Privacy policy
Privacy Policy
What is stored, why, and who can see it. Merc keeps the minimum needed to execute and audit trades.
Last updated 30 July 2026
Account data
The identity you sign in with — a Google account id and email, a Discord id and username, or an email address with a hashed password and an authenticator secret — plus your MEXC UID, subscription and trial status, Getting Started path, preferences such as your day boundary, the sources you Activate, your risk rules, and your invite relationships and Ascension volume.
Signal data
Raw messages from approved channels, parse results, and validation decisions — retained so any execution or refusal can be explained. For Copy traders, the trades they publish through their publish key are read from MEXC and turned into tickets; followers see the pair, side, and levels of a ticket, never the leader's balance.
Execution data
Orders planned and placed, fills, stops and targets, realized PnL, and lifecycle events tied to your account. Merc also reads your Futures balance and equity through your key to size trades, check the 100 USDT first-Activate floor, and show your balance on the desk.
Credentials
Exchange API keys, whether you paste them or mint them through Connect my MEXC, are stored encrypted and used only to place and manage your orders and read your balance. Secrets are never shown back after you save them. Passwords are stored hashed. Authenticator secrets are stored encrypted and decrypted only to check the code you enter.
What partners and Copy traders see
Signal providers get a partner desk with aggregate, source-level numbers only: follower counts, ticket outcome counts, and summed follower PnL for their sources. Individual identities, positions, and results are never exposed to them. Catalog reputation is built from follower outcomes in aggregate.
Third parties / processors
MEXC receives your orders and, when you use Connect my MEXC, mints your key through its broker program; Merc is a MEXC broker and receives API broker commission on your volume. Subscription payments in USDT-TRC20 or QRPH are processed by KwikPay; Merc stores order amounts and status, never card or wallet credentials. Sign-in emails, verification codes, and password resets are sent through Resend. Product analytics are processed by PostHog (US cloud) so we can understand usage and onboarding — identified by internal user id, with session recording off, not sold for advertising. Sign-in and MEXC key connect also record request IP and user-agent (the last 50 per account) for operator review of account-transfer requests; they are not used to automatically merge accounts.
Notifications and sharing
If you turn on trade notifications, your browser's push endpoint is stored so Merc can send them; turn them off in Preferences to remove it (blocking them in the browser alone stops delivery but leaves the record). PnL share cards always show the pair, side, leverage, and result; username, position size, USDT amount, prices, and rank appear only if you toggle them on. Whoever you share a card with can see everything on it.
Your controls
You can Deactivate sources, rotate or revoke your key (delete it on MEXC and Reconnect), hide your Trades history from the desk with Reset all trades in Settings, turn notifications off, and request deletion of your account at any time.