Privacy Policy

Version 2.21 — Last updated: 7 October 2026

Prefer the plain-language version? →

Changelog compared to version 2.20

  • §2.10: if you use a partner's discount code at checkout, we also record that link, and we read from our payment provider which code you used and whether the payment stuck; in our administration we only keep which invoice (number and amount) was paid with which discount code, not who you are. A discount code only gives the discount that belongs to that code; the link itself changes nothing about your price

Changelog compared to version 2.19

  • §2.13 (new), §3, §4 and §5: if you enter the TER of an ETF whose TER we do not know, or report that it is missing, we store that with your account for your own estimate, and our team receives an internal notification with only the fund and the value, without your user ID

Changelog compared to version 2.18

  • §2.8, §3, §4 and §5: if something unexpectedly goes wrong on our server, we record that error automatically: the type of error, the error message (in which we mask, among other things, e-mail addresses, IDs, IP addresses, long codes and amounts by fixed rules — a short value such as a ticker symbol can remain), the kind of page, the location in the code, the code version and how often and when the error occurred. We do not read your request itself (no request body, headers, cookies, IP address or query string), and we store no user ID. Our team receives an internal notification via Resend in our team mailbox at Proton (kept for at most 30 days). We keep such an error for up to 90 days after the last time it occurred

Changelog compared to version 2.17

  • §2.12 (new), §3 and §5: for each account we record on which days you opened the app — only the date, nothing about what you did — for account management and internal usage statistics, and keep it for at most 400 days

Changelog compared to version 2.16

  • §2.8 and §4: our team automatically receives an internal notification for a failed import, rejected rows, a row we do not recognise, a balance or amount that does not reconcile and for import feedback you send us, with only technical attributes of the import and your user ID, never the content of your file or the text of your feedback

Changelog compared to version 2.15

  • §2.11, §4 and §5: our team automatically receives an internal notification when a trial starts, with your email address and your answer to ‘how did you find us’. We keep internal notifications to our team for at most 30 days
  • §4 and §12 name Proton AG in Switzerland, which hosts our team mailbox that receives these notifications and the notifications of new waiting-list sign-ups. The transfer relies on the European Commission’s adequacy decision for Switzerland

Changelog compared to version 2.14

  • §1 and §11: our registered address has changed to Le Mairekade 77, 1013 CB Amsterdam. Nothing changes in how we handle your data

Changelog compared to version 2.13

  • §2.8, §3, §4 and §5: if some rows of your file could not be imported (or none could), we offer — only on your own click — to send just those rows to our team: every row we show you in the list (at most 200), the rows the same transaction is built from and the header row of the file or files they come from, under the same rules as a failed import file (purpose, access for the founders only, storage in the EU, at most 30 days, deleted with your data). When you share an import file or such rows, our team gets an internal email about it, as with a bug report, containing only the broker, the count, a reference and your user ID — never the content

Changelog compared to version 2.12

  • §2.4 and §3: we use the country that belongs to your IP address to decide whether we can offer you a subscription in your country. That country is not stored
  • §2.7, §3 and §5: when you join the waitlist we store the country of your connection (the country code only)
  • New §12 for users in the United States

Changelog compared to version 2.11

  • New §2.11, with rows in §3 and §5: after you take out a subscription we ask you once, optionally, how you found us. We keep your answer (or the fact that you skipped the question) with your account

Changelog compared to version 2.10

  • §2.3 now lists everything we receive from Stripe and keep: besides the status of your subscription and payments, also your Stripe customer and subscription number and the term, and — only if you arrived via a partner code — per instalment the invoice and payment number, the amount and the pseudonymous card fingerprint
  • §2.10 and §5 are precise about the fraud signals: your IP address is stored only as a hash made with a secret key (HMAC); your billing address is not stored, contrary to what this said before
  • §2.6 names the sign-up and checkout steps we count, and that parts of a web address that point to you or your portfolio are replaced before the address is sent to Vercel
  • §4 names Parqet, from which our server fetches company logos per investment (by ticker symbol, ISIN code or product name); your browser does not contact Parqet. The price-data provider row now also says we send ISIN codes and sometimes an investment’s product name
  • §7: the full data export is a JSON file, not a CSV file; you can additionally download your transactions as CSV

Changelog compared to version 2.9

  • §4 describes the share link with which you can publish your portfolio yourself as a read-only page: what a visitor sees (percentages, and amounts only if you switch that on), what is never visible, that the feature is off by default and that revoking works immediately

