Legal
Privacy Policy
In force from August 11, 2026. Version 2026-08-11, the same version string recorded against your account when you accepted it.
This policy is specific because a vague privacy policy is a bad sign in a product that asks you to trust its numbers. Every field, purpose, processor and retention period below was read out of the code and the schema, not adapted from a template.
If you want only the essentials, read clause 2 and clause 10.
1Who holds your data, and how to reach us
ValueMarkers is operated by Attitude Ventures LLC, a limited liability company formed in Delaware, United States. That company is the controller of the personal data described in this policy. Its registered agent for service of process is A Registered Agent, Inc., 8 The Green, Ste A, Dover, DE 19901, United States.
Write to legal@valuemarkers.com for anything in this policy: a copy of your data, a correction, deletion, an objection, or a question. A person reads that mailbox. For everyday product problems, use hello@valuemarkers.com.
2The short version
We sell a research subscription for money. That is the whole business model, so we have no reason to collect more about you than the product needs. We hold your account details, what you write in the product, a record of what we billed and what we emailed you, and server logs. We do not sell personal data, we run no advertising, we load no analytics or tracking scripts on this site, and there is no consent banner because there is nothing non-essential to consent to.
If something below is wrong about your account, tell us and we will fix it.
3What we hold
This is the complete inventory of personal data in our own database. Nothing is collected silently that is not listed here.
| Category | Fields | Where it comes from |
|---|---|---|
| Account | Email address, display name, a one-way hash of your password, whether the address is verified, account created and last sign-in times, your time zone if the browser reports a valid one, your light or dark preference, and your preferred markets. | You, at registration and in settings. |
| Acceptance of these documents | The moment you accepted the terms and this policy, the version string you accepted, and the IP address the acceptance came from. | Recorded automatically when you register. |
| How you found us | Your answer to "how did you hear about us", a referral channel, and a referral code if you arrived through one. | You, at registration. Optional. |
| Your research | Theses per company: bull case, bear case, notes on the moat, free notes, conviction, status, entry and target prices, entry date, and the guardrails you set as an indicator, a comparison and a threshold. Watchlists and their items. Saved screens and saved valuation versions. Portfolios you choose to create, with ticker, exchange, number of shares, cost basis, purchase date and notes. | You, in the product. Positions and cost bases are optional; the product works without them. |
| Alerts and inbox | Guardrail breach and recovery records with the value at the time, your in-app inbox items and whether you read them, your per-type email preferences, and a delivery log per notification. | Generated by the nightly checks on the guardrails you set. |
| Billing | Your subscription state and trial dates, the customer and subscription identifiers issued by our payment processor, and a record per payment: amount, currency, status and date. | You and the payment processor. Card numbers never reach us. |
| Email delivery log | One row per message we attempted: the address, the type, the subject, the provider, its message id, whether it was sent or failed, and any error. | Written by our own mailer, so we can prove what we did and did not send. |
| Product use | A per-account event log of actions such as signing in, viewing a company, running a screen, using the valuation workbench, and creating a thesis, with the time and a small amount of context. Used to tell an active account from a dormant one and to decide what to build. | Generated as you use the product. |
| If you cancel | The reason you select and any comment you write, with the date. | You, in the cancellation flow. The comment is optional. |
| Server logs | Request paths, methods, timestamps, status codes, response times and IP addresses. | Generated by the server, for security and debugging. |
3.1What we deliberately do not collect
- No brokerage or bank credentials, and no connection to any brokerage account. There is no field for them and no integration that could ask.
- No card numbers. Card details are entered on our payment processor and never touch our servers.
- No government identifiers, no date of birth, no phone number unless you connect an optional notification channel yourself.
- No special category data: nothing about health, beliefs, politics, ethnicity or sexual life. Do not put such data into a free text field.
- No third-party tracking. We load no analytics, advertising, session-recording or fingerprinting scripts on this site.
4Why we hold it, and on what legal basis
For readers in the European Union, the European Economic Area and the United Kingdom, the legal bases are those in Article 6 of the GDPR.
| What we do with it | Data used | Legal basis |
|---|---|---|
| Run your account: authenticate you, keep you signed in, show you your own work. | Account, research. | Performance of our contract with you. |
| Do the thing the product is for: re-test your guardrails against new data on a schedule, and send you the alert, inbox item and weekly brief that follow. | Research, alerts, account, email preferences. | Performance of our contract with you. |
| Take payment, prevent payment fraud, issue invoices and keep accounts. | Billing, account. | Performance of our contract, and compliance with tax and accounting law. |
| Send transactional email: verification, password reset, receipts, payment problems, cancellation. | Account, billing, email log. | Performance of our contract. |
| Send product email about the tool itself, and the onboarding sequence that follows registration. | Email address, display name. | Our legitimate interest in helping a new subscriber use what they signed up for. Every such message carries one-click unsubscribe, and you can turn each type off in settings. |
| Keep the service secure, investigate abuse, enforce rate limits, and hold evidence of what was agreed. | Server logs, acceptance record, account. | Our legitimate interest in a secure service and in being able to prove the terms of a contract. |
| Understand whether accounts are being used, and decide what to build or fix. | Product use events, aggregate counts. | Our legitimate interest in improving a product we sell. Never combined with data from anyone else and never shared for advertising. |
| Improve the product from what people tell us when they leave. | Cancellation reason and comment. | Our legitimate interest in a better product. Giving a reason is not a condition of cancelling. |
You can object to any processing we base on legitimate interest. See clause 10.
