Privacy Policy
Zipston (“Zipston”, “we”, “us” or “our”) operates the website available at https://zipston.com (the “Site”) and provides stock-screening and related informational tools (collectively, the “Services”). We respect your privacy and are committed to protecting your personal data.
This Privacy Policy explains what data we collect, how we use it, how we share it, and the rights you have—particularly under the EU/EEA General Data Protection Regulation (“GDPR”).
If you have any questions, please contact us at contact@zipston.com.
1) Who we are (Controller)
For the purposes of applicable data protection laws, the controller of your personal data is Zipston (operated by its individual owner). If and when Zipston is incorporated as a company, we will update this notice accordingly.
2) Data we collect
2.1 Data you provide
- Account / Access data: email address, password-less sign-in confirmations (if applicable), consent confirmations.
- Communications: content of messages you send us (support requests, feedback).
- Billing (future subscriptions): If you purchase a subscription, our payment partner will collect billing details (e.g., name, email, address, payment card tokens). We receive only minimal information necessary for accounting and entitlement (e.g., plan, status, last 4 digits, expiry month/year as a tokenized reference—no raw card numbers).
2.2 Data collected automatically
- Technical data: IP address, device identifiers, browser type/version, operating system, user-agent, pages visited, timestamps, referral URLs.
- Cookies and similar technologies: To operate the Site, secure sessions, remember preferences, and measure usage/analytics.
2.3 Data from third parties
- Analytics / error reporting (e.g., privacy-aware analytics tools, server logs).
- Payment processors (subscription status, invoices, refunds, chargebacks).
- Market/data vendors (market data we display is typically not personal data, but interaction with such data on our Site may produce usage logs).
3) Why we use your data (Legal bases)
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide and secure the Services | Account creation, login links, access control, fraud prevention | Performance of a contract (Art. 6(1)(b) GDPR); Legitimate interests (security) |
| Communications | Responding to inquiries; service announcements | Legitimate interests; or consent where required |
| Subscriptions & payments | Managing plans, entitlements, receipts | Performance of a contract; legal obligation (tax) |
| Analytics & improvement | Diagnostics, usage patterns, feature quality | Legitimate interests (to improve and secure our Services) |
| Compliance & enforcement | Enforcing Terms, preventing abuse, lawful requests | Legal obligation; legitimate interests |
Where we rely on consent, you can withdraw it at any time.
4) Cookies
- Strictly necessary cookies for authentication and core functionality;
- Preference cookies to remember settings (e.g., theme);
- Analytics cookies (privacy-aware) to understand usage and improve performance.
You can manage cookies in your browser settings. Some features may not function without essential cookies.
5) How we share data
- Service providers / processors under contract (e.g., hosting, analytics, email delivery, error monitoring, payment processing). They may only process data on our instructions and must protect it appropriately.
- Legal and compliance recipients where required by law or to protect our rights, users, or the public.
- Business changes: If we reorganize, merge, or transfer assets, your data may be transferred to the successor, subject to this Policy.
6) International transfers
We may process data on servers located in the EU or other jurisdictions. Where transfers outside the EEA/UK occur, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms. You may contact us for more information.
7) Data retention
- Account/contact records: for the life of your account and a reasonable period thereafter.
- Logs/analytics: short to moderate periods for security and improvement.
- Billing records: as required by tax/accounting laws.
When data is no longer necessary, we delete or anonymize it.
8) Your rights
- Access, correct, or delete your personal data;
- Restrict or object to certain processing;
- Data portability;
- Withdraw consent at any time (where processing is based on consent);
- Lodge a complaint with your local supervisory authority.
To exercise your rights, contact contact@zipston.com. We may need to verify your identity.
9) Security
We implement reasonable technical and organizational measures designed to protect personal data, including encryption in transit (HTTPS), access controls, and least-privilege practices. However, no method of transmission or storage is 100% secure.
10) Children
Our Services are not directed to children under 16 (or the minimum age required by your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us to remove it.
11) Third-party links and data sources
Our Site may link to third-party websites or display market data provided by third parties. We are not responsible for the privacy practices of such third parties. Review their policies separately.
12) Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be indicated by updating the “Effective date”. Continued use of the Services after changes constitutes acceptance.