Changelog compared to version 2.8

  • §5 now states the actual retention periods of the platforms for “technical log files” — Vercel 1 day, Supabase 7 days — instead of the never-verified “at most 90 days” that stood there. We therefore keep those logs considerably shorter than previously stated, and we do not forward them to any other party

Changelog compared to version 2.7

  • §4 now names the correct contracting parties. Our counterparty at Stripe is Stripe Payments Europe, Ltd in Ireland (not Stripe, Inc. in the US), and at Supabase it is Supabase Pte. Ltd; in both cases the transfer to the United States goes to an affiliate and is described separately
  • §4 states the version and date of each processor's data processing agreement, and Upstash's data location is now specified as EU-Ireland — noting that the entity itself is American, because “the data sits in the EU” is not a complete answer on its own
  • The Transfer Impact Assessment we offered “on request” now actually exists and covers every transfer outside the EEA
  • §2.3 names the correct Stripe entity
  • §4 is more honest about two things that were missing: when you request a login code Upstash sees your email address (as a short-lived counter), and Vercel keeps your computed dashboard figures in a cache for at most two days
  • The price alert you can set up yourself contains your position's ticker and goes out through our email provider; that is now stated in §4 instead of living only in the code
  • The outdated notice at §2.3 claiming payments were “not active yet” has been removed — paying has been possible since September 2026

Changelog compared to version 2.6

  • New §2.10 on referral codes: if you arrive through a partner's code, we record which code that was — and what we do and do not show that partner about it. The core: a partner gets counts and amounts, never who you are
  • §5 extended with the matching retention periods, including the separate period for the fraud signals (90 days at most, after which they are erased while the accounting record remains)

Changelog compared with version 2.5

  • §2.9 added, with rows in §3 and §5: the confirmation you give when taking out a subscription — that the service starts immediately — is now recorded (user ID, timestamp, text version). That is a legal obligation under consumer law, not an optional consent, and it appeared in no document while the recording itself had already been built

Changelog compared with version 2.4

  • §2.8 and §5: bug reports now have a hard retention period of 90 days with automatic clean-up, and are deleted immediately when you erase your stored data. It previously said “until the report has been dealt with”, with nothing technical enforcing it
  • §4 clarified: the internal notification we receive for a bug report contains only the category and your user ID. The content of your report is not emailed, precisely because a mailbox is not covered by that retention period

Changelog compared with version 2.3

  • §2.8 added: bug reports and sending along a failed import file — only when you click to do so yourself — including purpose limitation, access for the founders only, EU storage and a retention period of 30 days
  • Processing purposes (§3) and retention periods (§5) extended for these two processing activities

Changelog compared with version 2.2

  • Upstash added as a sub-processor (§4): rate limiting for security and fraud prevention, temporarily processes your IP address within the EU
  • §6 extended: optional two-factor authentication (TOTP) for users
  • The “(future)” marker on Stripe removed now that payment processing is part of the service

Changelog compared with version 2.1

  • Cookieless web statistics and performance monitoring via Vercel (Vercel Web Analytics and Speed Insights) added as §2.6, with the processing purposes (§3) and the sub-processors (§4)

Changelog compared with version 2.0

  • §2.5 added: optional, consent-based data sharing for product improvement (feedback + voluntary sample exports), with the corresponding processing purposes (§3) and retention periods (§5)

Changelog compared with version 1.0

  • Vercel data transfer clarified: primarily EU, SCCs and technical measures for incidental US routing
  • Supabase: CLOUD Act exposure named and SCCs added as an additional safeguard
  • Legal basis for service messages corrected to performance of the contract (art. 6(1)(b))
  • Rights extended: withdrawal of consent, Belgian supervisory authority (GBA), and a statement on automated decision-making
  • Privacy contact person named; retention period for account data justified

StockQuarters Capital VOF (“StockQuarters”, “we”, “us”) respects your privacy. This privacy policy explains which data we collect, why, how we use it and which rights you have. We are based in Amsterdam, the Netherlands, and fall under the General Data Protection Regulation (GDPR).

1. Who is responsible?

StockQuarters Capital VOF
Le Mairekade 77, 1013 CB Amsterdam, the Netherlands
Email: hello@stockquarters.nl
Chamber of Commerce (KvK) number: 42067834

For questions about the processing of personal data you can contact our privacy contact person at privacy@stockquarters.nl.

