Privacy Policy
Effective Date: [September 04, 2025]
INTRODUCTION
Finkipedia ("we," "us," "our," or the "Platform") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our financial research platform at www.finkipedia.com (the "Service").
This Policy applies to all users globally and includes specific provisions for:
- Canadian users (PIPEDA compliance)
- European Union users (GDPR compliance)
- California users (CCPA compliance)
- Other international users
By using Finkipedia, you consent to the data practices described in this Privacy Policy.
1. INFORMATION WE COLLECT
1.1 Information You Provide Directly
#### Account Information
- Email address (required)
- Username (optional)
- Password (encrypted)
- Full name (optional)
#### Payment Information (Pro/Premium Users)
- Processed directly by Stripe - we do NOT store:
- Credit card numbers
- Banking information
- Full billing details
- We only retain:
- Last 4 digits of card
- Card type
- Billing postal code
- Subscription status
#### Communications
- Support inquiries
- Feedback and suggestions
- Survey responses (optional)
1.2 Information Collected Automatically
#### Usage Data
- Pages viewed and features used
- Search queries for stocks/companies
- Time spent on pages
- Click patterns and interactions
- AI research assistant queries (Pro/Premium)
#### Technical Data
- IP address
- Browser type and version
- Device type (desktop/mobile/tablet)
- Operating system
- Time zone setting
- Language preferences
- Screen resolution
#### Cookies and Tracking Technologies
- Session cookies (essential for login)
- Preference cookies (language, display settings)
- Analytics cookies (Google Analytics)
- Performance cookies
See our Cookie Policy for details.
1.3 Information From Third Parties
- Stripe: Payment confirmation and subscription status
- Public Data Sources: Financial statement data (not personal information)
1.4 Information We Do NOT Collect
- Personal financial information (bank accounts, investment portfolios)
- Social Security/Insurance numbers
- Investment history or positions
- Personal income or net worth
- Sensitive personal information (health, religion, political views)
2. HOW WE USE YOUR INFORMATION
2.1 Primary Purposes
- Service Delivery: Provide access to financial research and analysis
- Account Management: Maintain your account and subscription
- Communication: Send service updates and respond to inquiries
- Improvement: Enhance platform features and user experience
- Security: Protect against fraud and unauthorized access
- Legal Compliance: Meet regulatory obligations
2.2 Specific Use Cases
#### All Users
- Display relevant financial data and research
- Save preferences and settings
- Provide customer support
- Send critical service announcements
- Ensure platform security
#### Registered Users
- Manage account and authentication
- Track subscription status
- Provide personalized features
- Send account-related emails
#### Pro/Premium Users
- Process payments via Stripe
- Provide premium features
- Priority support
2.3 AI and Algorithmic Processing
- Your searches and interactions help improve our algorithms
- We analyze aggregate usage patterns (not individual behavior)
- AI models do not train on personal information
- Research queries are processed but not linked to identity
2.4 Marketing Communications (Opt-in Only)
With your explicit consent, we may send:
- New feature announcements
- Educational content about markets
- Platform tips and tutorials
You can opt-out at any time
3. LEGAL BASIS FOR PROCESSING (GDPR)
For EU/UK users, we process your data based on:
3.1 Contract Performance
- Account creation and management
- Subscription services delivery
- Customer support
3.2 Legitimate Interests
- Improving our services
- Fraud prevention and security
- Analytics (with opt-out available)
3.3 Consent
- Marketing communications
- Optional cookies
- Newsletter subscriptions
3.4 Legal Obligations
- Tax records
- Regulatory compliance
- Law enforcement requests
4. HOW WE SHARE YOUR INFORMATION
4.1 We Do NOT Sell Your Personal Information
We never sell, rent, or trade your personal information to third parties.
