Privacy Policy
1. Who we are
TickerMover operates the website tickermover.com. Questions about this Privacy Policy or requests to exercise your rights should be directed to support@tickermover.com.
2. What we collect
2.1 Information you provide directly
- Email address — for account creation, password reset, and product updates.
- Authentication credentials — password (hashed and salted by Supabase, never visible to us in plain text), or third-party OAuth tokens if you sign in via Google etc.
- Watchlist — the tickers you save.
- Optional profile fields — name, trading experience, primary goal — collected during onboarding to tailor what we show you. You can leave these blank.
- Support correspondence — emails you send to us for assistance.
2.2 Information we collect automatically
- Server logs — IP address, browser user-agent, page URL, timestamp, response code. Used for debugging, abuse prevention, and aggregate analytics. Retained 30–90 days then deleted.
- Cookies and similar technologies — see the dedicated section below. Essential cookies are always used; analytics and advertising cookies are used only if you consent.
- Aggregate usage data — how many users hit which pages, used in anonymous form to improve the product.
2.4 Cookies and similar technologies
We ask for your consent before setting any non-essential cookie, using the banner shown on your first visit. You can change or withdraw your choice at any time via Cookie settings. The categories we use:
| Category | Purpose | Consent |
|---|---|---|
| Essential | Sign-in/session, security, and remembering your cookie choice. The site cannot function without these. | Always on (no consent needed) |
| Analytics | Understand how the site is used so we can improve it. Our default analytics (Plausible) is privacy-friendly and sets no cookies; any cookie-based analytics we add will sit in this category. | Only with your consent |
| Advertising | Measure and target our advertising (for example Google Ads and the Meta/Facebook pixel), including conversion tracking. These set cookies and share limited event data with the ad platform. | Only with your consent |
Advertising and cookie-based analytics tags do not load at all until you opt in. If you reject them, they stay off. You can also block or delete cookies in your browser settings.
2.3 Information we do NOT collect
- Your trading account, brokerage credentials, or trade history. (We are not a broker; we have no way to access these.)
- Bank account or full credit card numbers.
- Physical address (unless required for a future invoiced enterprise plan, with your consent).
- Government identifiers (national insurance number, passport, etc.).
3. Why we collect it (Purpose & Legal Basis)
| What | Why | Legal basis |
|---|---|---|
| Email + password | Authenticate you; recover lost access | Necessary for the contract you have with us |
| Watchlist | Show you stocks you care about | Necessary for the contract |
| Server logs | Detect abuse, fix bugs, plan capacity | Legitimate interest |
| Product update emails | Tell you about new features | Your consent (opt out anytime) |
4. Who we share it with (Data Processors)
We use industry-standard third parties to run the Service. Each acts as a Data Processor on our behalf and is contractually obligated to handle your data only for the agreed purpose:
- Supabase (database + auth) — stores your email, password hash, watchlist. Servers in Asia/Singapore.
- Railway (hosting) — runs our application servers; sees IP addresses in logs.
- Cloudflare (CDN + WAF) — sees IP and request metadata; provides DDoS protection.
- Stripe (payments) — receives payment info directly from you when you upgrade. Card details go directly to Stripe; we never see or store them. Stripe is a PCI-DSS Level 1 certified processor.
- Resend (email delivery) — delivers transactional emails; sees your email and the message body.
- Groq — processes text from public press releases through their language model. We do not send your personal data to Groq, only public earnings text.
- Anthropic / OpenAI (optional, for editorial features) — same as above; only public market commentary, never your personal data.
- Plausible Analytics — privacy-friendly, cookieless site analytics; does not identify you individually.
- Advertising & measurement partners (only if you consent to advertising cookies) — e.g. Google (Google Ads / Google Analytics) and Meta Platforms (the Facebook/Instagram pixel). When enabled, these receive limited event data (such as page views and conversions) and identifiers to measure and target our ads. They act as independent controllers for that data under their own privacy policies. If you do not consent, none of these are loaded.
We do not sell your personal data for money. We do not share your account data with data brokers. If you consent to advertising cookies, limited activity data is shared with our advertising partners (above) so we can measure and target our ads — you can withdraw that consent at any time via Cookie settings, and it will stop.
5. Cross-border transfers
Some of our processors (Cloudflare, Stripe, Resend, Groq, Anthropic) operate servers outside the UK. Where this happens, transfers are made under standard contractual clauses or equivalent safeguards as required by UK GDPR and the Data Protection Act 2018.
6. How long we keep it
- Account data: as long as your account is active, plus 90 days after deletion (to handle disputes).
- Server logs: 30–90 days, then deleted.
- Payment metadata: 7 years (required by HMRC record-keeping rules).
- Email correspondence: 2 years from last reply, then archived.
7. Your rights
Under UK GDPR you have the right to:
- Access — request a copy of the data we hold about you.
- Correction — ask us to fix inaccurate data.
- Erasure — delete your account and associated personal data (subject to retention obligations above for billing records).
- Withdraw consent — opt out of product update emails anytime via the unsubscribe link.
- Complaint — if you are unhappy with how we handle your data you may lodge a complaint with the ICO (ico.org.uk).
To exercise any of these rights, email support@tickermover.com from the address associated with your account. We will respond within 30 days.
8. Security
We use industry-standard practices: HTTPS everywhere, password hashing (bcrypt via Supabase), database row-level security so users can only see their own data, environment-isolated production credentials, and rate limiting on authentication endpoints. No system is bullet-proof; if we discover a personal data breach we will notify affected users and the ICO within the timelines required by UK GDPR.
9. Children
The Service is not intended for users under 18. We do not knowingly collect personal data from children. If you believe a child has provided us their data, contact us and we will delete it.
10. Changes to this Policy
If we materially change this Policy (e.g. expand the categories of data we collect, add new processors, change retention periods), we will notify registered users by email at least 14 days before the change takes effect.
11. Contact
Privacy questions or access requests: support@tickermover.com.