2. Which data do we collect?

2.1 Account data

When you create an account, we collect:

  • Email address
  • Authentication via a one-time verification code (OTP) by email — no passwords are stored. We use a passwordless sign-in method.

2.2 Financial transaction data

When you upload a CSV or PDF file from your broker, we process the data it contains. This may include:

  • Transactions (purchases, sales, dividends)
  • Ticker symbols and ISIN codes
  • Prices, quantities and amounts
  • Transaction dates
  • Broker name

Important: we never ask for your broker credentials. We have no access to your broker account. You upload a file yourself that you download from your broker.

2.3 Payment data

Payments are processed by Stripe Payments Europe, Ltd (Ireland). We do not store credit card numbers or bank details ourselves. Stripe processes this data under its own privacy policy. From Stripe we receive and keep only:

  • Your Stripe customer and subscription number, to link your payment to your account
  • Subscription status, the plan you chose and the term (end of the trial and of the current period, and whether your subscription stops at the end of the period)
  • Whether a payment succeeded
  • Only if you arrived via a partner’s referral code (§2.10): per paid instalment the invoice and payment number, the amount and currency, and the pseudonymous card fingerprint Stripe returns for your payment card — never your card number

2.4 Technical data

When you use our service we collect:

  • IP address (for security and fraud prevention)
  • Browser type and operating system
  • Time of visit
  • The country that belongs to your IP address (the country code only), to decide whether we can offer you a subscription in your country. We do not store that country, except when you join the waitlist (§2.7).

We use no third-party tracking cookies. See our Cookie Policy for more information.

2.5 Data you share voluntarily for product improvement (optional)

During the beta phase and afterwards you can help us improve the service — entirely voluntarily and only with your explicit, prior consent. This is separate from the core functionality: the service works fully without you taking part, and you can withdraw your consent at any time.

This covers:

  • Feedback you send us (bug reports, remarks, corrections to an import).
  • Voluntarily donated sample exports from your broker, to build and improve our import function (parser) — including for new brokers.

How we handle this:

  • Separate and optional. We ask for a separate, not pre-ticked consent for this, apart from the terms and conditions. You give consent per item.
  • Anonymisation. Sample exports are anonymised on receipt: directly identifying data (such as name and account number) is removed or replaced. We need an export because of its format (columns, date notation, kinds of rows), not because of your specific positions or amounts.
  • Separate storage. Donated samples are kept apart from your production portfolio and are not used to populate your account or to profile you.
  • Withdrawable. You can withdraw your consent at any time via your account settings or via privacy@stockquarters.nl. Withdrawal works for the future; samples already processed and anonymised may no longer be traceable to you.
  • Never sold. We never sell or rent this data to third parties.

2.6 Web statistics and performance data

We use cookieless web statistics and performance monitoring via Vercel (Vercel Web Analytics and Speed Insights) to see how many visitors view our pages and how fast they load. This sets no cookies and builds no profile of you. From your IP address and browser (user agent) Vercel derives an aggregated, daily-rotating visitor hash that is not traceable to you. In addition, we count a handful of steps in signing up and checking out: email address entered, code confirmed, subscription viewed or chosen, checkout started, paid for or cancelled, a notice that a feature requires a subscription, and an import started. Such a count carries at most the chosen subscription (monthly or yearly) or the reason for that notice — never an amount, your email address or anything else that identifies you. Parts of a web address that point to you or your portfolio, such as the fund on a position page, are replaced with a placeholder before the address is sent to Vercel. We receive aggregated statistics only (page views, approximate country, device and browser type, and load times). This data is never sold and not used for advertising.

2.7 Waiting list (before launch)

If you sign up for our waiting list, we process your email address and the broker(s) you specify (including any free-text option). Sign-up works with double opt-in: you first receive a confirmation email and your sign-up only becomes active once you confirm it. We use this data solely to inform you about the launch and important product updates, and to gauge which brokers we should prioritise — not for other advertising or profiling. In addition, we store the country of your internet connection at the moment you sign up — the country code only, never your IP address — to see in which countries there is demand and to email you only about an offer that is available in your country. The legal basis is your consent; you can withdraw it at any time or ask for deletion via privacy@stockquarters.nl (and, once we send updates, via the unsubscribe link in every email). The confirmation and notification emails are sent via our email provider Resend (see §4).

