Privacy Policy
Draft last updated June 17, 2026 · Posted July 4, 2026
This policy describes what Marsad Markets collects when you use the Marsad Markets, how we use it, who processes it, and the rights you have. It reflects what the application actually collects. The Service is available globally, so this policy covers residents of the European Economic Area (EEA), the United Kingdom, the United States, and elsewhere — your specific rights depend on where you live (see “Your rights”).
1. Who is responsible for your data (controller)
Marsad Markets is the data controller for the personal data described here and decides how and why it is processed. The infrastructure providers listed below act as our processors (sub-processors), handling data only on our instructions. Contact for any privacy matter: support@marsadmarkets.com.
2. Information we collect
We collect only what the Service needs to run your account:
- Account details: your email address, a password (stored hashed by our authentication provider — we never receive or store your plaintext password), and your display name. Optionally a username and avatar URL if you add them.
- Preferences: your chosen account size (a number you set for position-sizing math) and your theme preference.
- Content you create: watchlists (ticker symbols), portfolio entries you type in yourself (ticker, share count, optional cost basis — a self-entered tracking list, not a connection to any brokerage or bank), and price/criteria alerts you configure.
- Agreement record: the version and timestamp of the Terms, Privacy Policy, and Disclaimer you accept at registration.
- Technical logs: standard server logs at our hosting providers, which include your IP address, browser/user-agent, and request metadata, used for security and reliability.
We do not ask for or store financial-account credentials, government IDs, or payment-card data (the Service is free; no payment data is collected). We do not knowingly collect special-category data.
3. How we use it
- to create and operate your account and authenticate you;
- to provide and personalize in-app features you configure (watchlists, portfolio tracking, alerts, position sizing);
- to send essential service email (e.g. signup confirmation, security);
- to secure, debug, prevent abuse of, and improve the Service.
We do not sell your personal information, we do not “share” it for cross-context behavioral advertising, and we do not use it for third-party advertising or profiling.
4. Our lawful bases (GDPR / UK GDPR Art. 6)
For users in the EEA/UK, we rely on these lawful bases, by purpose:
- Performance of a contract — to create and run the account and provide the features you sign up for (account, watchlists, portfolio tracking, alerts).
- Legitimate interests — to keep the Service secure, prevent abuse, debug, and maintain essential logs; balanced so as not to override your rights and freedoms.
- Legal obligation — where we must retain or disclose data to comply with applicable law.
- Consent — we do not currently carry out any consent-based processing (no analytics, marketing, or tracking). If we ever add optional processing, we will request your consent first and you may withdraw it at any time.
5. Who processes your data (sub-processors)
We share personal data only with the infrastructure providers that run the Service:
- Supabase — database, authentication, and transactional email. Stores the account and content data above.
- Vercel — frontend hosting and content delivery. Processes request logs (incl. IP).
- Render — backend API hosting. Processes request logs (incl. IP).
Market-data and filings providers do not receive your personal information. When the Service fetches public market data or filings (for example, price, fundamentals, or SEC data), those requests carry no user identifiers — they ask only about securities, never about you.
Placeholder — for legal counsel to draft
Operational, not just text: a GDPR Art. 28 Data Processing Agreement (DPA) must be in place with each of Supabase, Vercel, and Render (each publishes one). Execute/confirm these — see the operational items in docs/legal/LEGAL_REVIEW_CHECKLIST.md.6. International data transfers
Our processors operate infrastructure in the United States, so if you are in the EEA or UK your personal data is transferred to and processed in the United States. For those transfers we rely on the processors’ appropriate safeguards — Standard Contractual Clauses (SCCs) (and the UK Addendum) and any applicable adequacy framework — incorporated in their data-processing terms.
Placeholder — for legal counsel to draft
Operational, not just text: confirm the specific transfer mechanism each processor offers (SCCs / UK Addendum / Data Privacy Framework participation) and that it is incorporated in the executed DPA. This is a contract to verify, not a statement to assert blindly.7. Cookies & tracking
We use only essential cookies: an authentication/session cookie (so you stay logged in) and a small preference cookie for your theme. The application contains no third-party analytics, advertising, or tracking technologies. Because we use only strictly-necessary cookies, no cookie-consent banner is required (essential cookies are exempt under the ePrivacy rules).
Placeholder — for legal counsel to draft
If analytics or any non-essential cookie/script is added later, a compliant prior opt-in consent mechanism (not just a notice) becomes required under ePrivacy/GDPR — do not ship any such tool without it.8. Retention
We keep account and content data for as long as your account is active. When you delete your account (or ask us to), we delete or de-identify your personal data within a short period — typically up to 30 days — except where we must retain limited records to meet a legal obligation or for security/abuse-prevention. Technical server logs are retained for a limited period (typically up to 90 days) by our hosting providers.
Placeholder — for legal counsel to draft
Confirm and document the exact retention periods (post-deletion grace and log retention) as an operational decision; the figures above are reasonable defaults to finalize.9. Security
We use reasonable technical and organizational measures, including encryption in transit, hashed passwords, scoped access keys, and row-level access controls. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
10. Your rights (depend on where you live)
You can exercise any of the rights below via support@marsadmarkets.com. We will respond within the time required by your local law (for the EEA/UK, generally within one month). We will not discriminate against you for exercising your rights.
EEA & UK (GDPR / UK GDPR). You have the right to:
- access a copy of your personal data;
- rectify inaccurate data and complete incomplete data;
- erase your data (“right to be forgotten”);
- restrict or object to certain processing (including processing based on legitimate interests);
- data portability (receive your data in a portable format);
- withdraw consent where processing is based on consent;
- lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office (ICO); in the EEA, your national Data Protection Authority).
United States (incl. California CCPA/CPRA and similar state laws). You have the right to know what we collect, to access and delete it, to correct it, and to opt out of “sale”/“sharing” — and we do not sell or share personal information, so there is nothing to opt out of.
Placeholder — for legal counsel to draft
Confirm the exact, jurisdiction-specific rights language and any required disclosures (CCPA/CPRA categories collected/disclosed and metrics; the precise GDPR response window and any verification/appeal steps) with privacy counsel.11. Children
The Service is not directed to, and is not intended for, children. We do not knowingly collect personal data from anyone under 18 (a deliberately conservative bar that covers both the U.S. COPPA threshold of 13 and the GDPR child-consent thresholds of 13–16 used across EEA states). If you believe a child has provided us data, contact us via support@marsadmarkets.com and we will delete it.
Placeholder — for legal counsel to draft
The exact minimum age can be set per jurisdiction; confirm the chosen threshold with counsel.12. Data-breach notification
If a personal-data breach occurs that is likely to affect you, we will notify affected users without undue delay, and we will notify the relevant supervisory authority where required. Under the GDPR/UK GDPR, notification to the supervisory authority is generally required within 72 hours of becoming aware of a qualifying breach.
Placeholder — for legal counsel to draft
Operational, not just text: maintain an incident-response plan that can actually meet the 72-hour authority deadline and the user-notification duty, and confirm the exact thresholds/content with counsel.13. Changes & contact
We may update this policy; for material changes we will notify you in-app or by email and, where required, ask you to re-confirm your agreement. Questions or requests: support@marsadmarkets.com.