In short: we collect the minimum needed to run accounts, licensing, payments and optional alerts. Your watchlists, preferences and any API keys stay on your device. We don’t sell your data. You have full UK GDPR rights and can complain to the ICO.
TickerEyes is designed to be privacy-preserving. Your watchlists, preferences, licence and any API keys you add are stored locally on your device and are not sent to us. We collect the minimum personal data needed to run accounts, licensing, payments and optional alerts.
| Data | Purpose | Lawful basis (UK GDPR) |
|---|---|---|
| Email address | Passwordless sign-in (magic link), licence delivery, cross-device sync | Contract |
| Device fingerprint / device id | Bind a licence to a device; prevent sharing/abuse | Legitimate interests |
| Payment details | Handled by our payment provider (which acts as merchant of record) — we never see or store card numbers | Contract |
| Push subscription (if enabled) | Deliver alerts you opt into | Consent |
| Basic technical logs | Security, abuse-prevention, service reliability | Legitimate interests |
We use trusted third-party providers to run the Service, in the following categories: a cloud hosting and email-delivery provider, and a payment provider. The hosting provider processes data on our behalf under a data-processing contract. The payment provider acts as the merchant of record for your purchase (see our Terms of Service) and is an independent controller of the payment and tax data it collects to charge you and meet its own legal obligations; that handling is governed by its own privacy policy. We do not sell your personal data. You can ask us for details of the specific providers we use by emailing info@tickereyes.com.
Some of our providers may process data outside the UK/EEA. Where they do, we rely on appropriate safeguards: for UK transfers the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, and for EEA transfers the EU Standard Contractual Clauses. You can request details of the transfer destinations and a copy of the safeguards by emailing us.
We keep personal data only as long as needed. In practice: account and licence data for the life of your account and up to 12 months after closure; transaction and tax records for 6 years to meet HMRC and accounting obligations; security and audit logs for up to 12 months. After these periods we delete or anonymise the data. We will action deletion requests subject to those legal minimums.
Under UK GDPR you can request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent for alerts at any time. To exercise these, email info@tickereyes.com; we respond free of charge within one month. Where we rely on legitimate interests (device binding and technical logs) you may object, and we have carried out a legitimate-interests assessment. You can also complain to the Information Commissioner’s Office (ico.org.uk). The Service is not directed at children; we do not knowingly collect data from anyone under 18.
We use local storage only for essential app state (your preferences, licence, session) — exempt from consent under PECR as strictly necessary — and we do not use third-party advertising or tracking cookies. Web-push notifications are sent only if you opt in (your consent) and can be turned off at any time in your browser or device settings. Any consent prompts default to the most privacy-preserving option.
TechProf Ltd (trading as TickerEyes) — info@tickereyes.com. EU users may raise data-protection matters at the same address.