1. Introduction
This Privacy Policy explains how we collect, use, protect, and share your personal information when you use our platform, and the control you have over your data.
Our platform is for educational purposes and all data processing supports that purpose; it does not involve providing financial advice or recommendations.
2. Data Controller Information
Stockoscope Pty Ltd
ABN: 67 656 633 948
44 Atlantic Blvd, Glenfield NSW 2167, Australia
Privacy Officer: [email protected]
3. Information We Collect
3.1 Information You Provide
| Category | Data Types | Purpose |
|---|---|---|
| Account Information | First and last name, email address, and password (stored encrypted by our authentication provider) | Account creation and management |
| Profile Data | Watchlists (lists of tickers you save) | Saving your watchlists |
| Payment Information | Card brand, last four digits, expiry, billing country, and Stripe customer ID. We never receive or store full card numbers. These are handled directly by our payment processor, Stripe. | Subscription billing, renewals, fraud prevention, customer service |
| Communication Data | Support tickets, feedback, survey responses, email preferences | Customer service and improvements |
3.2 Information We Collect Automatically
| Category | Data Types | Purpose |
|---|---|---|
| Usage Data | Features accessed, pages viewed, search queries, time spent | Service improvement and analytics |
| Device Information | IP address, device type, operating system, browser type, screen resolution | Security and optimization |
| Location Data | Approximate location such as country, region, and time zone (inferred from IP address) | Content localization and compliance |
| Technical Data | Log files, error reports, performance metrics | Troubleshooting and maintenance |
3.3 Information from Third Parties
- Social Login Data: Basic profile if you use Google/X/Microsoft sign-in
- Financial Data Providers: Market data linked to your queries
- Analytics Partners: Aggregated usage patterns
4. Legal Bases for Processing
We process your data under the following legal bases:
4.1 Contract Performance
Essential for providing our services, including account management, subscription processing, and core platform features.
4.2 Legitimate Interests
For business operations such as fraud prevention, security, service improvements, and aggregated analytics, balanced against your privacy rights.
4.3 Consent
For optional features like marketing communications and non-essential cookies.
4.4 Legal Obligations
To comply with our legal obligations, including tax, accounting, and record-keeping requirements, and to respond to lawful requests from authorities.
5. How We Use Your Information
5.1 Service Delivery
- Create and authenticate your account
- Provide access to financial data and tools
- Save your watchlists
- Deliver customer support
5.2 Personalization & Enhancement
Any personalization is limited to your experience of the Platform, not to the analytical outputs. We use your information to:
- Remember display preferences (such as theme) and recently viewed stocks, kept on your device
- Improve the user interface based on aggregated usage patterns
- Develop new features based on user needs
We do not build a financial profile of you, and we do not use your personal or financial circumstances to tailor scores, valuations, or screening results. Any custom score weights, assumptions, or screen criteria you set are calculation parameters you have chosen, not a profile of you; the analytical outputs are the same for every user who chooses the same parameters.
5.3 Communications
- Send transactional emails (receipts, alerts, security notices)
- Deliver product updates and new feature announcements
- Share educational content and general market information (with consent)
- Provide educational resources about financial analysis concepts
- Respond to your inquiries and requests
6. Data Sharing and Disclosure
6.1 Service Providers
We share limited personal data with vetted processors who support our operations under written contracts that restrict their use of the data. Our current key processors are:
- Authentication: Google Firebase (account login and credential storage). Hosted in the United States.
- Hosting and Database: DigitalOcean (application hosting and primary database for user accounts, watchlists, and related data). Hosted in the United States.
- Payments: Stripe (subscription billing and payment processing). Hosted in the United States; Stripe processes card data under PCI DSS Level 1.
- Transactional & lifecycle email: Resend (account, billing, trial, and security email delivery). Hosted in the United States.
- Newsletter email: MailerLite (opt-in marketing newsletter delivery only). Hosted in the European Union.