2.8 Error reports and failed imports

If something goes wrong in the app, you can help us fix it. In both cases below this happens only after you click to do so yourself — we never send anything along automatically in the background when you do. If an import fails, we reject rows from your file, your file contains a row we do not recognise or a balance or amount that does not reconcile, or you send us feedback on an import, our team does receive an automatic internal notification, containing only technical attributes of the import, such as the broker and the error code, and your user ID — never the content of your file or the text of your feedback (see §4 and §5). An unexpected error on our server is also recorded automatically; when that happens we do not read your request itself, we store no user ID, and we mask data such as e-mail addresses and amounts in the error message by fixed rules (see ‘Automatic error recording (server)’ below).

Bug report. If you report a problem (“this number is wrong”, “this position is missing”), we store the category you chose, any explanation you added, the page you were on, and — if you report a specific position — its ticker symbol. We use this solely to investigate and resolve the report. We keep a report for at most 90 days — ample time to investigate and resolve it — after which it is deleted automatically. If you erase your stored data in the app, or delete your account, the report goes with it immediately.

Failed import file or rows not imported. If processing your broker export fails, we offer to send the file along so we can reproduce the error and repair the import function. If you choose to do so, we store a copy of the raw file. If some rows of your file could not be imported (or none could), we offer to send only those rows: every row we show you in the list (at most 200, including the ones not visible yet), the rows the same transaction is built from (such as a matching fee or currency row) and the header row of the file or files those rows come from — never the rest of your file. If you choose to do so, we store a copy of those rows. Such a file and such rows contain your real financial data — transactions, amounts and sometimes an account number too. Stricter rules therefore apply to them:

  • Purpose. Technical fault diagnosis only: reproducing the error and repairing the import function (parser). Never for analysis of your portfolio, profiling, marketing or training models.
  • Access. The two founders only, via a separate administrator key. Other users cannot reach it — and neither can you: after sending, the copy is no longer visible in your account.
  • Storage. Within the EU (Supabase, Frankfurt), stored and transmitted encrypted.
  • Retention. At most 30 days. After that the copy is deleted automatically.
  • Gone sooner if you want. If you erase your stored data in the app, or delete your account, the copy goes with it immediately. If you want a file or rows you sent earlier removed in the meantime, email privacy@stockquarters.nl.
  • Never shared. We do not share or sell these files or rows to third parties.

The legal basis for both is your consent; you give it each time, and you are never obliged to. The service works fully without you taking part.

Automatic error recording (server). If something unexpectedly goes wrong on our server while loading a page or carrying out an action, our server records it automatically, so that we can find and fix the error. For each kind of error we keep: the type of error and the error message; the kind of page it happened on (the page template, such as ‘position page’); the technical location in the code; the version of our code; a technical error code; and how often and when the error occurred. Before storing the error message, we automatically mask e-mail addresses, tokens and keys, IDs (UUIDs), IP addresses, ISINs and IBANs, the parameters of web addresses, long codes, amounts and longer numbers, and quoted values that look like data. This masking is rule-based, so a short value in an error message, such as a ticker symbol or a small number, can remain. We do not read the request itself for this: not the content you sent (the request body), not the headers or your cookies, not your IP address and not the query string of the web address. We do not store a user ID with an error. If an error is new, comes back or occurs often, our team receives an internal notification with this data, via Resend in our team mailbox at Proton (see §4); we keep such a notification there for at most 30 days. The errors themselves are stored within the EU (Supabase, Frankfurt); only the two founders have access to them. We keep an error for up to 90 days after the last time it occurred; after that it is deleted automatically. The legal basis is our legitimate interest in a service that works.

2.9 Confirmation when you take out a subscription

When you take out a paid subscription, we ask you to actively confirm beforehand, once, that the service becomes available immediately — that is, during the statutory 14-day cooling-off period. We record that confirmation because consumer law requires us to be able to demonstrate that you gave that agreement in advance and expressly.

  • What we record. Your user ID, the moment (UTC) and the version of the text you saw at that moment. Not the contents of your order, and no payment details — those stay with Stripe (see §4).
  • When. At the moment you choose a plan, before you are sent to the payment page.
  • Retention. For as long as your account exists. If you erase your stored data in the app, this confirmation stays — it is evidence attached to the contract, not portfolio data. If you delete your account, it goes with it. See §5.

