- Restriction (Article 18) - request restriction of processing in specific circumstances.
- Data portability (Article 20) - receive your data in a structured format and transfer it to another controller.
- Objection (Article 21) - object to processing based on legitimate interests.
- Automated decision-making (Article 22) - not subject to decisions based solely on automated processing. This App does not make such decisions.
- Withdraw consent - withdraw your consent for referral code processing at any time (without affecting prior lawful processing).
- Complaint - lodge a complaint with your member state's data protection authority.
To exercise your rights, contact us via Section 16. We will respond within 30 days (extended if necessary, with reasons).
10. Your Rights (CCPA/CPRA · California Users)
If you are a California resident, under the California Consumer Privacy Act and California Privacy Rights Act (CPRA), you have the following rights:
- Know - the categories of personal information we collect, purposes, sources, retention periods, and recipients.
- Delete - request deletion of your personal information (subject to exceptions).
- Correct - request correction of inaccurate personal information.
- Opt-out of sale/sharing - this App does not sell or share your personal information for cross-context behavioral advertising, so no opt-out is needed.
- Limit use of sensitive personal information (CPRA) - this App does not collect sensitive personal information as defined by CCPA.
- Non-discrimination - exercising these rights will not result in discrimination or denial of service.
Submit requests via Section 16. To verify identity, we may ask you to confirm via your registered email.
11. Children's Privacy
This App is not directed at children under 13, and we do not knowingly collect children's information. If you are a guardian and believe we have collected a child's information by mistake, please notify us via Section 16, and we will delete it promptly.
12. Local Storage and Cookies
- This website does not use tracking cookies and does not deploy advertising tracking. To measure aggregate page visits, this website uses Cloudflare Web Analytics, a cookieless analytics tool that does not collect personal information and does not track you across sites.
- The client stores
config.dat(encrypted config),license.dat(encrypted credentials), andpanic.log(crash log) locally; you can manually delete residues after uninstalling.
13. Automatic Updates
To ensure security and maintain functionality, the App automatically checks for updates when online (at startup and during operation). Security patches and resource updates are applied automatically in the background; major updates to the main program are downloaded and take effect on your next launch or restart. All update content is verified by digital signature and only replaces the App's own signed files, without installing other software. If you obtained the App via Microsoft Store, updates are managed by the store mechanism.
14. Data Breach Response
In the event of a personal data breach likely to endanger your rights and freedoms, we will notify the relevant supervisory authority within 72 hours under GDPR Article 33, and notify affected users if there is high risk.
15. Policy Changes
We reserve the right to modify this Policy at any time. Material changes will be announced on this website and within the App; continued use of the App after changes constitutes acceptance of the revised Policy. You can check the latest version and effective date on this page at any time.
16. Contact Us
If you have any questions or requests regarding this Privacy Policy or your personal information, please contact us via:
Email: [email protected]
Please mark the subject as "Privacy" for priority handling.
If you disagree with our processing and are not satisfied with our response, you have the right to lodge a complaint with the data protection authority in your jurisdiction.