Profit Alerts
Home Features How it works Pricing FAQ
Sign in Start free
Back to home
Privacy

Privacy Policy

Last updated May 31, 2026 ~4 min read 10 sections

Contents

  1. Information We Collect
  2. How We Use It
  3. App Permissions
  4. Data Sharing
  5. Data Retention
  6. Security
  7. Your Rights
  8. Cookies
  9. Children
  10. Contact
Our commitment: Profit Alerts only collects data necessary to deliver the service. We never sell your personal information to third parties.
01

Information We Collect

Category Data Purpose
AccountEmail address, hashed passwordAuthentication
PreferencesWatchlist tickers, direction filter, languagePersonalized dashboard
DeviceFCM push token, platform (iOS/Android)Push notifications
UsagePage visits, hashed IP addressAnalytics, abuse prevention
BillingStripe customer ID, subscription statusPayments (Stripe handles card data)

We do not collect location, contacts, camera, microphone, or any other device sensor data.

02

How We Use Your Information

  • Authenticate your account and maintain your session
  • Deliver personalized market signals and news for your watchlist
  • Send push and email alerts when a watchlist ticker has a high-confidence signal
  • Process subscription payments through Stripe
  • Improve the service and prevent abuse
  • Comply with legal obligations
03

App Permissions

Permission Why Required?
Notifications Send real-time market alerts for your watchlist tickers Optional
Internet Load market news, signals, dashboard data, and account sync Required
Vibration Haptic feedback when a notification arrives Optional

We never request access to location, camera, microphone, contacts, storage, or biometric data.

04

Data Sharing

We do not sell your personal data. We share data only with the following trusted sub-processors:

  • Supabase / PostgreSQL — database hosting (EU/US servers)
  • Vercel — application hosting and serverless functions
  • Stripe — payment processing (PCI-DSS Level 1)
  • Resend — transactional email delivery
  • Firebase (Google) — push notification delivery
  • OpenAI — AI analysis of news headlines (no personal data sent)
05

Data Retention

We retain your account data for as long as your account is active. You may request account deletion at any time by contacting support. Upon deletion, personal data is removed within 30 days. Anonymized analytics data may be retained indefinitely.

06

Security

  • Passwords are hashed with bcrypt (never stored in plain text)
  • All connections use HTTPS / TLS 1.2+
  • Session tokens are signed with HMAC-SHA256
  • API endpoints are protected with CSRF tokens and rate limiting
  • IP addresses are stored as one-way hashes
07

Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access — request a copy of your data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your account and data
  • Portability — receive your data in a machine-readable format
  • Opt-out — disable push and email notifications from settings
08

Cookies

We use only strictly necessary cookies:

  • session — authentication token (httpOnly, Secure)
  • csrf_token — cross-site request forgery protection
  • lang — language preference (en/es)

We do not use advertising, analytics, or tracking cookies.

09

Children's Privacy

Profit Alerts is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately.

10

Contact

Questions about your privacy?

We're here to help. Reach out anytime.

support@profitalerts.app

© 2026 Profit Alerts · Home Privacy Terms Contact