The legal basis is a legal obligation (art. 6(1)(c) GDPR, pursuant to art. 7:230p of the Dutch Civil Code). So this is not an optional consent like the ones in §2.5: you cannot withdraw it separately without ending the subscription itself.

2.10 Partner referral codes

If you arrive through a partner's referral code, or use a partner's discount code at checkout, we record that link. We need it to determine whether and when that partner is owed a fee.

  • What we record. Which code you used, when that happened, and whether an instalment was actually collected. Alongside that, a few fraud signals needed to tell whether a signup is genuine: your IP address at the moment you used the code, which we store only as a hash made with a secret key (HMAC), never readable, plus the pseudonymous card fingerprint our payment provider returns. We do not store your billing address. With a discount code, we read from our payment provider which code you used and whether the payment stuck; in our administration we only keep which invoice (number and amount) was paid with which discount code, not who you are.
  • What the partner sees. Counts and amounts, and nothing else. We never tell a partner who signed up through their code — no name, no email address, no town, no signup moment, and nothing about your portfolio. The monthly statement a partner receives consists solely of counts and amounts.
  • Retention. The link itself is kept for as long as our administration and statutory tax retention require; the fraud signals are erased sooner. See §5.

Legal basis. Legitimate interest (art. 6(1)(b) and (f) GDPR): we must be able to meet our obligation to the partner and to counter misuse of the programme. The link itself changes nothing about your price; a discount code only gives the discount that belongs to that code.

2.11 How you found us (optional)

After you take out a subscription, we ask you once how you came across StockQuarters — for example through a search engine, LinkedIn, an AI assistant or a friend. The question is entirely optional: you can skip it and the service works exactly the same.

  • What we record. The channel you choose, any explanation you type yourself under “Other” (at most 200 characters), and the moment you answered or skipped the question — so we do not ask it again.
  • What for. Only to understand through which channels new users find us. We do not use it for advertising or profiling and share it with no one. We also receive the channel you chose (or your explanation under “Other”) in an internal notification to our team (§4).
  • Retention. For as long as your account exists; see §5.

Legal basis. Legitimate interest (Art. 6(1)(f) GDPR): knowing which channels work. Your answer is voluntary, and you can have it deleted via privacy@stockquarters.nl.

2.12 On which days you use the app

To know whether StockQuarters is actually being used, and whether a reminder makes sense for you, we record for each account on which days you opened the app. Nothing more.

  • What we record. Only the date (in UTC) of each day on which you opened a page of the app while signed in: one record per day, however often you come back that day. Not which pages you view, not at what time, not what you do, no IP address and no device data. We also look at the moment your login session was last refreshed, which our login service Supabase keeps anyway (§2.4).
  • What for. Managing your account, for example seeing whether you still use the service before we send you a reminder, and internal usage statistics, such as how many people used the app this week and how many new users come back after a week. Only our team sees it; we share it with no one and do not use it for advertising or profiling.
  • Retention. At most 400 days; deleted automatically after that. Deleted immediately when you delete your account. The dates are included in your data export; see §5.

Legal basis. Legitimate interest (Art. 6(1)(f) GDPR): knowing whether the service is used and who could use a reminder. It concerns dates only, without content. You can object to this via privacy@stockquarters.nl.

2.13 Fund costs you enter yourself

If we do not know the ongoing charge (TER) of an ETF in your portfolio, you can enter it yourself, or just report that it is missing.

  • What we record. With your account: the fund (ticker symbol and ISIN), the TER you entered, or that you only reported it as missing, and when.
  • What for. Your value only counts in your own estimate of fund costs; other users never see it. Our team also uses your input to fill in missing TERs for everyone: we receive an internal notification with only the fund and the value, without your user ID (§4), and we look at how many users reported each fund and which values they entered. We never take over an entered value for others without checking it.
  • Retention. Until you remove the value, clear your stored data or delete your account; see §5. Your input is included in your data export.

Legal basis. Performance of the contract (Art. 6(1)(b) GDPR) for your own estimate; legitimate interest (Art. 6(1)(f) GDPR) for filling in fund data for everyone. You can remove your input yourself, or object via privacy@stockquarters.nl.

