Privacy Policy

Version 2026-08-27 · Last updated 27/08/2026

[legal name] (company no. [company number]), [address], [country], is the controller for the processing of your personal data in Investment Planner. Privacy questions: [privacy email].

Must be completed by the service owner before publishing.

1. Data we process

  • Account data: email address, name (if provided), password in hashed form, language and currency.
  • Content you create: portfolios, holdings, transactions, cash, goals, savings plans, scenarios and notes.
  • Subscription: your Stripe customer id, status, interval, amount and period. Card numbers are processed only by Stripe.
  • Usage: aggregated events about which features are used, to improve the service.
  • Consent: which version of the terms and privacy policy you accepted, with a timestamp.
  • Support and feedback: tickets you create with subject, messages, any screenshots you attach, and technical details for bug reports (page, app version, language, browser, operating system and screen size).

2. Purposes and legal bases

  • To provide the service and your account — performance of a contract.
  • To bill and collect payment for Premium — contract and legal obligation (accounting).
  • For security, troubleshooting and abuse prevention — legitimate interest.
  • To handle your support and feedback tickets and reply to you — contract and legitimate interest.
  • To improve features based on aggregated usage — legitimate interest.
  • To demonstrate that you accepted the terms — legal obligation and legitimate interest.

3. Retention

Account and portfolio data is kept while you have an account. Deleting your account removes your portfolio data. Support tickets are anonymised on deletion: the link to your account is removed and attached screenshots are deleted, while ticket history may be retained in de-identified form for traceability. Records required for accounting are kept for seven years, and the consent log is kept as long as needed to demonstrate acceptance of the terms.

4. Recipients and processors

We never sell your data and do not use it for advertising. Where a provider processes data outside the EU/EEA, it happens under lawful transfer mechanisms such as the European Commission's standard contractual clauses.

  • Database, authentication and application hosting (cloud provider in the EU/EEA).
  • Stripe, for payments and subscription management.
  • Market data providers, which receive security symbols but never your holdings or amounts.
  • Email delivery for account messages such as password resets.

5. Your rights

Contact [privacy email] to exercise your rights. You may also lodge a complaint with [supervisory authority].

  • Access to your data and a copy of it.
  • Rectification of inaccurate data.
  • Erasure of your account and portfolio data.
  • Portability — you can export your portfolio to CSV inside the service.
  • Objection to and restriction of processing based on legitimate interest.

6. Cookies and local storage

We use necessary browser storage to keep you signed in (including the “Remember me” choice) and to store language and theme. We do not use third-party advertising or tracking cookies.

7. Product analytics and error logs

Product analytics tells us which features are used; it never profiles your finances. We record a fixed list of events (for example onboarding completed, a buy plan generated, a simulation run) together with your user id, a timestamp and technical counters such as a step number. We never send company names, tickers, portfolio value, transaction amounts, share counts, cash, prices or free text to analytics — this is filtered out in the client before the event is stored.

Analytics data is stored in our own database inside the EU/EEA and is not shared with ad networks or third-party analytics providers. The legal basis is our legitimate interest in improving the service; you may object as described in section 5. Figures in product dashboards are shown aggregated and small groups are suppressed so individual users cannot be identified. A small number of authorised administrators can additionally see account-level metadata — such as a masked email, country, plan and portfolio/holding counts — for support and product operations, but never portfolio values, transaction amounts or individual holdings.

Technical error logs are kept separate from product analytics. An error log contains the error message, the page, the build version and browser information — not your portfolio data. For support tickets, extended diagnostics are attached only if you actively opt in.

8. Security

Data is protected with encryption in transit, row-level access control so you can only read your own rows, and separated privileges for administrative operations. Only authorised personnel can access the production environment.

9. Changes

When this policy changes we publish a new version here with a new version date, and notify you in the service when the change is material.