5What we will never do with it
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not disclose it to data brokers.
- We do not use your writing to train machine learning models, and we do not send it to anyone who would.
- We do not show your theses, notes or positions to other users, and there is no public profile.
- We do not build profiles about you for anyone else, and we do not enrich your record from third-party data sets.
- We do not use your data to make decisions about you beyond running the product you paid for.
Two ordinary exceptions, stated plainly. We disclose data where the law compels it, and we will tell you unless we are forbidden to. And if the business is sold or reorganised, the data moves with it, bound by this policy until it is replaced by a policy no less protective; we will tell you before that happens.
6Who processes it for us
These are the only third parties that receive personal data, each under contract, each for one stated purpose. There are no others.
| Processor | What it does | What it receives | Where |
|---|---|---|---|
| Stripe, Inc. | Payments, checkout, invoices, the billing portal, tax calculation. | Your email address, name, billing address and card details, which you give it directly, plus the subscription record. | United States, with global processing. |
| Resend | Delivery of transactional email. | Your email address, name and the content of the message. | United States. |
| Brevo | Delivery of product and onboarding email. | Your email address and name. | European Union. |
| Cloudflare, Inc. | DNS, content delivery, denial-of-service protection, and the encrypted tunnel through which the site is reached. | Request metadata in transit, including your IP address. | Global edge network. |
| Slack Technologies | Internal operational notifications so a small team notices registrations, payments and cancellations. | Your email address and display name, with the event. | United States. |
The market data sources and public statistical agencies we read receive company identifiers only. They are never told anything about you, and they are not processors of your personal data.
7Where your data is held, and transfers out of the EEA
We are unusual here, so it is worth being exact. The application and its PostgreSQL database do not run on rented cloud infrastructure. They run on hardware we own and administer, in our own office in Spain, reachable only through an encrypted tunnel. Your account data and everything you write in the product are therefore processed in the European Union by default.
Some of the processors in clause 6 are established in the United States, so using the service involves transfers there. Those transfers rely on the European Commission standard contractual clauses, with the United Kingdom addendum where it applies, and on the EU-US Data Privacy Framework where the recipient is certified under it. We keep the volume of data that leaves the EEA small by design: what crosses is an email address and a name, the billing record held by the payment processor, and request metadata at the network edge.
The nightly database snapshot is copied to a second server we control so the service can be restored if the office hardware fails. The transfer runs over an encrypted channel.
You can ask us for a copy of the transfer safeguards we rely on. Write to legal@valuemarkers.com.
8How long we keep it
| Data | Kept for |
|---|---|
| Account record and everything you wrote in the product: theses, guardrails, notes, watchlists, saved screens, saved valuations, portfolios. | Until you delete it, or until the account is deleted, whichever comes first. Cancelling does not delete it. |
| Alerts, inbox items, notification preferences and the product use log. | Deleted with the account. |
| Cancellation reason and comment. | Deleted with the account. |
| Billing records: payments, invoices, subscription history. | As long as tax and accounting law requires, normally seven years, even after the account is deleted. We keep the amount, the date and the identifiers, not a card number. |
| The record that you accepted these documents, and which version. | While the account exists, and afterwards only where we need it as evidence of a contract that is still capable of being disputed. |
| Email delivery log. | Kept while the account exists, and kept afterwards only where the entry is still needed to show what we sent or did not send. You may ask us to remove your entries. |
| Server logs. | Rotated every night and kept for about five days of generations, then discarded. Never archived. |
| Database snapshots. | Fourteen days, then overwritten. A deletion is therefore fully worked through the snapshot set within fourteen days. |
| Aggregate page counts. | Indefinitely. They contain no identifier: one row per page per day with a number in it. |
9How we protect it
This list is what we actually do. We claim no certification we do not hold, and no measure we have not implemented.
- Passwords are hashed with bcrypt at twelve rounds and never stored or logged in any recoverable form. We cannot tell you your password because we do not have it.
- Access tokens are short-lived. The longer-lived refresh token is stored on our side only as a SHA-256 hash, is single-use, is rotated on every refresh, and is revoked on sign-out, so a stolen token has a narrow window and cannot be replayed.
- Sign-in is locked out after repeated failures from an address, registration is rate limited, and the API is rate limited per account.
- Traffic is encrypted in transit. The origin server accepts no direct inbound connections from the internet: it is reachable only through an authenticated outbound tunnel.
- Browser requests are accepted only from an explicit allowlist of our own origins, and responses carry hardening headers: no MIME sniffing, no framing, a restrictive referrer policy, no access to camera, microphone or location, and strict transport security in production.