3. Why do we process this data?

DataPurposeLegal basis (GDPR)
Email addressCreating an account and signing in via OTP verificationPerformance of the contract (art. 6(1)(b))
Financial transaction dataPortfolio dashboard, P&L calculations, dividend trackingPerformance of the contract (art. 6(1)(b))
Payment data (via Stripe)Processing the subscriptionPerformance of the contract (art. 6(1)(b))
Email addressService messages (OTP codes, subscription changes, security notifications)Performance of the contract (art. 6(1)(b))
IP address and technical dataSecurity, fraud prevention, debugging; deciding whether we offer a subscription in your countryLegitimate interest (art. 6(1)(f))
Aggregated usage statistics not traceable to individuals (such as the total number of active users or the average number of uploaded files)Improving the product and internal reportingLegitimate interest (art. 6(1)(f)). These statistics are computed at an aggregated level and are not traceable to individual users.
Web statistics and performance data (page views, approximate country, device and browser type, load times), via a cookieless, daily-rotating visitor hashMeasuring and improving visitor numbers and website performance (Vercel Web Analytics and Speed Insights)Legitimate interest (art. 6(1)(f)). Cookieless and aggregated; no profiling and not traceable to individual users.
Feedback you send us voluntarily (see §2.5)Improving the service and fixing errorsConsent (art. 6(1)(a))
Voluntarily donated, anonymised sample exports (see §2.5)Building and improving the import function (parser), including for new brokersConsent (art. 6(1)(a))
Waiting list: email address, broker choice and country (see §2.7)Informing you about the launch and product updates; setting import prioritiesConsent (art. 6(1)(a))
Bug report: category, explanation, page and possibly ticker symbol (see §2.8)Investigating and resolving reported errorsConsent (art. 6(1)(a))
Copy of a failed import file or of the rows not imported (raw broker export, see §2.8)Reproducing the import error and repairing the import function (parser)Consent (art. 6(1)(a))
Confirmation that the service starts immediately (given when taking out a subscription, see §2.9)Demonstrating that you expressly agreed, before delivery, to delivery during the statutory cooling-off periodLegal obligation (art. 6(1)(c)), pursuant to art. 7:230p of the Dutch Civil Code
How you found us (optional answer after taking out a subscription, see §2.11)Understanding through which channels new users find usLegitimate interest (Art. 6(1)(f))
Automatic error recording on the server: type of error, error message with automatically masked values, kind of page, location in the code, code version and counts (see §2.8)Finding and fixing errors in the serviceLegitimate interest (Art. 6(1)(f))
Dates on which you used the app (see §2.12)Managing your account, deciding whether a reminder makes sense, and internal usage statisticsLegitimate interest (Art. 6(1)(f))
Fund costs (TER) you entered or reported (see §2.13)Your own fund-cost estimate; filling in missing fund data for everyonePerformance of the contract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f))

4. Do we share data with third parties?

We do not sell your data. We do not share your data with advertisers or other third parties beyond what is needed for our service. We share data only with the following parties, and only in so far as necessary:

