Privacy Notice

This notice describes information handled by the Stock Tracker application and the purposes for handling it.

Version
1.0
Effective date
Last updated

Draft for product-owner and legal review. This policy should be reviewed before production publication.

Scope

This notice describes information handled by the Stock Tracker application. It does not make claims about unrelated systems operated by service providers or the service operator.

Information handled

The application handles account information such as an external identity reference, local account status, onboarding state, and preferences.

It handles user configuration such as watchlists, memberships, alert rules, and notification-channel state.

When Telegram is linked, the submitted destination is verified and stored in protected form. Deterministic protected comparison data may also be stored. The plaintext destination is not intended to be displayed after linking.

The application also handles global instrument metadata, provider mappings, quotes, daily prices, analytics snapshots, fetch state, provider operational history, alert evaluation state, triggers, delivery attempts, and application logs. Global market data is not necessarily personal data, but it may be associated with user-chosen positions through watchlists.

Logs are designed to avoid sensitive identities, destinations, market values, credentials, and raw payloads.

Purposes

Information is handled for authentication and account access, watchlist and preference operation, market-data and analytics display, alert evaluation, notification delivery, reliability, security, maintenance, retention, and cleanup.

The application does not add advertising or profiling through these product workflows.

External services

The relevant external service categories are the authentication provider, market-data providers, and Telegram when enabled. Only information required for the relevant operation is sent according to the implemented boundaries; external providers may receive information needed to perform that operation.

Market-data provider requests use instrument and provider context rather than local user identity. When Telegram is used, Telegram receives the explicit destination and prepared notification text for verification or alert delivery. The Telegram bot token is service configuration, not user data.

Protected Telegram destination storage

Telegram destinations are intended to be stored using authenticated protection, and a keyed fingerprint supports comparison and idempotency. The application does not display the stored destination after linking.

No security mechanism eliminates all risk, and this description does not promise absolute security or that Telegram cannot see a destination used for delivery.

Retention

Retention periods may vary by record category and operational need. User-owned configuration remains while needed for service operation or until lifecycle actions change it.

Removed memberships and archived rules may remain as durable records. Canonical daily-price history, analytics, and alert-trigger history follow product retention boundaries, while high-volume operational records and old quote history may be cleaned through bounded retention workflows. Active or current operational records are preserved according to workflow policy.

Data deletion limitations

The current UI supports removal or disabling of certain configuration. Removal may be a soft lifecycle transition. This task does not introduce a complete account-deletion or privacy-request workflow, and it does not promise immediate deletion.

For questions about information handling, use the support contact identified by the service operator.

Security and logs

The application uses access controls, CSRF protections, scoped ownership queries, protected destination storage, bounded validation, and secret-handling practices. No system can guarantee absolute security.

Operational logs are designed to exclude identities, secrets, destinations, protected values, raw provider payloads, and market values. Aggregate status and safe failure categories may be logged. Infrastructure-level access logging may require separate operational configuration.

International processing and changes

Third-party services may process information in locations determined by their own operations and policies.

This notice may be updated. The published version and effective date identify the current text.

Contact

For questions about this notice, use the support contact identified by the service operator.