Marsad Markets
Draft — not legal advice and not yet in effect. This document is a working draft pending review by qualified legal counsel. Bracketed values (e.g. [COMPANY]) are placeholders to be finalized before these terms take effect.

Privacy Policy

Draft last updated June 17, 2026 · Posted July 4, 2026

This policy describes what Marsad Markets collects when you use the Marsad Markets, how we use it, who processes it, and the rights you have. It reflects what the application actually collects. The Service is available globally, so this policy covers residents of the European Economic Area (EEA), the United Kingdom, the United States, and elsewhere — your specific rights depend on where you live (see “Your rights”).

1. Who is responsible for your data (controller)

Marsad Markets is the data controller for the personal data described here and decides how and why it is processed. The infrastructure providers listed below act as our processors (sub-processors), handling data only on our instructions. Contact for any privacy matter: support@marsadmarkets.com.

2. Information we collect

We collect only what the Service needs to run your account:

  • Account details: your email address, a password (stored hashed by our authentication provider — we never receive or store your plaintext password), and your display name. Optionally a username and avatar URL if you add them.
  • Preferences: your chosen sizing basis (a hypothetical number you set for position-sizing math — not money held) and your theme preference.
  • Content you create: watchlists (ticker symbols), portfolio entries you type in yourself (ticker, share count, optional cost basis — a self-entered tracking list, not a connection to any brokerage or bank), and price/criteria alerts you configure.
  • Agreement record: the version and timestamp of the Terms, Privacy Policy, and Disclaimer you accept at registration.
  • Technical logs: standard server logs at our hosting providers, which include your IP address, browser/user-agent, and request metadata, used for security and reliability.
  • Aggregate usage analytics: which pages are visited and which site referred the visit, measured by a privacy-focused, cookieless analytics service (Umami, hosted in the European Union). It sets no cookies, stores nothing on your device, and does not record who you are: visitor counting uses a salted hash that rotates daily and cannot be linked back to you, and we send it no account information — no user IDs, no email addresses, nothing from your signed-in session.

We do not ask for or store financial-account credentials, government IDs, or payment-card data (the Service is free; no payment data is collected). We do not knowingly collect special-category data.

3. How we use it

  • to create and operate your account and authenticate you;
  • to provide and personalize in-app features you configure (watchlists, portfolio tracking, alerts, position sizing);
  • to send essential service email (e.g. signup confirmation, security);
  • to secure, debug, prevent abuse of, and improve the Service;
  • to understand aggregate usage (which pages are visited, from which referrers) so we can improve the product — measured without cookies or personal identifiers, as described in “Cookies & tracking”.

We do not sell your personal information, we do not “share” it for cross-context behavioral advertising, and we do not use it for third-party advertising or profiling.

4. Our lawful bases (GDPR / UK GDPR Art. 6)

For users in the EEA/UK, we rely on these lawful bases, by purpose:

  • Performance of a contract — to create and run the account and provide the features you sign up for (account, watchlists, portfolio tracking, alerts).
  • Legitimate interests — to keep the Service secure, prevent abuse, debug, and maintain essential logs, and to measure aggregate usage with a cookieless, non-identifying analytics service; balanced so as not to override your rights and freedoms.
  • Legal obligation — where we must retain or disclose data to comply with applicable law.
  • Consent — we do not currently carry out any consent-based processing (no marketing, no advertising, no tracking that stores anything on your device; our analytics is cookieless and relies on legitimate interests, above). If we ever add processing that requires consent, we will request it first and you may withdraw it at any time.

5. Who processes your data (sub-processors)

We share personal data only with the infrastructure providers that run the Service:

  • Supabase — database, authentication, and transactional email. Stores the account and content data above.
  • Vercel — frontend hosting and content delivery. Processes request logs (incl. IP).
  • Render — backend API hosting. Processes request logs (incl. IP).
  • Umami (Umami Software, Inc. — Umami Cloud, EU region) — cookieless aggregate analytics. Receives the page URL, referrer, and standard request metadata (incl. IP address and user-agent, processed transiently to derive a daily-rotating salted visitor hash — the raw IP is not stored as a visitor identifier). Data residency: European Union.

Market-data and filings providers do not receive your personal information. When the Service fetches public market data or filings (for example, price, fundamentals, or SEC data), those requests carry no user identifiers — they ask only about securities, never about you.

Placeholder — for legal counsel to draft

Operational, not just text: a GDPR Art. 28 Data Processing Agreement (DPA) must be in place with each of Supabase, Vercel, and Render (each publishes one). Execute/confirm these — see the operational items in docs/legal/LEGAL_REVIEW_CHECKLIST.md.

