Privacy Policy — Defense Invest
Draft — Last updated: [DATE]
⚠️ This is a working draft prepared with AI assistance, not a legal document reviewed by a lawyer. If you serve users in the EU/EEA, UK, or California, GDPR / UK GDPR / CCPA impose specific binding requirements (legal basis for processing, data subject rights, breach notification timelines, a Data Processing Agreement with Supabase/Lovable as sub-processors, etc.) that this draft does not fully implement. Have this reviewed before publishing.
1. What data we collect
Account data: email address and password (stored securely via Supabase Auth; passwords are hashed, never stored in plain text).
Usage data: pages visited, features used (search, filters, favorites), and timestamps, collected via our internal analytics system for the purpose of understanding product usage. See Section 4.
Content you create: tickers you flag as favorites, any custom notes or context edits you make within the Service.
We do not collect: payment card details directly (if/when a paid subscription is introduced, this will be handled by a third-party payment processor such as Stripe, which will have its own privacy policy).
2. How we use this data
- To provide and operate the Service (authentication, displaying your favorites, personalizing your experience).
- To monitor and improve the Service (aggregate usage analytics).
- To communicate with you about your account or the Service (e.g., service updates, security notices).
- [IF/WHEN PAID SUBSCRIPTIONS ARE INTRODUCED: to process payments and manage your subscription, via our payment processor.]
We do not sell your personal data to third parties.
3. Legal basis for processing (EU/EEA/UK users)
[TO CONFIRM WITH COUNSEL] Processing is generally based on: performance of a contract (providing the Service you signed up for), and our legitimate interest in operating and improving the Service. Where required, we will seek your consent (e.g., for optional analytics or marketing communications).
4. Analytics
We track page views and key interactions (e.g., searches performed, filters used) associated with your account, to understand how the Service is used and improve it. This data is accessible only to the Service operator via a restricted internal dashboard. [NOTE: the current build also allows anonymous/pilot access without a named account — if this persists into a commercial launch, this section must be updated to describe how anonymous sessions are tracked and for how long.]
5. Third-party data processors (sub-processors)
We rely on the following third-party infrastructure providers, who may process data on our behalf:
- Supabase (database, authentication, hosting)
- Lovable (application platform)
- [Payment processor — TO BE ADDED once selected, e.g. Stripe]
Each of these providers has its own privacy and security practices; links to their policies will be added here.
6. Data retention
- Account data is retained for as long as your account is active.
- Analytics data is retained for [PERIOD TO BE DEFINED, e.g. 12 months] before aggregation or deletion.
- Upon account deletion request, we will delete or anonymize your personal data within [PERIOD TO BE DEFINED], except where retention is required by law.
7. Your rights
Depending on your location, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at [CONTACT EMAIL — TO BE DETERMINED]. [TO CONFIRM WITH COUNSEL: EU/UK users have specific statutory rights under GDPR that must be listed explicitly and with defined response timelines (typically 30 days).]
8. Security
We take reasonable technical and organizational measures to protect your data (encrypted connections, hashed credentials, access controls). No system is completely secure, and we cannot guarantee absolute security.
9. International data transfers
[TO CONFIRM WITH COUNSEL: if the Service's infrastructure (Supabase/Lovable) stores or processes data outside the EU/EEA for EU users, this requires an appropriate transfer mechanism — e.g. Standard Contractual Clauses — to be documented here.]
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified to you via the Service or by email.
11. Contact
Questions about this Privacy Policy or your data: [CONTACT EMAIL — TO BE DETERMINED]