Privacy notice
- We hold your email address, a hash of your password, a display name, and whatever you type into the app: tickers, share counts, prices, dates, labels, alert rules and journal notes.
- We never connect to a broker or a bank, so we hold no account numbers, no credentials, and no balance you have not typed in yourself. An account you create carries the name and account type you entered, and nothing is ever fetched from an institution or checked against one.
- We do not sell or share your data. There are no advertisers, no data brokers and no analytics vendors involved, and this site makes no third-party requests at all.
- The live database is not encrypted at rest, so the operator can read the rows you store. The offsite backups are encrypted.
1. Who we are
iVest Group operates StockIQ and is the data controller for the personal data described in this notice. This notice covers the public marketing pages and the StockIQ application behind sign-in.
For anything about privacy or your data, email [email protected]. Please put the word "privacy" in the subject line so it is routed correctly. We have not appointed a Data Protection Officer; we are not required to.
2. What we collect
Everything below is either typed in by you, produced automatically by your browser making a request to our server, or generated by us to run your account. We buy no data, we enrich nothing from third parties, and we run no trackers.
| Category | Exactly what | Source |
|---|---|---|
| Account data | Email address; a salted one-way hash of your password; a display name and avatar you choose; whether the address has been confirmed; the marketing preference you set at signup; the timestamps at which the account was created, accepted these terms, and last signed in to; the IP address the account was created from. | You, except the signup IP address, which comes from your browser |
| Account security tokens | Two kinds of short-lived, single-use token: one that confirms your email address, one that resets a forgotten password. Each is stored only as a SHA-256 hash of the value we emailed you, never in the clear, alongside the time it was issued, the time it expires and the time it was used. | Generated by us when you sign up or ask for a reset |
| Content you create | Ticker symbols, share counts, purchase and sale prices, transaction dates, portfolio labels, cash amounts you type, alert rules and their thresholds, watchlist entries, and trading journal entries including any CSV you import into the journal. | You |
| Usage and security data | Session records; the IP address and user agent recorded in the audit log; login and failed-login timestamps; the URL, status code and time of each request in the web server access log. | Your browser, automatically |
| Communications | Emails you send us and our replies. | You |
Your password itself is never stored and never logged, and it cannot be recovered from the hash. If you forget it, ask for a reset from the sign-in page: we email a link that is valid for one hour and can be used once, and using it signs the account out of every session. The confirmation link sent when you sign up is likewise single-use and is valid for 24 hours. Neither token is stored in a form we could read or reuse — only the hash of it is kept, and only for the period in section 6.
What you have to give us
An email address and a password are required to open an account: they are how you sign in and how we reach you, so without them no account can be created and the contract cannot be performed. Nothing else is required. Every other category above is either produced by your browser making a request, generated by us to run the account, or optional — the app works with none of your holdings, labels, alerts or journal entries in it, and the marketing box is unticked until you tick it.
There is no per-user Telegram destination. You do not supply a chat identifier and we do not store one. Alerts are posted to a single channel operated by us, which means the alert text — the ticker it concerns and the condition it met — is visible to the operator and passes through Telegram's servers. Per-user delivery is not built.
Payment data
None is held today, because paid plans are not currently available for purchase. When they are, card details will be collected by a payment provider directly and we will hold only a payment reference and the country needed for VAT. This notice will be updated before that happens.
3. What we deliberately do not collect
This list is not aspirational. There is no field for any of it anywhere in the system.
- Your legal name. The display name is free text and can be anything, including nothing recognisable.
- Your postal address.
- Your date of birth.
- Your National Insurance number, or any other government identifier.
- Bank account numbers, sort codes, brokerage account numbers or client reference numbers.
- Credentials for any other service: a broker login, a bank login, an API key, an OAuth token, a one-time code. There is no credential store in the product.
- Any balance, holding or transaction you have not typed in or imported yourself.
- Special category data as defined in Article 9 UK GDPR: health, ethnicity, religion, political opinion, sexual orientation, biometrics, trade union membership.
- Precise location, device identifiers, contact lists, or any data from advertising or analytics networks — we run none.
