Privacy Policy

How we collect, use, and protect your information

Effective Date: January 15, 2026 | Last Updated: January 26, 2026

Summary: We collect only what's necessary to provide portfolio tracking. We never sell your data. Your brokerage credentials are never shared with us. You can delete your account and data at any time.

Information We Collect

We collect different types of information to provide and improve our service.

Account Information
  • Email address
  • Name (optional)
  • Authentication via Clerk (MFA supported)
Portfolio Data
  • Stock symbols and positions
  • Price targets and alerts
  • Notes and annotations
  • Chart preferences
Financial Connections
  • Holdings and transactions (via Plaid)
  • Account metadata
  • Never your brokerage credentials
  • Never ability to move funds
Usage & Technical
  • Features accessed
  • Device and browser info
  • IP address (anonymized)
  • Error logs for debugging

How We Use Your Information

Service Operation

Core

Display your portfolio, provide alerts, generate analytics, sync across devices

Service Improvement

Core

Analyze usage patterns, fix technical issues, develop new features

Security

Core

Detect fraud, enforce terms, comply with legal obligations

Information Sharing

We do NOT sell your personal information. We never sell, rent, or trade your data to third parties for marketing purposes.

Service Providers

We share limited information with trusted providers who help us operate the service:

Authentication
Clerk
Email, auth tokens (SOC 2 certified)
Hosting
Vercel
Encrypted application data (SOC 2 certified)
Database
Neon
Encrypted user data (SOC 2 certified)
Caching
Upstash
Session data (SOC 2 certified)
Financial Connections
Plaid
User authorization only (SOC 2 certified)
Billing
Stripe
Payment processing (PCI DSS certified)

Data Security

Encryption
  • All data encrypted in transit (TLS 1.2+)
  • Sensitive data encrypted at rest (AES-256-GCM)
  • Passwords handled by Clerk (never stored by us)
Access Control
  • Phishing-resistant MFA required for financial features
  • Role-based access control
  • Regular security audits

Data Retention

Data Type Retention Period Justification
Account data Duration of account Service operation
Portfolio data Duration of account Service operation
Financial connections Until disconnected User convenience
Usage analytics 2 years Service improvement
Security logs 3 years Security and compliance

Data Deletion

When you delete your account:

  1. Plaid connections are immediately revoked
  2. Personal data is marked for deletion
  3. 30-day grace period for account recovery
  4. Permanent deletion after grace period

Your Rights

Access & Portability

  • View all data we have about you
  • Export your portfolio data
  • Download account information

Deletion

  • Delete your account at any time
  • Request deletion of specific data
  • 30-day recovery window

Control

  • Update your information
  • Manage connected accounts
  • Adjust notification preferences

California Privacy Rights (CCPA)

California residents have additional rights:

Right to Know

Categories and sources of personal information collected

Right to Delete

Request deletion of personal information

Right to Opt-Out

We do not sell personal information

Non-Discrimination

Equal service regardless of privacy choices

To exercise CCPA rights, email privacy@positiontracker.trading with subject "CCPA Request."

Cookies and Tracking

Essential Cookies

Required

Authentication, session management, security (CSRF protection), and user preferences

Analytics

Optional

Usage patterns to improve the service. You can opt out through browser settings or cookie preferences.

We honor "Do Not Track" browser signals when possible.

Children's Privacy

PositionTracker is not intended for users under 18 years of age. We do not knowingly collect information from children. If you believe a child has provided us information, please contact us immediately.

International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including:

Third-Party Privacy Policies

Our service integrates with third parties that have their own privacy policies:

Policy Changes

We may update this Privacy Policy from time to time. Material changes will be communicated via email notification, in-app notification, or prominent notice on our website. Continued use after changes constitutes acceptance.

Contact Us

Have questions about your privacy? We're here to help.