VoraRoute connects to your broker account through an authorization token you grant and can revoke. We never receive your broker password, and we never hold your money.
Please read this policy before using the service. By creating an account you consent to the practices described here. If you do not agree with them, do not use VoraRoute.
VoraRoute is order-routing software operated by MBF Group LLC, a limited liability company registered in Wyoming, with its address at [STREET ADDRESS], Sheridan, WY 82801. In this policy, "VoraRoute", "we", and "us" mean that entity, and "you" means the person who holds a VoraRoute account.
We are a software provider. We are not a broker, a futures commission merchant, a clearing firm, a bank, or a money transmitter. We do not hold client funds, and we do not open, own, or control any brokerage account.
This policy covers the VoraRoute website and application. It does not cover third-party websites you reach through links from ours, or anything you do directly with your broker.
Because VoraRoute connects to your broker only through OAuth authorization, several categories of information never reach us at all. This follows from how the product is built, not from a promise we could quietly change:
If a future version of VoraRoute ever needed to collect anything on this list, we would publish an updated policy and obtain your consent before doing so.
Account details. Your name, email address, a hashed password, and any two-factor settings you enable.
Broker authorization. The access and refresh tokens your broker issues when you authorize VoraRoute, together with the scopes you granted. Section 4 covers these in detail.
Brokerage account metadata. Account identifiers and names, whether an account is live or demo, and its eligibility status — read from your broker after you authorize.
Trading activity. Signals received, whether each was routed, skipped, or failed and why, order identifiers returned by your broker, and the open positions, fills, and realized profit and loss needed to apply the risk limits you set.
Your configuration. Risk limits, active hours, position sizing, notification preferences, and which accounts you have switched on.
Billing. Subscription status, invoice history, and a payment-method reference token from our processor — not the card number itself.
Technical information. IP address, browser and device type, timestamps, and application logs generated when you use the service.
You can browse our public website without providing any of this. Creating an account and connecting a broker requires it; without it we cannot provide the service.
When you connect an account, your broker asks you to sign in on their own page and approve a specific list of permissions. Your broker then issues VoraRoute a token, and that token is what lets us place, modify, and cancel orders in the accounts you enable.
The token is limited to the permissions you approved: submitting and cancelling orders, and reading positions, fills, account balances, and the contract list. It cannot be used to move money, to change your broker account settings, or to read your password.
You can revoke it at any time, from your VoraRoute account or directly from your broker. Revoking stops all routing immediately.
Tokens are encrypted at rest and are used only to communicate with your broker on your behalf. We do not transmit them to any third party, and we do not use them for any purpose other than the routing and risk checks you have configured.
We use the information above to route signals to the accounts you have enabled according to your settings; to apply your risk limits before an order is sent and record when a signal was skipped as a result; to show you the alerts log; to notify you about connection failures, expired authorizations, and limits being reached; to provide support; to bill your subscription; to investigate faults, prevent fraud, and keep the service secure; and to meet legal, tax, and regulatory obligations that apply to us.
We do not sell your data and we do not share it with advertisers. We do not use your trading activity to trade for our own account, and we do not aggregate it into any product sold to third parties.
If you are in the European Union, the European Economic Area, or the United Kingdom, we process your personal data on the following grounds:
We share data only with service providers who need it to run VoraRoute, and only to the extent required. These are [HOSTING PROVIDER] for application hosting and database storage, [PAYMENT PROCESSOR] for subscription billing and card handling, [EMAIL PROVIDER] for account and routing notifications, and [ERROR MONITORING] for detecting and diagnosing faults. We also communicate with your broker, using the token you granted, in order to place orders and read account state.
Your broker and your signal source operate under their own privacy policies, which apply to anything you do directly with them. We do not control those policies.
We may disclose information where we are legally required to — for example in response to a valid subpoena, court order, or regulatory request — or where it is necessary to establish or defend a legal claim. If VoraRoute is acquired or merged, your data may transfer as part of that transaction, and we will notify you before it does.
Your alerts and routing log is retained for 90 days and then deleted. Authorization tokens are kept until you revoke them or close your account. Account details and configuration are kept until you close your account, then deleted within 90 days. Billing and invoice records are retained for [RETENTION PERIOD] to meet tax and accounting obligations, and security and access logs for [RETENTION PERIOD]. Some data may persist briefly in encrypted backups after deletion, and is overwritten on the normal backup cycle.
Closing your VoraRoute account revokes every broker authorization and stops all routing. It does not close your brokerage accounts and does not affect any position that is open at the time — those remain entirely with your broker, and managing them is your responsibility.
All traffic between you, VoraRoute, and your broker is encrypted in transit using TLS. Authorization tokens are encrypted at rest. Passwords are stored only as salted hashes, so we cannot read them. Two-factor authentication is available and strongly recommended, because your VoraRoute account can place orders. Access to production systems is limited to personnel who need it, and is logged.
You are responsible for keeping your VoraRoute credentials confidential and for notifying us promptly if you suspect unauthorized use. No system is perfectly secure, and we cannot guarantee absolute security.
To report a vulnerability, write to security@voraroute.com. We will acknowledge your report and will not pursue action against good-faith security research.
If a breach affects your personal data, we will notify you and, where required, the relevant authorities, without undue delay. The notice will describe what happened, what data was affected, what we are doing about it, and what steps you may want to take.
Depending on where you live you may have some or all of the following rights, and we honour these requests regardless of jurisdiction where we reasonably can: to access the data we hold about you; to export your alerts log and configuration in a portable format, which you can also do yourself as CSV at any time; to have inaccurate details corrected; to delete your account and data, subject to records we must keep for tax or legal reasons; to revoke a broker authorization without closing your account; to object to or restrict processing; and to withdraw consent where processing is based on it.
Write to privacy@voraroute.com and we will respond within [RESPONSE PERIOD] days. We may need to verify your identity first. We do not charge for these requests, and we will not restrict or degrade your service for making one.
If you are in the EU, EEA, or UK and are not satisfied with our response, you may lodge a complaint with your local supervisory authority.
If you are a California resident, the California Consumer Privacy Act gives you additional rights:
To exercise these rights write to privacy@voraroute.com. We will verify your identity before acting on the request. An authorized agent may submit a request on your behalf with written permission.
We use cookies that are necessary for the service to function: keeping you signed in, remembering your session, and protecting against cross-site request forgery. We do not use advertising cookies or third-party tracking pixels.
[IF ANALYTICS ARE USED, DESCRIBE THEM HERE — provider, what is measured, whether a consent banner is shown, and how to opt out.]
You can control cookies through your browser settings, though disabling the necessary ones will prevent you from signing in.
VoraRoute is operated from the United States and our infrastructure is hosted in [REGION]. If you use the service from another country, your data will be transferred to and processed in the United States, which may not offer the same data-protection standards as your home country. Where the law requires a transfer mechanism, such as Standard Contractual Clauses, we rely on [MECHANISM].
VoraRoute is for adults. You must be at least 18 years old, and old enough to hold a futures brokerage account in your jurisdiction, to use the service. We do not knowingly collect data from anyone under 18, and if we learn that we have, we will delete it promptly.
If we change this policy in a way that materially affects how we handle your data, we will email you at the address on your account and post the updated version here before the change takes effect. The version number and date at the top of this page always reflect the current text. We encourage you to review it periodically.
Privacy questions and data requests go to privacy@voraroute.com. Security reports go to security@voraroute.com. Everything else goes to support@voraroute.com.
MBF Group LLC
[STREET ADDRESS], Sheridan, WY 82801
Wyoming, United States