- Text you submit is length-limited and sanitised, request bodies are capped, and queries are parameterised by the data layer, so submitted content cannot be executed as code or SQL.
- The database runs on hardware we administer ourselves rather than a shared managed service, and administrative access to it is limited to the operator of the service.
- Snapshots are taken nightly and transferred over an encrypted channel to a second machine we control.
No system is perfectly secure. If you find a weakness, write to legal@valuemarkers.com and we will take it seriously, act on it, and thank you.
10Your rights, and how to use them
If you are in the European Union, the European Economic Area or the United Kingdom you have the rights below. We extend the same rights to everyone else, because running two standards would be more work than doing it properly once.
- Access. Ask what we hold and get a copy.
- Portability. Get the data you gave us in a machine-readable form. The product exports screener results and portfolio holdings as CSV by itself; for a full copy of the account, ask us and we will assemble it.
- Rectification. Have anything inaccurate corrected. Your name, email, preferences and everything you wrote are editable in the product.
- Erasure. Have the account and its contents deleted, subject to the billing records we must keep for tax law.
- Restriction and objection. Object to processing we base on legitimate interest, including the product use log and the product email sequence, and ask us to restrict processing while a dispute is open.
- Withdraw consent. Where we rely on consent, take it back at any time, with no effect on what was lawful before.
- Complain. Complain to your national data protection authority. In Spain, where the servers sit, that is the Agencia Española de Protección de Datos.
10.1How to exercise them
Write to legal@valuemarkers.com from the address on the account, or from another address if you tell us which account you mean. We may ask a question to satisfy ourselves that the request is really yours; we will not ask for a document you have no reason to send us. We answer within 30 days, and inside one month at the outside as the GDPR requires. There is no charge unless a request is excessive or repetitive, in which case we will say so before doing anything.
Cancelling a subscription is self-serve on the billing page. Deleting the account is not self-serve today, so it goes through that mailbox and a person does it; when we finish building the self-serve version we will say so here. Once done, the account and your research are gone from the live database immediately and out of the snapshot set within fourteen days.
11California residents
This clause is for residents of California and uses the vocabulary of the California Consumer Privacy Act as amended by the CPRA.
We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the past twelve months, and we do not do either today. We do not offer financial incentives for personal information.
11.1Categories involved
Identifiers, such as your name, email address and IP address. Commercial information, such as your subscription and payment history. Internet or network activity, such as the product use log and server logs. Financial information limited to the subscription record; the payment card itself is held by our payment processor and not by us. Everything you write in the product, which is content you chose to create. We do not collect sensitive personal information as that term is defined, and we do not use or disclose personal information for any purpose other than those listed in clause 4.
11.2Your rights
You may ask us to tell you the categories and specific pieces of personal information we hold, the sources, our purposes and the categories of recipients; to delete it; and to correct it. Because we neither sell nor share personal information, and because we do not collect sensitive personal information, the rights to opt out of sale or sharing and to limit the use of sensitive personal information have nothing to operate on, but you may exercise them and we will confirm that position in writing.
Use legal@valuemarkers.com. An authorised agent may act for you with written permission we can verify. We will never deny you service, charge you a different price, or give you a lesser product because you exercised a privacy right.
13Email we send, and how to stop it
Three kinds, and the difference matters.
- Transactional. Verify your address, reset your password, confirm a payment, warn you that one failed, confirm a cancellation. These are part of the service and cannot be turned off while the account exists.
- The service itself. Guardrail breach alerts, earnings notices, the weekly brief. This is what you subscribed for. Every one of these carries a one-click unsubscribe that works without signing in, and each type has its own switch in settings, so you can keep breach alerts and drop the weekly brief.
- Product email. A short sequence after you register that explains how to use the tool, and occasional notes about the product. One click to stop, in any of them.
Unsubscribe links are signed and expire, so nobody can unsubscribe you by guessing a URL. We log every message we attempt, which is how we can tell you exactly what we sent and when. We do not track whether you opened a message in order to build a profile of you.
14Automated processing
The nightly guardrail check is automated: it compares a figure to a threshold you chose and emails you when the comparison fails. Scores and rankings are computed by formula. All of this produces information for you to read, not decisions about you. Nothing in the service makes an automated decision that has a legal or similarly significant effect on you, so the right in Article 22 of the GDPR does not arise. No output about a company is a decision about a person.
15Children
The service is for adults, and the terms require you to be 18. We do not knowingly collect personal data from children. If you believe a child has registered, write to legal@valuemarkers.com and we will delete the account and its data promptly.
16If something goes wrong
If personal data we hold is exposed or lost, we will investigate, contain it, and tell the competent supervisory authority within 72 hours of becoming aware where the law requires it. We will tell affected users directly, without undue delay, where the incident is likely to put them at risk, and we will say what happened, what data was involved, what we did, and what you should do. We would rather tell you early and imprecisely than late and neatly.
17Changes to this policy
When this policy changes materially we email your registered address at least 14 days before it takes effect, and we publish the new text here with a new version string. The version you accepted is recorded against your account, so it is always possible to establish which text applied at a given moment. Corrections that do not change your rights may take effect at once.