What we do not connect to, and what that leaves
StockIQ has no Open Banking connection, no brokerage API key store, no OAuth link to any provider and no read-only account access of any kind. Nothing about your investments is ever retrieved from an institution or verified against one.
What that leaves is what you typed. An account you create in the app carries a name you chose and an account type you picked from a short fixed list, and both are recorded. Neither is fetched from anywhere and neither is checked against anything, so the record identifies an account to you and authenticates nothing to anyone. There is a field for the account name, and you fill it in.
4. Why we process it, and on what lawful basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Running your account and producing the analysis you asked for | Account data; content you create | Contract — Article 6(1)(b) |
| Writing to you about your account while you hold one, which you cannot opt out of: security notices, changes to the terms or to this notice, notices that a trial is about to end or has ended, and a password reset you have asked for | Email address | Contract — Article 6(1)(b) |
| Confirming that the address on an account belongs to you, and proving that a password reset was asked for by the account holder | Email address; the hashed confirmation and reset tokens and their timestamps | Contract — Article 6(1)(b); legitimate interests — Article 6(1)(f) for the account security part |
| Delivering alerts you have configured | Alert rules; the ticker and condition each one names | Contract — Article 6(1)(b) |
| Keeping the service secure: rate limiting, blocking repeated failed sign-ins, investigating abuse, diagnosing faults | Usage and security data | Legitimate interests — Article 6(1)(f) |
| Refusing a run of accounts opened from the same network in one day | The IP address an account was created from | Legitimate interests — Article 6(1)(f) |
| Marketing email about StockIQ | Email address | Consent — Article 6(1)(a) |
| Meeting tax and accounting obligations, once paid plans open | Payment records | Legal obligation — Article 6(1)(c) |
Our legitimate interests, stated plainly
The interest is keeping a small service running without being overwhelmed by credential-stuffing, bulk account creation and automated abuse. The data used is the minimum that makes that possible — an IP address, a user agent, a timestamp, and the record that a confirmation or reset link was issued and whether it was used. It is kept for the periods in section 6, which are not all the same: twelve months for the audit log, and, for the address an account was opened from, as long as the account itself. None of it is used to build a profile of you, none of it is used to market to you, and none of it is combined with the content of your portfolio. You can object to this processing: section 11, item 7 sets out that right and how to exercise it.
Marketing
Creating an account does not subscribe you to marketing. The signup form carries a separate box for it, unticked by default, and the address goes to a separate list. It is opt-in, and you can withdraw consent at any time, either from the unsubscribe link in the message or by emailing us. Withdrawing consent does not affect processing carried out before you withdrew it, and it does not stop the service email described above, which is part of running the account.
5. Cookies
StockIQ sets one cookie, only after you sign in, and it is strictly necessary. The reverse proxy in front of the site can set strictly necessary security cookies of its own. There are no advertising, analytics or cross-site tracking cookies, and therefore no consent banner. The detail is on the cookie policy.
6. How long we keep it
| Data | Retention |
|---|---|
| Account data and the content you create | For the life of the account. Closing an account marks it inactive; it does not remove the rows. Erasure is carried out by hand when you ask for it, and completed within 30 days of the request. |
| The IP address an account was created from | It sits on the account record, so it lasts as long as the account does. That is longer than the 12 months the audit log keeps an address for. |
| Session records | Until the session expires — 7 days idle, 30 days absolute. Expired sessions are purged by a nightly job. |
| Email confirmation and password reset tokens | A confirmation link expires after 24 hours and a reset link after one hour. The hashed row is kept for 30 days after that expiry, so that a question about a link which did not work can be answered, and a nightly job then deletes it. |
| Audit log entries (sign-in events, IP address, user agent) | 12 months, then deleted. |
| Web server access logs | No more than 30 days. |
| Support and enquiry email | 24 months from the last message in the thread. |
| Encrypted backups | A rolling window of 14 daily, 8 weekly and 12 monthly snapshots. Nothing is kept beyond 12 months. |
7. Who else sees it
Four processors run the service: IONOS, Cloudflare, Brevo and Backblaze. They act on our instructions under a contract that meets Article 28 UK GDPR, and none of them is permitted to use your data for their own purposes.