- Analytics: Google Analytics (aggregated and pseudonymized usage analytics). IP anonymization is enabled.
- Logos: Logo.dev (company logo lookup; receives ticker symbols, not personal data).
We do not sell your personal information. We share data with these processors only to the extent needed to deliver the Service, and not to provide personalized financial advice or recommendations.
6.2 Market Data Providers
We source market data from third-party providers. These providers may have their own privacy policies governing their handling of data. We do not share your personal information with these providers except as required to deliver the Service.
6.3 Business Transfers
If Stockoscope is involved in a merger, acquisition, financing, or sale of all or part of its business, your personal data may be transferred to the party involved as part of that transaction. We will require the recipient to honor this Privacy Policy, and we will notify you by email or in-app notice of any change of controller and of any choices you may have.
7. International Data Transfers
Stockoscope is based in Australia. Because our processors operate globally, your personal data may be transferred to and stored in countries outside your country of residence, including the United States and the European Union.
- Primary processing locations: Australia (us as controller), United States (Firebase, DigitalOcean, Stripe, Resend, Google Analytics, Logo.dev), European Union (MailerLite).
- Transfer safeguards (EU/UK users): For transfers of personal data from the European Economic Area or United Kingdom to the United States, we rely on the EU-U.S. Data Privacy Framework where the receiving processor is certified, and on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum) where it is not.
- Australian users: Where we disclose personal information overseas, we take reasonable steps under Australian Privacy Principle 8 to ensure overseas recipients handle the information consistently with the APPs.
- Your rights: You may request information about where your data is stored and what safeguards we use by emailing [email protected].
8. Data Security and Breach Notification
We take reasonable steps to protect your data using industry-standard security practices, and we rely on established infrastructure providers (such as Google/Firebase, DigitalOcean, and Stripe) that maintain their own recognized security programs. Card payments are handled by Stripe under the PCI DSS standard.
8.1 Technical Safeguards
- TLS encryption for data in transit;
- Provider-managed encryption for data at rest (Firebase, DigitalOcean, Stripe);
- Authentication controls and restricted administrative access;
- Routine patching of dependencies and infrastructure.
8.2 Organizational Measures
- Access to personal data is limited to authorized personnel on a need-to-know basis;
- Team members are bound by confidentiality and data-handling obligations;
- Logging and monitoring of access to production systems.
8.3 Breach Notification
If we become aware of a data breach that is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). Where applicable, we will also notify supervisory authorities and affected individuals as required by the GDPR (Articles 33 and 34) or other applicable laws.
8.4 Use of Personal Data for AI Model Training
We do not use your personal data to train third-party generative AI models, and our processor contracts prohibit them from doing so on our behalf. Any use of AI tools internally is limited to non-personal or aggregated data.
9. Data Retention
We retain data based on purpose and legal requirements:
| Data Category | Retention Period | Justification |
|---|---|---|
| Account Data | Active account + 30 days | Service delivery and account management |
| Usage Analytics | 2 years | Service improvement and performance insights |
| Security Logs | 1 year | Security monitoring and fraud prevention |
| Deleted Content | Up to 30 days (system-level backup) | Operational recovery and rollback |
| Billing Records | 7 years from end of financial year | Australian tax law (s262A Income Tax Assessment Act 1936) and equivalent record-keeping rules |
10. Your Privacy Rights
Depending on your location and applicable law, you have the following rights regarding your personal data. We will respond to valid requests within the timeframes required by the law applicable to you (and in any case no later than 30 days, unless an extension is permitted).