4.2 Service Providers
We share limited information with:
- Stripe (payment processing)
- Amazon Web Services (hosting)
- Google Analytics (anonymized analytics)
- SendGrid (email delivery)
- Cloudflare (security and performance)
All service providers are:
- Contractually obligated to protect your data
- Prohibited from using your data for other purposes
- Required to comply with applicable privacy laws
4.3 Legal Disclosures
We may disclose information if required by:
- Court order or subpoena
- Law enforcement request (with proper legal basis)
- Regulatory investigation
- To protect our legal rights
- To prevent fraud or security threats
4.4 Business Transfers
If Finkipedia is acquired or merged:
- Your information would be transferred
- We would notify you before transfer
- New entity would be bound by this Privacy Policy
4.5 Aggregate Information
We may share anonymized, aggregate data that cannot identify you:
- Platform usage statistics
- Market research trends
- General demographic information
5. DATA RETENTION
5.1 Retention Periods
- Account Data: Duration of account + 3 years (legal/tax requirements)
- Payment Records: 7 years (tax and accounting requirements)
- Usage Logs: 24 months
- Marketing Data: Until consent withdrawn
- Cookies: Variable (see Cookie Policy)
5.2 Account Deletion
When you delete your account:
- Personal information deleted within 30 days
- Some data retained for legal obligations
- Anonymized aggregate data may be retained
- Backup systems may retain data for 90 days
6. DATA SECURITY
6.1 Security Measures
We implement industry-standard security including:
- Encryption in transit (TLS/SSL)
- Encryption at rest for sensitive data
- Secure password hashing (bcrypt)
- Regular security audits
- Access controls and authentication
- Regular software updates and patches
- DDoS protection via Cloudflare
6.2 Your Security Responsibilities
- Use strong, unique passwords
- Keep login credentials confidential
- Report suspicious activity immediately
- Log out from shared devices
6.3 Breach Notification
If a data breach occurs:
- Affected users notified within 72 hours
- Regulatory authorities notified as required
- Mitigation steps communicated
- Support provided to affected users
7. YOUR PRIVACY RIGHTS
7.1 Rights for All Users
- Access: Request copy of your personal data
- Correction: Update inaccurate information
- Deletion: Request account deletion
- Opt-out: Unsubscribe from marketing
- Data Portability: Export your data
7.2 Additional Rights for EU/UK Users (GDPR)
- Restriction: Limit processing of your data
- Objection: Object to certain processing
- Automated Decision-Making: Opt-out of purely automated decisions
- Withdraw Consent: Where processing is based on consent
- Lodge Complaint: With supervisory authority
7.3 Additional Rights for California Users (CCPA)
- Know: Categories and specific pieces of personal information collected
- Delete: Request deletion (with exceptions)
- Opt-Out: Of sale of personal information (we don't sell data)
- Non-Discrimination: Equal service regardless of privacy choices
7.4 Canadian Users (PIPEDA)
- Access: To personal information we hold
- Accuracy: Challenge and correct data
- Accountability: We're accountable for data under our control
- Purpose Limitation: Collection limited to identified purposes
7.5 How to Exercise Your Rights
Email: privacy@finkipedia.com
Response time: Within 30 days (45 days for complex requests)
8. COOKIES AND TRACKING
8.1 Our Cookie-Minimal Approach
Finkipedia is committed to protecting your privacy:
- We only use essential cookies required for Platform functionality
- No tracking cookies are used
- No advertising cookies are used
- No third-party analytics cookies are used
8.2 Essential Cookies We Use
- Session Management: Maintain your login state
- Security: Cloudflare security features
- Authentication: Secure token storage
- Payment Processing: Stripe payment flow (when purchasing)
8.3 Google Analytics (Cookieless Mode)
We use Google Analytics 4 in a privacy-preserving configuration:
- No cookies are set by Google Analytics
- IP addresses are anonymized
- No user profiles or persistent identifiers
- Session-based measurement only
- No cross-site tracking
8.4 Your Control
Since we only use essential cookies:
- No cookie banner is required
- No consent needed for essential operations
- You can still control cookies via browser settings
- Blocking essential cookies may affect Platform functionality
For details, see our Cookie Policy.