PartyPurposeLocationSafeguardsData processing agreement
Supabase (Supabase Pte. Ltd)Database hosting, authentication, file storageStored in the EU (Frankfurt, Germany). Our contracting party is Supabase Pte. Ltd in Singapore; access from the US by Supabase, Inc is covered by Standard Contractual Clauses (SCCs).SCCs (module 2), encryption at rest and in transit, Transfer Impact Assessment on fileYes — version 1 of 1 August 2026
Vercel, Inc.Website hosting and edge delivery, including a temporary cache of computed dashboard figures under your user ID (at most two days); cookieless web statistics and performance monitoring (Vercel Web Analytics and Speed Insights)Primarily EU (Frankfurt). In incidental cases content may be delivered via servers in the US.SCCs, supplemented with technical measures (TLS encryption). The web statistics are cookieless and aggregated: no profiles are built and no data is sold. A Transfer Impact Assessment is available on request.Yes — pre-signed, effective 31 March 2026
Stripe Payments Europe, LtdPayment processingIreland (EU). To carry out the payment, Stripe transfers data to Stripe, LLC in the US.Data Transfers Addendum: Stripe, LLC is certified under the EU-US Data Privacy Framework, with SCCs (modules 1 and 2) as a fallbackYes — 18 November 2025, with a separate Data Transfers Addendum
Upstash, Inc.Rate limiting for security and fraud prevention — briefly keeps a counter per IP address, user ID or, when you request a login code, your email addressEU (Ireland). Upstash, Inc. is based in the US; the stored data stays in the EU region.SCCs (modules 2 and 3), encryption in transit (TLS). The data is short-lived: a counter with a window of 5 minutes to an hour that then expires automatically — at the very most after a little over two hoursYes — April 2025
Resend (Plus Five Five, Inc.)Sending email messages (waiting-list confirmation, invitations, transactional and lifecycle messages), a price alert if you set one up yourself — which contains the ticker of the position you are following —, an internal notification for a bug report containing only the category and your user ID, never the content of your report, and an internal notification when you share an import file or rows not imported with us, containing only the broker, the count, a reference and your user ID, never the content, and internal operational notifications to our team: when a trial starts, containing your user ID, your email address, plan, language, the end date of your trial and your answer to ‘how did you find us’ (the channel you chose, or your own explanation under ‘other’); for import feedback, a failed import, rejected rows, an unknown transaction type or a balance or amount that does not reconcile, only technical attributes of the import (broker, error code or row type, file type and line number, parser version, number of rows and a reference), for feedback also whether you allowed us to replay your import, and your user ID — never the content of your file or the text of your feedback; for a reported missing TER, only the fund (ISIN, ticker symbol and exchange listing), the reported value and how many users reported it, without your user ID; and for an unexpected error on our server the error message (with values masked by fixed rules) and technical attributes of that error (see §2.8), without your user IDUSSCCs (modules 1 through 3) and certification under the EU-US Data Privacy FrameworkYes — 31 December 2025, pre-signed
Proton AGOur team mailbox (admin@stockquarters.nl): receives the internal notifications above (under Resend) and the notifications of new waiting-list sign-ups. We keep these notifications in that mailbox for at most 30 days; after that they are deleted automaticallySwitzerland (Plan-les-Ouates, Geneva)Adequacy decision of the European Commission for Switzerland (article 45 GDPR); stored encryptedYes — version of 10 February 2026, part of the terms
External price-data providerPrice data, and matching ISIN codes to exchange listings — we send ticker symbols, ISIN codes and sometimes an investment’s product name, no personal dataN/A — ticker symbols, ISIN codes and investment product names, no personal dataN/A (no personal data)N/A
ParqetCompany logos next to your positions. Our server requests a logo per investment (by ticker symbol, ISIN code or product name) and keeps it in our own storage; your browser loads the logo from us and never contacts ParqetN/A — ticker symbols, ISIN codes and investment product names, no personal dataN/A (no personal data)N/A

For every transfer outside the European Economic Area we rely on Standard Contractual Clauses (SCCs) in accordance with articles 44–49 GDPR, supplemented for Stripe and Resend by their certification under the EU-US Data Privacy Framework — with one exception: for Proton in Switzerland we rely on the European Commission’s adequacy decision for Switzerland (article 45 GDPR). We have assessed those transfers in a Transfer Impact Assessment; that document, like a copy of the data processing agreements themselves, is available on request via privacy@stockquarters.nl.

If you share your portfolio yourself through a share link (Settings → Sharing), you publish that page, not us. Anyone with the link then sees the derived figures you chose: returns and weights in percentages, and only if you switch it on yourself, amounts in your portfolio currency. Never your e-mail address or name (unless you enter a name yourself), quantities, purchase prices, prices, transactions, cash balance or broker details. The feature is off by default; you can switch the link off or replace it at any time, after which the old link stops working immediately. We count how often the page was viewed, not by whom.

