Privacy Policy (Polityka prywatności / RODO)
1. Data controller
Data controller (administrator danych): Antoni Zieliński, a natural person operating in Poland as unregistered business activity. Registered/postal address: [address — to be completed]. Contact for any privacy matter: contact@hedgeyourown.com.
2. What we collect, why, and on what legal basis
Account: your email, password hash, and your saved language/theme preference — legal basis: performance of the contract you enter by registering (RODO art. 6(1)(b)).
Holdings: the symbols and quantities you enter yourself, or — where you connect one — pull from a READ-ONLY broker sync — legal basis: contract (they power your charts and the holdings-filtered news digest). We never place or modify a trade using this data.
Payments: a payment reference, the amount and currency charged, the plan purchased, and the timestamp of your withdrawal-rights consent — legal basis: contract. Your card or BLIK details themselves are processed directly by Stripe (card payments) or PayU (BLIK and Polish card payments) — each of them acts as an INDEPENDENT DATA CONTROLLER for your payment-instrument data; we only ever receive a reference back, never your full card number.
Security — a log of login attempts: every sign-in and registration attempt records the IP address and the account email that was attempted, kept for 90 days — legal basis: legitimate interest (RODO art. 6(1)(f)) in detecting brute-force and credential-stuffing attacks against accounts (see docs/SECURITY.md). We never store a password here, not even hashed, and not even for a failed attempt.
Server logs: our web server (nginx) keeps standard access logs (IP address, requested path, timestamp) for about 14 days before they are rotated away — legal basis: legitimate interest in operating and securing the service.
Analytics — only after you accept it via the cookie banner: a pseudonymous visitor id (this still counts as personal data under RODO), which pages you viewed and when, the referring site's domain, utm campaign tags, a coarse device class (mobile/desktop), and conversion events — legal basis: consent, withdrawable at any time from the cookie settings.
First-touch attribution — also only with that analytics consent, and only once: the FIRST utm_source/medium/campaign, referring site domain, and landing page you arrived on are saved onto your account a single time and never overwritten by a later visit — legal basis: consent. Purpose: measuring which marketing channels actually bring paying customers, not just visitors. Deleted when your account is deleted (§6).
Anonymous aggregate purchase statistics: when a purchase completes, we separately log an anonymous conversion event carrying the SAME first traffic source and campaign as above — but never your account id or email — so we can see, in aggregate, which channels convert into paying customers. Legal basis: consent (same as the analytics/first-touch consent above); kept in the same raw-analytics window as the rest of this section (up to 13 months, §5). Subscription renewals are not part of this: a renewal is counted without any traffic source or campaign.
Cancellation feedback: if you tell us why you cancelled (an optional reason plus a free-text note) — legal basis: your consent in giving it / our legitimate interest in improving the service; never shown to anyone else and never used to target you.
AI features: if you use the Pip chat assistant, your message (and the recent turns of that conversation) is sent to Anthropic's API to generate a reply — legal basis: contract (a feature you actively chose to use). Separately, for the portfolio-filtered news digest, the headlines about the stocks you hold are sent to Anthropic for summarisation — legal basis: contract. In both cases the prompts are built so Anthropic is never asked to, and the reply is checked so it never does, give investment advice or a buy/sell signal (§4).
Transactional email: purchase receipts, renewal or access-ending reminders, monthly rebalance notices, and the news digest are sent to your account email — legal basis: contract (these are notices you are entitled to as a subscriber).
Marketing email: we send occasional promotional email (win-back messages to a lapsed subscriber, and any future new-strategy or offer announcements) ONLY if you tick an unticked-by-default opt-in box (at registration, guest checkout, or the strategy unlock form) — legal basis: consent (RODO art. 6(1)(a)). We record the time you gave that consent. Every marketing email carries a one-click unsubscribe link that works immediately, with no login required, and you can withdraw this consent at any time; doing so never affects the transactional email above.
3. Who else sees your data (recipients)
Stripe, Inc. (card payments; USA/Ireland) — an independent controller of your card-payment data.
PayU S.A. (BLIK and Polish card payments; Poland) — an independent controller of your BLIK-payment data.
Hetzner Online GmbH (hosting; data centres in Germany and Finland) — our processor; hosts the server and database this service runs on.
Resend, or the SMTP mailbox provider we have configured (transactional email delivery) — our processor for sending you receipts, reminders, and the digest.
Anthropic, PBC (USA) — our processor for the Pip chat assistant's replies and the news-digest summaries.
TradingView — only when you open a price chart AND have either accepted cookies ('Accept all') or clicked that chart's own 'Show TradingView chart' button, which loads a widget or script directly from TradingView's own service; see the Cookie Policy for exactly when this happens. The homepage's live ticker is NOT TradingView — it is built entirely from our own cached price data.
We do not sell personal data to anyone, and we do not run advertising networks or third-party ad trackers.
4. Transfers outside the EEA
Stripe and Anthropic are established in the USA. Where personal data is transferred to them outside the European Economic Area, we rely on the safeguard each provider itself documents for that transfer — typically their certification under the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses — the sign-off lawyer should confirm the exact mechanism currently relied on by each named provider before this policy is finalised.
5. How long we keep it
Account data: for as long as your account exists; deleted on request (§6), except payment records that Polish accounting/tax law requires us to keep for up to around 5 years.
Login-attempts security log: 90 days, then automatically pruned.
Server (nginx) access logs: about 14 days.
Raw analytics events: up to 13 months, then deleted.
News-digest cache: up to 12 months.
Cancellation feedback: for as long as your account record is kept, for the same reason as other account data.
6. Your rights
You have the right to access, rectify, erase, restrict the processing of, port, and object to the processing of your personal data, and to withdraw analytics consent at any time via the cookie settings; you can also export your data from your account. You can withdraw marketing-email consent at any time via the one-click unsubscribe link carried on every such email (no login needed) — this never affects the transactional email you are otherwise entitled to. You may lodge a complaint with the Polish supervisory authority (Prezes Urzędu Ochrony Danych Osobowych, UODO, uodo.gov.pl). Requests: contact@hedgeyourown.com.
Last updated / effective: 12 September 2026.