Telegram is an independent messaging service, not a processor acting for us: there is no Article 28 contract with it and we do not claim one. What we do is publish a message to a channel we run. The paragraph under the table sets out what reaches it.
| Who | What they do | Where |
|---|---|---|
| IONOS SE | Hosts the virtual server the application and database run on | European Economic Area |
| Cloudflare, Inc. | DNS, reverse proxy and protection against denial-of-service attacks. Sees the IP address, user agent and requested URL of every visit | United States, with a global edge network |
| Brevo (Sendinblue SAS) | Mail relay, for three separate things. Email you send to our contact address and our replies pass through it. Account email is sent through it: the address confirmation, the password reset link, and the notices telling you a trial is about to end and has ended. Marketing email, if you opted in to it, is sent through it as a separate list with its own unsubscribe. Account email is a service message about your account and carries no unsubscribe, because you cannot opt out of your own password reset | European Economic Area |
| Backblaze, Inc. | Holds the offsite backup copy. The data is compressed and encrypted before it leaves our server, so they hold ciphertext and no key | United States |
| Telegram Messenger (not a processor) | An independent messaging service we publish alert messages to. Not acting on our instructions and under no Article 28 contract with us. An alert message carries a ticker, the rule that fired, the threshold and the value that met it — no email address, no name and no account identifier | Outside the United Kingdom |
On the Telegram row specifically: alerts go to one channel the operator runs, not to a destination you supply, and nothing that identifies you is put in the message. Somebody reading that channel learns that a rule on a ticker fired. They do not learn whose rule it was, because the message does not say.
Beyond that list: no advertisers, no data brokers, no analytics provider, no affiliate network, no social media pixel. We have never sold, rented or exchanged personal data, and the business model does not need us to — revenue is subscription only.
People working on StockIQ can read the database in the course of operating and repairing it. Access is limited to those who need it. See section 10 for what that means in practice.
We will disclose data where we are legally required to — a court order, or a lawful request from a regulator or law enforcement body. Where we are permitted to tell you, we will.
8. Where your data goes
The server, the database and the on-machine backups sit in the United Kingdom or the European Economic Area. Three arrangements involve data outside it: Cloudflare operates a global network from the United States; Backblaze, a United States company, holds the offsite backup copy, which is encrypted before it leaves our server so they hold ciphertext and no key; and Telegram, which carries alert notifications, operates outside the United Kingdom.
For Cloudflare and Backblaze, where a transfer is to a country the UK has not covered by adequacy regulations, we rely on the International Data Transfer Agreement, or on the UK Addendum to the European Commission's standard contractual clauses, together with an assessment of the risks in the destination country. You can ask us for the detail of the safeguard used for any specific transfer.
Telegram is different. There is no transfer agreement with Telegram and none is attached to it here, because there is no processing contract to attach one to: we publish a message to a channel on a service we do not control. What limits the exposure is the content rather than a clause. An alert message names a ticker, the rule that fired, the threshold and the value that met it, and carries no email address, no name and no account identifier, so nothing that identifies you crosses that boundary. Nothing else in the product touches Telegram.
9. Automated analysis and automated decisions
The scores, valuations, screens and rankings in StockIQ are produced automatically. They are computed about publicly listed companies, from public filings and public market data, by exactly the same rules for every user. They are not computed about you. Your holdings are not an input to them, and the output would be identical if your account did not exist.
Because of that, no automated decision is taken about you that produces a legal effect or similarly significantly affects you, and Article 22 UK GDPR does not apply to the analysis. Your data is not used to train machine learning models.
There is one automated decision about you, and it is a security measure: repeated failed sign-in attempts from an IP address cause that address to be blocked temporarily. If you are blocked and believe you should not be, email us and a person will review it.
10. How we protect it, and what we do not claim
What is actually in place:
- All traffic is served over HTTPS. Plain HTTP requests are redirected.
- Passwords are stored as salted one-way hashes using a deliberately slow hashing function. They are never stored or logged in plain text.
- The session cookie is HttpOnly, Secure and SameSite=Lax, with a 7-day idle limit and a 30-day absolute limit.
