Privacy Policy
Last updated: January 15, 2025
Effective Date: January 15, 2025
At Trader Map, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our portfolio tracking platform and services. Please read this policy carefully to understand our practices regarding your personal data and how we will treat it.
Table of Contents
1. Information We Collect
1.1 Information You Provide to Us
- Account Information: Name, email address, password, and profile photo when you create an account
- Financial Information: Portfolio holdings, transaction history, investment amounts, and stock symbols you track
- Payment Information: Credit card details, billing address, and payment history (processed securely through Stripe)
- Profile Data: User preferences, notification settings, and customization choices
- Communications: Messages, feedback, and correspondence when you contact our support team
1.2 Information We Collect Automatically
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages visited, features used, time spent on platform, click patterns
- Log Data: Access times, error logs, and system activity
- Location Data: General geographic location based on IP address
- Performance Data: App crashes, load times, and technical diagnostics
1.3 Information from Third Parties
- Stock Market Data Providers: Real-time quotes, historical prices, and company fundamentals from EODHD API
- Authentication Services: Information from OAuth providers (Google, etc.) if you choose social login
- Payment Processors: Transaction confirmations and payment status from Stripe
2. How We Use Your Information
We use your information for the following purposes:
- Service Provision: To provide, operate, and maintain our portfolio tracking platform
- Account Management: To create and manage your user account
- Portfolio Tracking: To calculate performance metrics, track holdings, and generate analytics
- Payment Processing: To process subscription payments and manage billing
- Communications: To send service updates, notifications, and respond to your inquiries
- Personalization: To customize your experience and recommend relevant features
- Security: To detect fraud, prevent abuse, and protect our users and platform
- Analytics: To understand usage patterns and improve our services
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
- Product Development: To develop new features and enhance existing functionality
3. Information Sharing and Disclosure
We do NOT sell your personal information to third parties.
We may share your information in the following circumstances:
- Service Providers: With third-party vendors who perform services on our behalf (hosting, analytics, payment processing, customer support)
- Payment Processors: With Stripe to process subscription payments securely
- Data Providers: With EODHD for stock market data (we only share necessary identifiers, not personal information)
- Legal Requirements: When required by law, court order, or government request
- Business Transfers: In connection with a merger, acquisition, or sale of assets (users will be notified)
- With Your Consent: When you explicitly authorize us to share information
- Aggregated Data: We may share anonymized, aggregated data that cannot identify you
4. Data Security
We implement industry-standard security measures to protect your personal information:
- Encryption: All data transmitted between your device and our servers is encrypted using TLS/SSL
- Secure Storage: Data at rest is encrypted using AES-256 encryption
- Authentication: Passwords are hashed using bcrypt with secure salt
- Access Controls: Strict internal access controls and authentication requirements
- Infrastructure Security: Hosted on Vercel with enterprise-grade security and DDoS protection
- Database Security: PostgreSQL databases hosted on Supabase with row-level security policies
- Payment Security: PCI-DSS compliant payment processing through Stripe (we never store credit card details)
- Regular Audits: Periodic security assessments and vulnerability scanning
- Monitoring: 24/7 system monitoring and incident response protocols
Important: While we implement robust security measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.
5. Data Retention
We retain your personal information for as long as necessary to:
- Provide you with our services
- Comply with legal obligations (tax, accounting, regulatory requirements)
- Resolve disputes and enforce our agreements
- Maintain backup and business continuity
Retention Periods:
- Active Accounts: Data retained while your account is active
- Deleted Accounts: Most data deleted within 30 days, some retained for up to 7 years for legal/tax purposes
- Transaction Records: Retained for 7 years for tax and financial compliance
- Log Data: Retained for 90 days for security and debugging
- Marketing Data: Retained until you unsubscribe or for 3 years of inactivity
6. Your Privacy Rights
6.1 Rights for All Users
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and data
- Export: Download your portfolio data in CSV format
- Object: Object to certain data processing activities
- Opt-Out: Unsubscribe from marketing communications
6.2 Additional Rights for EU/EEA Users (GDPR)
- Data Portability: Receive your data in a machine-readable format
- Restrict Processing: Request limitation of data processing
- Withdraw Consent: Withdraw consent at any time (where processing is based on consent)
- Lodge Complaint: File a complaint with your local data protection authority
- Automated Decisions: Not be subject to decisions based solely on automated processing
6.3 Additional Rights for California Residents (CCPA)
- Know: Know what personal information is collected, used, shared, or sold
- Delete: Request deletion of personal information
- Opt-Out: Opt out of sale of personal information (we do not sell your data)
- Non-Discrimination: Not be discriminated against for exercising your rights
6.4 How to Exercise Your Rights
To exercise any of these rights, contact us at privacy@tradermap.com. We will respond within 30 days (or as required by applicable law).
8. Third-Party Services
Our platform integrates with the following third-party services:
- Supabase: Authentication and database services (Privacy Policy)
- Stripe: Payment processing (Privacy Policy)
- EODHD: Stock market data (Privacy Policy)
- Vercel: Hosting and infrastructure (Privacy Policy)
- Upstash: Redis caching and rate limiting (Privacy Policy)
These services have their own privacy policies. We encourage you to review them.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.
When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses approved by the European Commission
- Privacy Shield Framework (where applicable)
- Adequacy decisions by relevant authorities
- Other legally approved transfer mechanisms
10. Children's Privacy
Trader Map is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@tradermap.com. We will delete such information promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make changes:
- We will update the "Last updated" date at the top of this policy
- For material changes, we will notify you via email or in-app notification
- We will provide a 30-day notice period before changes take effect
- Continued use of our services after changes constitutes acceptance of the updated policy
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Trader Map Privacy Team
Email: privacy@tradermap.com
Support: support@tradermap.com
Response Time: We aim to respond to all privacy inquiries within 30 days
EU Representative (GDPR)
For EU data protection inquiries, contact our EU representative at eu-privacy@tradermap.com
This Privacy Policy was last updated on January 15, 2025. By using Trader Map, you acknowledge that you have read and understood this Privacy Policy.