Privacy Policy

EFFECTIVE JULY 25, 2026 · SHAMBURG MARKETS LLC

1. What this covers

This Privacy Policy describes how Shamburg Markets LLC ("we," "us") handles personal information in connection with shamburgmarkets.com, the Shamburg Markets workspace, and the Shamburg Data API and developer console (the "Service").

2. Information we collect

Account information: your email address, password credentials (handled by our authentication provider; we never see your password), and optional profile details.

Content you create: watchlists, portfolios, custom dashboards, screeners, alerts, and preferences, stored so the Service can provide them back to you.

Portfolio information: if you link a brokerage account through Plaid, we receive read-only information such as holdings, balances, and transactions. Your brokerage login credentials are provided directly to Plaid and never touch our servers; Plaid's handling of your information is described in its own privacy policy. If you import holdings by file or enter them manually, we store what you provide.

Usage information: pages and features used in the workspace, and API request counts by key, endpoint, day, and response status, collected to enforce plan limits and gating, operate usage dashboards, bill correctly, and prevent abuse. We do not sell usage data.

Payment information: processed by Stripe. Card numbers are transmitted directly to Stripe and never touch our servers; we retain only subscription status, plan, and invoice records.

3. How we use information

To provide and secure the Service (authentication, gating, rate limiting, abuse prevention); to operate portfolio, watchlist, and alert features; to bill subscriptions; to show you your own usage; to communicate service notices; and to improve the Service using aggregate, de-identified statistics.

4. Sharing

We share information only with the processors that run the Service: Supabase (authentication and account database), Stripe (payments), Plaid (brokerage account linking, where you choose to use it), Vercel (web hosting), and Fly.io (application and API hosting). Each processes data under its own terms as our service provider. We do not sell personal information. We may disclose information if required by law or to protect the Service.

5. Cookies and local storage

The Service stores session tokens and interface preferences in your browser's local storage to keep you signed in and remember your settings. We do not use advertising cookies or third-party trackers.

6. Retention and deletion

Account data and content you create are retained while your account is active. Usage records are retained for billing and audit purposes. You may request deletion of your account and associated personal information by contacting us; some records (e.g., invoices) may be retained where legally required. Unlinking a brokerage account stops further collection through Plaid.

7. Security

API keys are stored only as cryptographic hashes. Transport is encrypted (TLS) everywhere. Access to production systems is limited and credentialed.

8. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal information, or to object to certain processing. Contact us to exercise them.

9. Children

The Service is not directed to individuals under 18, and we do not knowingly collect personal information from them.

10. Changes and contact

We will post updates to this policy here and note the effective date. Contact: support@shamburgmarkets.com.