Privacy
Privacy Policy
Who we are
StockSetupLists.com (the “Service”) is operated by Zero Vector Apps LLC (“we,” “us”). This policy explains what personal information we collect, how we use it, and the rights you have over it.
Information we collect
We deliberately collect the minimum information needed to operate the Service. Specifically:
- Account information. Your email address and a unique account identifier. If you sign in with a third-party provider (e.g., Google), we receive only the basic profile information that provider sends us.
- Authentication tokens. Short-lived session tokens stored in your browser or app and verified on each request.
- User preferences. Settings you save in the product, such as your saved indicators and UI preferences.
- Information you choose to send us. Text you type and send — for example an answer to an in-app survey. We store it against your account so we can read it and act on it. The words you write stay with your account and are never sent to an analytics provider. Whether you answered, and which multiple-choice option you picked, is sent to Firebase Analytics as an event — the text you typed is not.
- Entitlement status. Whether your account has access to paid features.
- Server logs. Operational logs (request paths, timestamps, response codes, error traces) retained for up to 90 days for debugging and security. These may include IP addresses.
- Website usage counts. Anonymous, aggregate counts of which public pages are viewed and which buttons are clicked on this website. These counts contain no information that identifies you: no cookie, no identifier, no IP address and no browser fingerprint is recorded, and nothing links one page view to another or to your account. We cannot tell how many people the counts represent, only how many times something happened.
Market data displayed on the Service is licensed from a third-party data provider and contains no information about you.
Cookies, local storage, and analytics
We deliberately keep our use of cookies and browser storage narrow. We do not use any third-party analytics, advertising, behavioral-tracking, or marketing cookies on our marketing website. The website does keep its own anonymous, aggregate counts of page views and button clicks, described in section 02. Those counts are first-party — the data goes only to us, never to a third party — and collecting them stores nothing on your device and reads nothing from it.
The only browser storage the website relies on is what's strictly necessary to operate the Service:
- Authentication state stored in your browser's local storage (not cookies) by our authentication provider, so your sign-in survives page reloads. Without this you would be signed out on every refresh.
- Session and CSRF protection cookies set transiently by the authentication provider's sign-in flows. These exist only for the duration of the sign-in and are not used to track you.
Because everything the website stores is strictly necessary to authenticate you and deliver the Service you requested, we do not show a cookie-consent banner on the marketing pages. The ePrivacy Directive and analogous laws exempt strictly-necessary storage from the consent requirement.
The StockSetupLists app — analytics.Our app (on iOS, Android, and the web app at /app) includes Google's Firebase Analytics so we can understand how the app is used in aggregate and decide what to build next.
- What's collected: a random, resettable app-instance identifier, screen views, a small set of in-app events we instrument (for example, sign-in completed, a setup list opened, a chart opened), device model, OS/app version, language, and an approximate (city-level at most) location derived from your IP.
- What's not collected: your account identifier, your email, or your name. We do not enable User-ID or Google Signals, we do not link analytics to Google Ads, and we do not track you across other apps or websites.
- Your control: in regions that require opt-in consent (the EU/EEA, UK, and Switzerland) the app asks before any analytics are recorded. Everywhere else analytics are on by default and you can turn them off anytime in Settings → Privacy → Share analytics. You can also reset the app-instance identifier from your device settings.
You can clear the website's storage at any time from your browser's settings (doing so will sign you out), or opt out of app analytics as described above.
How we use information
- To authenticate you and keep your account secure.
- To remember your preferences across sessions.
- To read and act on feedback or survey answers you choose to send us.
- To determine whether you are entitled to access paid features.
- To operate, debug, and improve the Service (logs, error tracking).
- To communicate with you about service updates and, if you have opted in, occasional product communications.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information. We do not use your personal information to train AI models.
Service providers
We rely on a small number of third-party service providers to operate the Service. They process information only on our behalf and only as needed to provide their services. The categories of providers we use are:
- Cloud hosting and database providers — to host the Service and store account data.
- Authentication providers — to manage account sign-in and identity.
- AI model providers — to generate the market digest from aggregate, non-personal market data. No personal information is sent.
- Market data providers — to supply the price and reference data the Service analyzes. No user data is shared.
- Payment and subscription processors — to handle billing for paid features (when paid features go live).
Where required, we rely on industry-standard processor agreements with these providers, including the Cloud Data Processing Addendum that governs our use of cloud hosting, database, and authentication services. That addendum incorporates the EU Standard Contractual Clauses for cross-border data transfers.
Data retention and deletion
We keep your personal information only as long as we need it. Specific retention windows:
- Account information and preferences — retained while your account is active and for up to 24 months after your last sign-in, then purged.
- Legal-acceptance audit records — each time you accept the Terms or this Policy we record which versions you accepted, when, and the IP address and browser user agent the acceptance came from. Those two details are what make the record evidence rather than an assertion, so this record deliberately outlives your account: it is retained for the longer of (a) the life of your account or (b) the period required by applicable law for evidentiary purposes, up to 7 years after account deletion, after which it is scheduled for automatic deletion. We keep it on the basis of our legitimate interest in being able to establish that you agreed to the terms in force at the time, and to comply with legal obligations.