9. CHILDREN'S PRIVACY
- Our Service is not directed to children under 18
- We do not knowingly collect data from minors
- If we discover minor's data, we delete it immediately
- Parents may contact us about their child's information
10. INTERNATIONAL DATA TRANSFERS
10.1 Data Location
- Primary servers located in Canada
- Some processing in the United States
- Service providers may be globally located
10.2 Transfer Safeguards
For EU/UK users:
- Standard Contractual Clauses with processors
- Adequacy decisions where applicable
- Appropriate safeguards per GDPR Article 46
10.3 Your Acknowledgment
By using Finkipedia from outside Canada, you consent to data transfer to Canada and other countries where we operate.
11. THIRD-PARTY LINKS
- Our Platform may contain links to third-party websites
- We're not responsible for their privacy practices
- Review their privacy policies before providing information
- Third-party financial data providers have separate terms
12. CHANGES TO THIS POLICY
12.1 Notification of Changes
- Material changes notified via email
- 30 days notice for significant changes
- Updated version posted on platform
- Continued use constitutes acceptance
12.2 Version History
- All previous versions archived
- Changes documented in update log
13. CONTACT INFORMATION
13.1 Data Controller
Finkipedia Inc.
33 Bloor St East 5th Floor,
Toronto, ON M4W 3H1,
Canada
13.2 Contact Methods
Privacy Inquiries: privacy@finkipedia.com
General Support: support@finkipedia.com
Data Protection Officer: dpo@finkipedia.com
13.3 Response Times
- Acknowledgment: Within 48 hours
- Full response: Within 30 days
- Complex requests: Up to 45 days with notice
14. REGULATORY INFORMATION
14.1 Supervisory Authorities
Canada (Federal)
Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, Quebec K1A 1H3
Toll-free: 1-800-282-1376
Website: www.priv.gc.ca
European Union
Users may lodge complaints with their local Data Protection Authority.
List available at: https://edpb.europa.eu/about-edpb/board/members_en
California
California Privacy Protection Agency
Website: https://cppa.ca.gov/
15. CONSENT AND ACKNOWLEDGMENT
By using Finkipedia, you acknowledge that:
- You have read and understood this Privacy Policy
- You consent to the collection and use of information as described
- You are at least 18 years of age
- You understand your privacy rights
For EU Users: Where we rely on consent, you may withdraw it at any time by contacting privacy@finkipedia.com
APPENDIX A: DATA PROCESSING DETAILS
Categories of Personal Data Processed
| Category | Examples | Purpose | Legal Basis |
|----------|----------|---------|-------------|
| Identity | Email, username | Account management | Contract |
| Technical | IP address, browser | Security, functionality | Legitimate interest |
| Usage | Pages viewed, searches | Service improvement | Legitimate interest |
| Financial | Subscription status | Service delivery | Contract |
| Communication | Support tickets | Customer service | Contract |
Data Recipients
| Recipient | Purpose | Location | Safeguards |
|-----------|---------|----------|------------|
| Stripe | Payment processing | USA | PCI DSS compliant |
| DigitalOcean | Server hosting | Canada/USA | SOC 2 compliant |
| Google Analytics | Analytics | USA | Privacy Shield |
| Namecheap | Email services | USA | Industry standard security |
| Cloudflare | CDN & Security | Global | ISO 27001 certified |
APPENDIX B: COOKIE DETAILS
| Cookie Name | Purpose | Duration | Type |
|------------|---------|----------|------|
| session_id | Authentication | Session | Essential |
| preferences | User settings | 1 year | Functional |
| _ga | Google Analytics | 2 years | Analytics |
| _stripe_mid | Payment processing | 1 year | Essential |
This Privacy Policy is effective as of [September 04, 2025] and supersedes all previous versions.
END OF PRIVACY POLICY