- The database is not reachable from the internet. Only the web ports are open to the outside world; the database and the authentication service listen on an internal network only.
- Administrative access to the server is by SSH key on a non-default port, with password authentication disabled, root login disabled and a default-deny firewall.
- Repeated failed sign-ins are rate-limited and the source address is banned for an increasing period.
- Email confirmation and password reset links are single-use and short-lived — 24 hours and one hour respectively — and only a SHA-256 hash of the token is stored, so a read of that table cannot be replayed. Completing a reset revokes every existing session on the account.
- Backups are compressed and encrypted with AES-256 before they leave the machine, and the offsite copy is encrypted again by the backup tool. The passphrase is not stored with the data.
The live database is not encrypted at rest. Someone with administrative access to the server can read the tickers, share counts, prices and labels you have entered. Do not type anything into StockIQ that you would not be willing for the operator to see.
Two-factor authentication is not offered yet. Your password is the only factor, so use one that is long and unique to this service.
No system is immune to compromise. A breach here would expose email addresses, password hashes and the positions you typed in. It could not expose a brokerage account, because none is connected — that is a smaller blast radius than a linked account, not an absence of risk.
11. Your rights
Under UK GDPR you have the following rights. Some of them apply only in particular circumstances, which are noted.
- To be informed. To know what we do with your data and why. This notice is how we discharge that; if something in it is unclear, ask and we will explain it.
- Of access. To get a copy of the personal data we hold about you, together with the supporting information in this notice. Email us and we will send a machine-readable export of your account and its contents.
- To rectification. To have inaccurate data corrected and incomplete data completed. Most of it you can edit yourself in the app; for anything you cannot reach, email us.
- To erasure. To have your data deleted where we no longer need it, where you withdraw the consent it relied on, or where you object and we have no overriding ground to continue. Closing your account marks it inactive rather than erasing it; ask us to erase it and we will, within 30 days of the request, subject to the backup window in section 6. Two things are outside that: the sign-in audit records, which we keep for the 12 months in section 6 on the legitimate-interests ground in section 4 so that repeated attacks can still be blocked, and support email, kept for 24 months from the last message in the thread. Both age out on their own schedule. You can object to the audit retention under item 7 and we will consider it on its merits.
- To restrict processing. To have us store your data but stop using it — for example while you contest its accuracy, or while an objection is being considered.
- To data portability. To receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where that is technically feasible. We provide it as CSV or JSON.
- To object. To object to processing based on legitimate interests, including the security processing in section 4. You have an absolute right to object to direct marketing, and we will stop immediately.
- Relating to automated decision-making and profiling. Not to be subject to a solely automated decision with legal or similarly significant effects. As section 9 explains, we do not take one — but the right stands, and the security block described there can be reviewed by a person on request.
Separately, where processing relies on consent you may withdraw that consent at any time under Article 7(3), as easily as you gave it.
How to exercise them
Email [email protected] from the address on your account. If you write from a different address we will ask you to verify the account another way, because handing your data to the wrong person is the worse failure.
We respond within one calendar month. If a request is complex or you have made several, we may extend that by up to two further months, and we will tell you within the first month if we do. Requests are free. We will only charge, or refuse, if a request is manifestly unfounded or excessive, and we will explain why if that happens.
12. Complaining to the regulator
If you think we have handled your data badly, please tell us first — we would rather fix it. You do not have to, and you can complain to the Information Commissioner's Office at any time. Complaining to the ICO does not affect any other legal remedy you have.
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113
ico.org.uk
13. Children
StockIQ is not intended for children. You must be 18 or over to open an account. We do not knowingly collect data from anyone under 18; if we find that we have, we delete it.
14. Changes to this notice
The date at the top of this page is the date of the current version. If we change something material — a new purpose, a new processor, a new category of data, a longer retention period — we will email account holders and post a notice in the app at least 14 days before the change takes effect. Minor corrections are made without notice and the date is bumped.
The terms of service and the cookie policy sit alongside this notice. A plain-English summary of the privacy design, with the reasoning behind it, is on the privacy and security page.