- A deletion marker — when you delete your account we write a small record keyed to your account identifier (no email address, no name) recording that the account was deleted. It is written for every deleted account, not only accounts that held a subscription, and it is kept indefinitely on the basis of our legitimate interest in making the deletion stick: without it, a late payment notification from an app store could silently re-create access for an account you asked us to erase.
- A free-trial marker — if you have ever started a free trial, we keep a one-way hash of the email address that started it. While your account exists we keep your account identifier alongside it; that identifier is removed when you delete your account, so what outlives the account is the hash alone. It exists so that one free trial per person is enforceable, which is not possible if the record disappears with the account. The email address itself is not stored in a readable form. It is retained for 24 months from the day the trial started, then automatically deleted.
- Server logs — retained for up to 90 days.
- Website usage counts — retained for up to 24 months, then purged. Because these counts identify nobody, there is nothing in them to attach to a deletion request.
- Backups — may persist for up to 30 additional days before being overwritten by routine retention cycles.
Right to delete your account. You can permanently delete your account at any time from the Settings screen (in-app) or by emailing support@zerovectorapps.com. Deletion immediately revokes your ability to sign in and purges your account document and every subcollection beneath it — preferences, survey answers, and anything else stored under your account — from active storage, except for the markers and the acceptance record named in the retention list above. Backup copies are overwritten within 30 days as part of routine retention.
If you have a subscription bought on this website. We cancel it for you as part of the deletion, so you are not billed again. The cancellation takes effect at the end of the period you have already paid for; we do not refund the remainder of that period. If we cannot reach our payment provider to cancel it, we do not delete anything — we tell you so, and you can cancel it yourself and try again. That is deliberate: erasing your account while a payment is still scheduled would leave you being charged for a service you can no longer sign in to.
If you subscribed through the App Store or Google Play, we cannot cancel it for you — only the store can. Deleting your account does not stop that subscription. Cancel it in your device's subscription settings before or after deleting your account.
Published market analysis (setup lists and digests) is retained indefinitely as part of the Service's record. It contains no personal information.
Your rights
Depending on where you live, you may have rights under laws such as the GDPR (EU/UK) or the CCPA (California), including:
- To request a copy of the personal information we hold.
- To correct inaccurate information.
- To request deletion of your account and personal data.
- To opt out of non-essential communications.
To exercise any of these rights, contact us at the address below. We will respond within the timeframes required by applicable law.
California residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- Right to know what categories of personal information we have collected about you, the sources, the purposes for which it was collected, and the categories of third parties with whom we share it.
- Right to delete personal information we have collected about you, subject to limited exceptions.
- Right to correct inaccurate personal information we hold about you.
- Right to opt out of sale or sharing of your personal information.
- Right to limit use of sensitive personal information for purposes other than providing the Service.
- Right to non-discrimination for exercising any of these rights.
We do not sell or share your personal informationas those terms are defined under the CCPA/CPRA. We do not use your personal information for cross-context behavioral advertising.
Categories of personal information we collect (CCPA categories, with business purpose):
- Identifiers (email address, account identifier) — to authenticate you and operate your account.
- Internet or other network activity information (request paths, timestamps, response codes, IP address in server logs) — for security, debugging, and service operation.
- User-provided content (saved preferences and settings; text you send us, such as survey answers) — to personalize the Service to your configuration.
- Inferences and account status (entitlement status indicating access level) — to deliver paid features.
To exercise any California right, email support@zerovectorapps.com with the subject line "California Privacy Request" and your account email. You may also designate an authorized agent to submit a request on your behalf, subject to verification.
Security and breach notification
We use industry-standard safeguards (encryption in transit, scoped service accounts, audit logging, least-privilege access) to protect your information. No system is perfectly secure; we cannot guarantee absolute security.
If we discover a security incident that compromises your personal information, we will:
- Investigate, contain, and assess the scope of the incident without undue delay.
- Notify affected individuals in accordance with applicable law, including the Florida Information Protection Act (FIPA, Fla. Stat. §501.171), which generally requires notification within 30 days of determining a breach has occurred.
- Notify the Florida Attorney General and any other state, federal, or foreign authorities (including supervisory authorities under the GDPR) where required by law.
Notifications will describe, to the extent known, the categories of information involved, the date of the incident, the steps we are taking, and the steps you can take to protect yourself.
International users
The Service is hosted in the United States. By using the Service from outside the US, you understand that your information will be transferred to and processed in the US, which may have data protection laws that differ from those of your country.
Children
The Service is not directed to children under 18 and we do not knowingly collect personal information from them. If you believe we have inadvertently collected information from a minor, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. Material changes will be announced on the Service and will take effect on the updated effective date shown above. Your continued use of the Service after changes take effect constitutes acceptance.
Contact
Privacy questions or requests: support@zerovectorapps.com.