10.1 Universal Rights
- Access: Request a copy of your personal data;
- Correction: Update inaccurate or incomplete data;
- Deletion: Request erasure of your data (“right to be forgotten”), subject to retention we are required to keep by law. You can also close your account from account settings; when you do, we keep your saved data for a 30-day grace period (so you can export or reactivate) before permanently deleting it, as set out in the Terms of Service;
- Portability: Receive your data in a machine-readable format where technically feasible. You can export your own content (your watchlists and preferences) at any time from account settings as JSON or CSV;
- Objection: Object to processing carried out under legitimate interests, including direct marketing;
- Restriction: Request that we limit how we process your data while we resolve a request;
- Consent withdrawal: Withdraw consent for processing that depends on consent (such as marketing emails or non-essential cookies) at any time, without affecting prior processing.
10.2 Regional rights and complaints
Depending on where you live you may have additional rights and the right to complain to your local privacy regulator. In Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply and you can complain to the OAIC (oaic.gov.au). In the EU/UK, the GDPR and UK GDPR apply and you can complain to your national data-protection authority (in the UK, the ICO, ico.org.uk). California residents have rights under the CCPA/CPRA to know, delete, correct, and opt out of the “sale” or “sharing” of personal information; we do not sell personal information for money, and you can opt out of any advertising or analytics “sharing” via our cookie controls or by emailing [email protected]. You will not be treated differently for exercising any of these rights.
10.3 Exercising your rights
Submit requests to [email protected] with reasonable proof of identity and the right(s) you wish to exercise. An authorized agent may submit a request on your behalf where the law allows.
11. Children’s Privacy
Our Service is not intended for users under 18. We do not knowingly collect data from minors. If we discover such collection, we will promptly delete the data.
12. Cookies and Tracking
We use cookies and similar technologies (browser local storage, and tracking pixels in our emails) to keep you logged in, remember your preferences, understand how the Service is used, and improve it.
12.1 Categories we use
- Essential (always on): authentication, security (CSRF), load balancing, and saving preferences such as theme. These are required to run the Service and cannot be disabled.
- Analytics (optional): Google Analytics and internal analytics to understand usage and fix issues, with IP anonymization enabled.
- Functionality (optional): remembering your theme, watchlists, time zone, and recently viewed stocks.
- Marketing / advertising: where we use advertising or retargeting cookies, we do so only with your consent, which you can withdraw at any time.
Third-party cookies and email tracking pixels are set by the processors listed in the Service Providers section (for example Google Analytics, and our email providers Resend and MailerLite); each has its own privacy policy.
12.2 Lifespan
Cookies range from session cookies (deleted when you close your browser) to short-term (24 hours to 7 days), medium-term (around 30 days, e.g. analytics), and long-term (1 to 2 years, e.g. preferences).
12.3 Managing your preferences
- Where required by your local law (including the EU/UK ePrivacy rules and GDPR), we show a cookie consent banner on your first visit and when our use of non-essential cookies materially changes. You can change your choices at any time via the cookie settings link in the site footer, or by emailing [email protected].
- You can also block or delete cookies in your browser settings (Chrome, Firefox, Safari and Edge all provide cookie controls), and opt out of analytics or advertising via tools such as the Google Analytics opt-out, the NAI opt-out, and Your Online Choices. California residents’ “Do Not Sell or Share” rights are covered in the Regional rights and complaints section.
Disabling essential cookies may prevent you from logging in or cause lost preferences; disabling optional cookies gives a more generic experience but does not block access.
12.4 Do Not Track and Global Privacy Control
We do not currently respond to browser “Do Not Track” (DNT) signals, as there is no agreed standard. Where the law requires (for example under the CCPA), we treat a Global Privacy Control (GPC) signal as an opt-out from the sale or sharing of personal information.
13. Privacy Policy Updates
We may update this policy to reflect legal or regulatory changes, new features or services, improved privacy practices, or user feedback. Material changes will be notified via email or in-app alert at least 30 days before taking effect; non-material edits (such as wording clarifications) will be reflected by updating the “last updated” date at the top of this page.
Related policies
Read this together with our Terms of Service, Investment Disclaimer, Billing & Refund Policy, and Data Sources & Usage Policy.
Contact
Questions about this policy? Email [email protected].