Privacy Policy
Last updated: September 19, 2026
Summary in one paragraph
We collect the minimum personal data needed to run the product: your email and password for the account; your name, watchlist, alerts and subscription state for the features that need them. We do not store IP addresses or browser fingerprints to the database, and do not see your payment-card details (Stripe handles them). For product analytics and advertising measurement we use Google Analytics 4 and Google Ads, which set cookies and receive limited usage and conversion data. Our servers also send Meta a hashed version of your email address when you sign up, start a trial, or are charged — hashing is not anonymisation, since Meta matches those hashes against its own records. All of it is detailed in the Cookies and Sub-processors sections below. We do not sell your personal data, and we do share limited advertising-measurement data as described there.
What we collect at signup
- Email address — required. Used for authentication, transactional email (welcome, trial reminders, alerts you’ve opted into), and account recovery. A one-way SHA-256 hash of it is also sent to Meta as a conversion signal — never the address itself. See Sub-processors.
- Password — required, minimum 8 characters. We never store the raw password; only a one-way bcrypt hash that cannot be reversed back to your password.
- Name — optional. Used only to personalise the welcome email and the dashboard greeting.
- Referral code — optional. If you signed up via someone else's referral link, we record which user referred you so we can credit them the referral bonus.
- Cloudflare Turnstile token — bot-challenge response. Verified server-side and immediately discarded after the check.
- Device fingerprint & IP address — used only to rate-limit signups against trial-farming bots. Held in volatile worker memory, never written to the database, and evicted on every backend restart.
What we store while you use the product
- Your tier (Free / Pro / Premium / Lifetime) and trial-end date.
- Your watchlist tickers, alert rules, and any settings you configure.
- Your Stripe customer ID — linked on first checkout. We never receive or store card numbers; Stripe handles all payment data directly.
- Your referral code (your own shareable code) and the count of unused referral credits you've earned.
- An internal drip-email state token list — a comma-separated string like
"3,7,end"that records which lifecycle emails we've already sent so we don't double-send. - Account
created_atandupdated_attimestamps for audit.
What we explicitly do not collect or store
- Payment card numbers — Stripe handles these directly. We only see a
stripe_customer_id. - Bank account details, SSN, passport, or other government IDs.
- Your brokerage credentials or actual portfolio holdings. Tapeline scans the public market — it does not connect to your broker.
- IP addresses in the database. We use them transiently in memory for rate limiting, but we don't persist them.
- Browser fingerprints in the database. Same as IPs — used for in-memory anti-abuse checks, never written down.
- Location or geolocation data.
- We have never sold your personal data and have no arrangement to. Separately — this is its own disclosure, not a footnote to that sentence — we do share limited advertising-measurement data with Google, and would with Meta if we enable it. Some privacy laws, California's among them, treat that kind of ad-measurement sharing as a regulated disclosure distinct from a “sale”, so we name it here rather than leave it to be inferred. What each company receives is itemised under Sub-processors, and the cookies involved are under Cookies.
Sub-processors
These are the third parties whose systems may touch your data when you use Tapeline. Each one is listed with what they see, and whether it is switched on today. Most act only on our instructions. The advertising platforms — Google Ads, and Meta if we enable it — are different: they decide their own purposes for what they receive and may combine it with data they already hold, so treat those two as independent recipients rather than as vendors working for us.
- Stripe — payment processing (PCI DSS Level 1). Sees your email and any billing data you provide directly to Stripe.
- Resend — transactional email delivery. Sees your email, your name (if set), and the message content of emails we send you.
- Cloudflare — DNS, Turnstile bot challenges, and Email Routing for inbound mail to
@tapeline.io. Sees email metadata and the bot-challenge interaction. - Google (Analytics 4 & Google Ads) — usage analytics and advertising measurement (US). Receives page views, in-app events, and signup/subscription conversion signals; sets analytics and advertising cookies (e.g.
_ga,_ga_*,_gcl_*). - Meta (Facebook & Instagram) — advertising measurement. Currently enabled. Meta is not a vendor acting only on our instructions: it decides its own advertising purposes and may combine what it receives with data it already holds about you. There are two separate flows. From our servers: when you create an account, when a trial starts, and when a subscription is charged, we send one event containing a SHA-256 hash of your email address, a hash of our internal account ID, the event name, a timestamp, a de-duplication ID, a currency, and — depending on the event — the amount charged, the plan, or how you signed up. We do not send your raw email address, your name, your IP address, your browser user-agent, or which page you were on. Hashing is not anonymisation: the whole point of sending a hash is that Meta matches it against its own records, so treat this as a disclosure of personal data. From your browser: Meta’s script runs on our public marketing pages only — deliberately never on the signed-in app, so it cannot see which tickers you look at — sets the cookies described under Cookies, and reports each page view. Loading that script tells Meta your IP address, browser and language, and because the request goes to facebook.com your browser may attach Facebook cookies it already holds, which can let Meta link the visit to your logged-in Facebook or Instagram account. That happens between your browser and Meta; we neither see nor store it, and a tracker-blocking extension prevents it.
