Back to Home
Stocky

Privacy Policy

Effective Date: July 19, 2026

At Stocky, operated by Alejandro Salvatore Vasquez, we are committed to protecting your privacy in full compliance with the European Union General Data Protection Regulation (GDPR). This Privacy Policy explains how we collect, process, and safeguard your data when using our market tracking platform.


Section 1: Data We Collect & Processing Purposes

We process only the minimum amount of personal data necessary to maintain your account and deliver core tracking capabilities:

  • Account Identifiers: Your email address, name, and surname (optional) provided during clickwrap registration to authenticate your access.
  • Subscription Status & Credits: Transaction flags, tier details (Scout, Explorer), and remaining AI usage budget generated through subscriptions.
  • Usage Metadata: Basic logs of query counters and API request speeds to prevent abuse and protect third-party market data lines.

We do not collect or store credit card details, bank information, or payment credentials. All payment processing is handled externally. No actual banking deposits, payments, or wallets are integrated into the platform for fund holding. Any cash positions or transactions entered by the user are stored purely as virtual ledger values for portfolio weight calculations.

Section 2: Integrations & Third-Party Processors

To deliver an advanced, real-time workspace, Stocky integrates secure third-party processors. Each service is fully GDPR-compliant:

2.1 Payments: Stripe & Link

All checkout flows, card transactions, and billing management are executed by our payment processor, Stripe, Inc. (and Stripe Managed Payments/Link). By initiating an upgrade, your billing email, payment details, and subscription parameters are processed securely by Stripe under their privacy policies.

2.2 Platform Infrastructure: Firebase

We use Google Cloud Firebase for secure user authentication and profile management. Account passwords are managed directly by Firebase Authentication, completely hidden from us.

2.3 Market Data: Financial Modeling Prep (FMP)

FMP provides our raw equity feeds. No personally identifiable user data is shared with FMP. We retrieve cached bulk data through secure server environments to prevent exchange tracking of individual user preferences.

2.4 User Files & Storage Processing

Any files, spreadsheets, and research documents that you upload are stored securely in private cloud storage containers managed directly by Firebase Storage. Content within these documents is read by AI processing integrations (which may include Google Gemini, OpenAI, or Anthropic models) only when you explicitly request it during an active session (e.g. asking the AI assistant to analyze a specific document). At all other times, your files remain in inert storage. Crucially, all integrations with our AI providers utilize secure, developer-grade API channels whose data privacy terms strictly prohibit using your files, queries, or chat histories for training machine learning models.

Section 3: Cookie-less Architecture & Local Browser Storage

Stocky is built on a privacy-first, cookie-less architecture. We do not utilize invasive tracking cookies, third-party analytics trackers (such as Google Analytics or Segment), or target advertising scripts. We utilize local browser storage (such as localStorage or session tokens) solely for essential functional state management (saving your light/dark mode preference, display currency selection, active login sessions, and timezones). Because we do not store tracking or non-essential cookies, no cookie consent banner is required or displayed on our platform.

Section 4: Data Security, Retention & Transfer

4.1 Secure Cloud Infrastructure

Your account profile and metadata are stored inside secure Google Cloud Firebase servers hosted in EU cloud server zones (primarily Frankfurt/Belgium). Since we operate out of Italy, all technical security configurations, secure database access models, and administrative policies conform fully to European data protection regulations.

4.2 Data Transfers & AI Local Processing

Your AI queries, document vault contents, and chat histories are processed strictly within the European Economic Area (EEA) using Google Cloud Vertex AI / Gemini API endpoints hosted in EU cloud server zones (primarily Frankfurt/Belgium). Your investment data never leaves the EEA for AI inference. Processing your subscriptions through Stripe, however, may require secure routing of basic billing profile details to Stripe servers outside the EEA (primarily the United States). To guarantee a level of protection equivalent to that of the EEA, Stripe transfers are executed under rigorous regulatory safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, and the EU-U.S. Data Privacy Framework.

4.3 Data Retention Periods

We retain your personal data (name, email, portfolio watchlists, and files) only for as long as your account is active. When you delete your account or request account termination, all active database records, portfolio logs, and uploaded files in your Files section are deleted immediately from active servers. Data in system backups is purged automatically within 90 days. Please note that transactional billing records are maintained longer to comply with statutory commercial record-keeping and tax retention requirements under Italian law.

Section 5: Your GDPR Rights & Supervisory Authority

5.1 Personal Rights

Under GDPR rules, you possess absolute, non-negotiable rights over your personal data:

  • Right to Access: You can request a summary and file copy of all account parameters we hold.
  • Right to Rectification: You can modify your name, password, or preferences at any time inside the app's Account tab.
  • Right to Erasure (Right to be Forgotten): You can permanently delete your user profile and active billing links by requesting account termination.
  • Right to Data Portability: You can request a machine-readable JSON bundle of your profile.

5.2 Right to Lodge a Complaint

If you believe that the processing of your personal data infringes GDPR rules, you have the statutory right to lodge a complaint with a supervisory authority. In Italy, the competent authority is the Garante per la protezione dei dati personali, located at Piazza Venezia 11, 00187 Rome (official website: www.garanteprivacy.it).

Section 6: Contact Information & Legal Entity

If you have questions regarding this policy, want to exercise your rights, or require data deletion assistance, please contact the controller:

Alejandro Salvatore Vasquez
Via Valle Scrivia 14, 00141 Rome, Italy
Partita IVA: IT04027981200
REA: RM - 1791774
Email: support@stockyexplorer.com

Stocky Stocky

Alejandro Salvatore Vasquez · Via Valle Scrivia 14, 00141 Rome, Italy · P.IVA: IT04027981200 · REA: RM - 1791774

support@stockyexplorer.com

© 2026 Stocky. All rights reserved.