6. International data transfers

Our hosting processors (Supabase, Vercel, Render) operate infrastructure in the United States, so if you are in the EEA or UK your personal data is transferred to and processed in the United States. For those transfers we rely on the processors’ appropriate safeguards — Standard Contractual Clauses (SCCs) (and the UK Addendum) and any applicable adequacy framework — incorporated in their data-processing terms. Analytics data is the exception in the other direction: it is processed and stored in the European Union (Umami Cloud, EU region) and is not a transfer out of the EEA.

Placeholder — for legal counsel to draft

Operational, not just text: confirm the specific transfer mechanism each processor offers (SCCs / UK Addendum / Data Privacy Framework participation) and that it is incorporated in the executed DPA. This is a contract to verify, not a statement to assert blindly.

7. Cookies & tracking

We use only essential cookies: an authentication/session cookie (so you stay logged in) and a small preference cookie for your theme. The application contains no advertising or cross-site tracking technologies of any kind.

For usage measurement we use Umami, a privacy-focused analytics service hosted in the European Union. It is cookieless: it sets no cookies and stores nothing on your device, so there is nothing for a cookie banner to ask about. It records page views and referrers in aggregate; visitors are counted with a salted hash that rotates daily, is computed server-side, and cannot identify you. We send it no account data — analytics is entirely separate from your signed-in session. Because we use only strictly-necessary cookies and the analytics stores nothing on your device, no cookie-consent banner is required (essential cookies are exempt under the ePrivacy rules).

Placeholder — for legal counsel to draft

The no-consent position for cookieless analytics rests on ePrivacy Art. 5(3) applying to device storage/access (none here) and GDPR legitimate interests for the transient IP processing — the position taken by privacy-focused analytics vendors and widely accepted, but a few EU regulators read fingerprint-adjacent techniques more broadly. Confirm with counsel; if counsel disagrees, the fallback is a prior opt-in for the analytics script. Any FUTURE tool that does store on-device requires prior opt-in consent — do not ship one without it.

8. Retention

We keep account and content data for as long as your account is active. When you delete your account (or ask us to), we delete or de-identify your personal data within a short period — typically up to 30 days — except where we must retain limited records to meet a legal obligation or for security/abuse-prevention. Technical server logs are retained for a limited period (typically up to 90 days) by our hosting providers.

Placeholder — for legal counsel to draft

Confirm and document the exact retention periods (post-deletion grace and log retention) as an operational decision; the figures above are reasonable defaults to finalize.

9. Security

We use reasonable technical and organizational measures, including encryption in transit, hashed passwords, scoped access keys, and row-level access controls. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

10. Your rights (depend on where you live)

You can exercise any of the rights below via support@marsadmarkets.com. We will respond within the time required by your local law (for the EEA/UK, generally within one month). We will not discriminate against you for exercising your rights.

EEA & UK (GDPR / UK GDPR). You have the right to:

  • access a copy of your personal data;
  • rectify inaccurate data and complete incomplete data;
  • erase your data (“right to be forgotten”);
  • restrict or object to certain processing (including processing based on legitimate interests);
  • data portability (receive your data in a portable format);
  • withdraw consent where processing is based on consent;
  • lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office (ICO); in the EEA, your national Data Protection Authority).

United States (incl. California CCPA/CPRA and similar state laws). You have the right to know what we collect, to access and delete it, to correct it, and to opt out of “sale”/“sharing” — and we do not sell or share personal information, so there is nothing to opt out of.

Placeholder — for legal counsel to draft

Confirm the exact, jurisdiction-specific rights language and any required disclosures (CCPA/CPRA categories collected/disclosed and metrics; the precise GDPR response window and any verification/appeal steps) with privacy counsel.

11. Children

The Service is not directed to, and is not intended for, children. We do not knowingly collect personal data from anyone under 18 (a deliberately conservative bar that covers both the U.S. COPPA threshold of 13 and the GDPR child-consent thresholds of 13–16 used across EEA states). If you believe a child has provided us data, contact us via support@marsadmarkets.com and we will delete it.

Placeholder — for legal counsel to draft

The exact minimum age can be set per jurisdiction; confirm the chosen threshold with counsel.

12. Data-breach notification

If a personal-data breach occurs that is likely to affect you, we will notify affected users without undue delay, and we will notify the relevant supervisory authority where required. Under the GDPR/UK GDPR, notification to the supervisory authority is generally required within 72 hours of becoming aware of a qualifying breach.

Placeholder — for legal counsel to draft

Operational, not just text: maintain an incident-response plan that can actually meet the 72-hour authority deadline and the user-notification duty, and confirm the exact thresholds/content with counsel.

13. Changes & contact

We may update this policy; for material changes we will notify you in-app or by email and, where required, ask you to re-confirm your agreement. Questions or requests: support@marsadmarkets.com.

Privacy Policy · Marsad Markets