- PostHog — product analytics. Not currently enabled. It receives your account ID, account tier, and product-usage events to build a per-user product profile, and sets analytics cookies. It is never sent your email address.
- Microsoft Clarity — session replay and heatmaps. Not currently enabled. It records how you move through pages.
- Plausible — privacy-focused traffic analytics. Not currently enabled. It is cookie-less and records no per-person identifier.
- Fly.io — backend hosting in Sydney. Sees the full database state since they host the database.
- Sentry — error tracking. May capture stack traces with limited non-PII context when something breaks.
- Telegram — used only for internal operational alerts to the Tapeline team (for example, a notification when someone signs up or subscribes). Those messages can include your email address. It is no longer offered as a user alert channel.
- Third-party market-data feeds — power the scanner with prices, fundamentals, macro indicators, SEC filings, and news. No user data is sent to any of them. They power the scanner; they never see you.
Cookies
One cookie is strictly necessary: a same-site, HTTP-only, secure session JWT with a 30-day expiry that keeps you signed in. Everything else is optional measurement. Google Analytics 4 and Google Ads are active and set analytics and advertising cookies (for example _ga, _ga_*, _gcl_*). PostHog, Microsoft Clarity and the Meta pixel would each set their own; of those, the Meta pixel is currently enabled.
Meta's script sets _fbp on every visit — a browser identifier lasting roughly 90 days — and _fbc when you arrive on a link carrying Meta’s click identifier (fbclid). Both are set on tapeline.io rather than on facebook.com, are readable by page JavaScript rather than HTTP-only, and are sent to Meta with the page address on each page view. The Meta script runs on our public marketing pages only, never on the signed-in app.
We do not yet have a cookie-consent banner, so the Google cookies are set when the page loads rather than after you choose. In the EU and UK, rules on non-essential cookies generally require consent before they are set. We are building that control; until it ships you can block these cookies with your browser’s settings or a tracker-blocking extension, though we do not treat a browser setting as a substitute for asking you.
Data retention
Active accounts: data retained as long as the account is open. Cancelled or deleted accounts: 30 days, then permanent deletion from primary stores; backup snapshots roll off within 90 days. Stripe-side data follows Stripe's own retention policy (typically 7 years for tax purposes).
Your rights
You can request, at any time:
- A full export of every field we hold on you (CSV or JSON).
- Correction of any inaccurate field.
- Permanent deletion of your account and all linked data.
- A list of which sub-processors received what data.
Email privacy@tapeline.io with your account email in the subject line. We respond within 7 days and fulfil the request within 30 days.
GDPR (EU) and CCPA (California)
Residents of the EU, UK, and California have additional rights under local law — access, correction, deletion, data portability, and the right to opt out of the sale or sharing of personal information. California’s CPRA treats “sharing” as a category separate from “sale”: passing identifiers to an advertising network so it can target you elsewhere can count even when no money changes hands. We do not sell your personal data and do not intend to — but we are not going to lean on that distinction, because we do run advertising and analytics tags that pass identifiers to third parties. Sub-processors and Cookies above are the current record of which are actually running. We do not yet offer a self-serve opt-out control; email the privacy address below and we will action it manually. Whether these obligations bind us as a matter of law has not been confirmed by counsel — see the note at the top of this page — and we would rather honour the request than argue the threshold.
Tapeline is operated from Australia. We transfer your data to the recipients listed in the Sub-processors section above, which are located in the United States, the European Union, and Singapore. For vendors processing on our instructions we rely on the data-protection terms in their standard agreements, including Standard Contractual Clauses where those apply. The advertising platforms are not in that category — they set their own terms and act for their own purposes, which is why they are called out separately above.
Children
Tapeline is not directed at users under 18 and we do not knowingly collect data from minors. If we learn we have, we delete it.
Changes to this policy
We log every change with a date stamp at the top of this page. Material changes (new sub-processors, new categories of data collected, changes to how long we keep things) get a heads-up email to all account holders 14 days before the change takes effect.