1. Who is responsible for your information
TickerHoof is the controller of personal information used to provide the TickerHoof service.
Privacy contact: support@tickerhoof.com.
2. Information we collect
Account information
- name, email address, public account identifier and account status;
- password hash, email-verification status, MFA configuration and recovery-code status;
- appearance, notification and product preferences.
Security and technical information
- IP address, browser or device details, login times and session records;
- rate-limit records, security events, audit entries and suspected-abuse information;
- cookie, local-storage and similar technology information described in the cookie policy;
- where you consent, Google Analytics information such as pages viewed, referral source, session activity, device or browser type and approximate location.
Subscription information
- plan, subscription status, billing period and Stripe customer or subscription references;
- payment status and limited billing metadata supplied by Stripe;
- we do not intend to receive or store your full card number.
Optional Alpaca information
- encrypted OAuth tokens and provider account identifiers;
- account status, balances, positions and synchronisation metadata made available under the permission you approve;
- TickerHoof does not use the integration to place trades.
Product and support information
- watchlists, saved symbols, feedback, notification history and data-export requests;
- support correspondence and information you choose to provide.
3. Why we use information and our legal bases
- Provide the contract: create and secure your account, deliver subscription features, save preferences and provide requested integrations.
- Legitimate interests: protect accounts, prevent abuse, improve reliability, understand feature use and maintain evidence of system actions, balanced against your rights.
- Legal obligations: retain accounting records, respond to lawful requests and meet applicable tax, consumer and security duties.
- Consent: use optional non-essential storage technologies or send marketing where consent is required. You can withdraw consent for future processing.
5. International transfers
Some providers may process information outside the United Kingdom. Where required, we use an applicable safeguard such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to standard contractual clauses or another lawful mechanism. Provider-specific details are available on request where appropriate.
6. How long information is kept
Retention depends on the purpose, sensitivity, legal requirements and security need. In general:
- account and preference data is kept while the account is active and for a limited closure period;
- verification and password-reset tokens expire quickly and old records are routinely removed;
- session and security records are retained long enough to investigate misuse and protect users;
- subscription and transaction records may be retained for accounting, tax and dispute periods;
- support and audit records are retained according to operational and legal need;
- Alpaca access tokens are deleted or revoked when the connection is removed, subject to backup and security-log cycles.
7. Security
Measures include Argon2id password hashing, MFA, encrypted storage for sensitive integration credentials, CSRF protections, rate limiting, secure session controls, audit records and restricted administrative access. No system is completely secure, so you should use a unique password and protect your authenticator and recovery codes.
8. Your privacy rights
Depending on the circumstances, UK data-protection law may give you rights to:
- be informed and access your personal information;
- correct inaccurate or incomplete information;
- request erasure;
- restrict or object to processing;
- receive certain information in a portable format;
- withdraw consent where processing relies on consent;
- complain to the Information Commissioner's Office.
Rights can be subject to exemptions and identity verification. Email support@tickerhoof.com to make a request. We will not ask you to send a password, MFA code or recovery code.
9. AI and automated processing
TickerHoof models generate market-research observations and confidence information. These outputs concern securities rather than making a decision about your legal rights or access to essential services. TickerHoof does not automatically execute a trade or make a brokerage order on your behalf.
Account security systems may automatically rate-limit requests or temporarily block suspicious activity. You may contact support if you believe a security control has affected you incorrectly.
10. Children
TickerHoof is not intended for anyone under 18. If we learn that an under-18 user has created an account, we may close it and delete information where appropriate.
11. Questions, complaints and changes
Contact support@tickerhoof.com with a privacy question or request.
You may complain to the UK Information Commissioner's Office. We would appreciate the opportunity to address the concern first, but you do not have to contact us before approaching the regulator.
We may update this notice as the service, providers or law changes. Material updates will be highlighted in the service or communicated by email where appropriate.