Privacy policy

What we collect, why we collect it, and how to make us delete it. Short version: your holdings are yours, and nobody buys them from us.

Last updated 28 August 2026


Who is responsible

Beka Tomashvili (trading as StoxDeck) is the data controller for information collected through stoxdeck.com and app.stoxdeck.com. Registered address: Anna Politkovskaya Street N 50, Building 2, Tbilisi, Georgia. Contact us about anything on this page at support@stoxdeck.com.

What we collect

Only what the product needs to work:

  • Your email address — it is how you sign in and how we confirm the account is yours.
  • Your password, hashed — stored as a scrypt digest, never as text. We cannot read it, and nor can anyone who obtains a copy of the database.
  • The transactions you enter — ticker, quantity, price, and date, plus the company name from the symbol you picked.
  • Your watchlist — the symbols you have bookmarked.
  • Session records — so you stay signed in. We store a SHA-256 hash of the session token, never the token itself, so a database leak cannot be replayed as a live login.
  • Billing records — your Paddle customer and subscription identifiers, status, and the billing email, mirrored from Paddle so we know whether your account is on Pro.

We do not collect your name, address, phone number, date of birth, or any financial account credentials. StoxDeck never connects to a brokerage and never asks for one’s login.

What we do not do

  • We do not sell or rent your data to anyone, for any price.
  • We do not run advertising trackers or third-party ad pixels.
  • We do not use your holdings to trade, to build a market data product, or to profile you.
  • We do not send marketing email you did not ask for. Account email is transactional — address confirmation and the like.

Cookies

One cookie, stoxdeck_session. It holds a random session token, is HttpOnly so page scripts cannot read it, is SameSite=Lax, is sent only over HTTPS in production, and expires after 30 days. It exists solely to keep you signed in, so there is no consent banner — a strictly necessary cookie does not need one.

Signing out deletes it and invalidates the session on the server, so the cookie is worthless afterwards even if it were copied.

Analytics

The site uses Vercel Analytics, which counts page views without cookies and without building a cross-site profile of you. It tells us which pages people read. It does not tell us who you are.

Who else processes your data

These are our subprocessors. Each one receives only what its job requires.

ServiceWhat it doesWhat it sees
MongoDB AtlasHosts the database holding your account and transaction records.Account, transactions, watchlist, sessions
VercelHosts and serves both the website and the application.Request logs, IP address, aggregate page analytics
PaddleMerchant of record. Takes payment, issues invoices, handles tax, and runs the billing portal.Name, email, billing address, payment details, purchase history
FinnhubSupplies market prices and symbol search results.Ticker symbols only — never anything identifying you
ResendDelivers account emails, such as address confirmation.Email address, message content
CloudflareTurnstile checks that the contact form is not being used by a bot.IP address, browser signals

Worth calling out: the market data provider is sent ticker symbols only. It is asked what NVDA costs. It is never told who is asking, or how many shares they hold.

Payments

Paddle acts as merchant of record and handles the entire checkout. Your card details go to Paddle and never touch our servers — we could not store them if we wanted to. Paddle collects the billing information it needs to charge you and to calculate tax, under its own privacy policy. We receive back only the identifiers and subscription status needed to unlock your account.

How long we keep things

  • Account and transactions — until you delete the account.
  • Sessions — 30 days, then removed automatically by the database.
  • Email confirmation tokens — deleted automatically once used or expired.
  • Billing records — kept for as long as tax and accounting law requires, typically several years, even after an account is deleted. This is a legal obligation rather than a choice.
  • Cached market prices — discarded within a day. They are prices, not personal data.

Deleting your account

Your profile page has a delete control. Using it removes your account record, your entire transaction history, and every active session, and signs you out everywhere immediately. It cannot be undone, and we cannot recover the data afterwards.

Billing records are the exception described above: they are retained to satisfy tax law, and are not used for anything else. If you would like deletion confirmed in writing, email support@stoxdeck.com.

Your rights

If you are in the UK, the EU, or another jurisdiction with equivalent law, you can ask us to give you a copy of your data, correct it, delete it, restrict how it is used, or object to that use. Email support@stoxdeck.com and we will respond within 30 days. There is no charge, and asking costs you nothing else either — we will not treat the account differently for it.

You also have the right to complain to your local data protection authority if you think we have handled your data badly. We would rather you told us first so we can fix it.

Security

Passwords are hashed with scrypt. Session tokens are stored only as hashes. Traffic runs over HTTPS. Market data and payment credentials are held server-side and never exposed to the browser. Database access is restricted and every query is scoped to the signed-in account, so one account cannot read another’s.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authority as the law requires.

Children

StoxDeck is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has created an account, tell us and we will remove it.

International transfers

Our subprocessors operate internationally, so your data may be processed outside your country, including in the United States. Where that involves transferring personal data out of the UK or EEA, it is done under the safeguards those regimes require, such as standard contractual clauses.

Changes

If this policy changes materially, we will email account holders before it takes effect. The date at the top always reflects the current version. See also our terms of service and refund policy.