5. How long do we keep data?

DataRetention period
Account dataFor as long as your account is active. After account deletion all account data is permanently erased from all systems within 30 days, including back-ups. This period is necessary for the technical processing of back-up rotation and to complete any fraud investigations.
Financial transaction dataFor as long as your account is active. Deleted immediately on account deletion.
Uploaded files (CSV/XLSX)The file content is kept for as long as your account is active, so that we can reprocess your import after improvements and help you with import problems. Deleted immediately when you erase your data or delete your account.
Payment dataIn accordance with the statutory retention obligation (7 years for tax administration) — managed by Stripe.
Technical log filesVercel (hosting): 1 day. That is the platform’s own retention period; it is not configurable on our plan and we do not forward the logs to any other party. Supabase (database and API): 7 days, likewise the platform period. The short-lived rate-limiting counters at Upstash expire with their own window (see §4).
Feedback (product improvement, §2.5)Until you withdraw your consent or the feedback has been processed.
Donated sample exports (anonymised, §2.5)For as long as relevant to the import function; deletion on request for as long as it is traceable.
Waiting-list data (email address, broker choice, country, §2.7)On the basis of your consent, until you withdraw it or ask for deletion (privacy@stockquarters.nl). Unconfirmed sign-ups are deleted as soon as they are no longer relevant.
Bug reports (§2.8)At most 90 days; deleted automatically after that. Deleted immediately when you erase your stored data or delete your account.
Copy of a failed import file or of the rows not imported (§2.8)At most 30 days; deleted automatically after that. Deleted immediately when you erase your stored data or delete your account.
Confirmation of immediate delivery for a subscription (§2.9)For as long as your account exists. Kept when you erase your stored data — it is evidence attached to the contract, not portfolio data — and deleted as soon as you delete your account.
Partner referral code (§2.10)For as long as our administration and statutory tax retention require (7 years). If you delete your account, the link to you as a person is severed; the accounting record remains without your data.
Fraud signals for a referral (§2.10)90 days at most. After that the IP hash and the card fingerprint are erased automatically, while the commission record itself remains.
How you found us (§2.11)For as long as your account exists. Deleted when you delete your account, or earlier on request.
Automatic error recording (server, §2.8)Up to 90 days after the last time the error occurred; deleted automatically after that.
Internal notifications to our team (§4)At most 30 days in our mailbox; deleted automatically after that.
Dates on which you used the app (§2.12)At most 400 days; deleted automatically after that. Kept when you clear your stored data, because it says nothing about your portfolio, and deleted immediately when you delete your account.
Fund costs you entered or reported (§2.13)Until you remove them; deleted immediately when you clear your stored data or delete your account.

6. How do we secure your data?

  • All data is stored encrypted (encryption at rest) and transmitted encrypted (TLS/HTTPS).
  • Authentication uses one-time verification codes (OTP) by email — no passwords are stored.
  • Access to production systems is limited to the two founders.
  • We use two-factor authentication on all internal accounts (GitHub, Supabase, Vercel, Stripe).
  • You can add extra protection to your own account with optional two-factor authentication (TOTP via an authenticator app).
  • Daily automatic database back-ups.

7. Your rights

Under the GDPR you have the following rights:

Right of access — You can request which data we process about you.

Right to rectification — You can have incorrect data corrected.

Right to erasure — You can have your account and all associated data deleted. You can do this directly via Settings in the app, or by sending an email to privacy@stockquarters.nl.

Right to data export (data portability) — You can download all your data as a JSON file via the export function in Settings; you can additionally download your transactions as a CSV file.

Right to restriction of processing — You can ask us to temporarily restrict the processing of your data.

Right to object — You can object to processing based on legitimate interest.

Right to withdraw consent — In so far as we process data on the basis of your consent (for example the voluntary data sharing for product improvement, see §2.5), you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before the moment of withdrawal.

Right to lodge a complaint — You can lodge a complaint with the supervisory authority in your country of residence. In the Netherlands this is the Autoriteit Persoonsgegevens. In Belgium this is the Gegevensbeschermingsautoriteit.

For all these requests you can get in touch via privacy@stockquarters.nl. We respond within 30 days.

8. Automated decision-making

We do not take automated decisions with legal effects or similarly significant consequences for you on the basis of your data. All calculations in StockQuarters (P&L, return, diversification) are informational and do not constitute a recommendation or a decision.

9. Children

StockQuarters is not intended for people under 18. We do not knowingly collect data from minors. If we discover that a minor has registered, we delete the account and all associated data.

10. Changes

We may adjust this privacy policy from time to time. In the event of material changes we will notify you by email, with a clear summary of the changes. The most recent version is always available at stockquarters.nl/privacy, including a version number and the date of the last change.

11. Contact

Do you have questions about this privacy policy or about the processing of your data?

StockQuarters Capital VOF
Email: privacy@stockquarters.nl (privacy matters) / hello@stockquarters.nl (everything else)
Address: Le Mairekade 77, 1013 CB Amsterdam, the Netherlands

12. Users in the United States

StockQuarters is a Dutch service built for investors in Europe. We do not currently offer subscriptions to people in the United States or its territories; visitors from there can join our US waitlist instead. This section gives US visitors and waitlist members the information US state privacy laws, such as the California Online Privacy Protection Act, ask for. The rest of this policy applies to you in full.

  • What we collect. The categories in §2: your email address and account details, the broker exports you upload yourself, your subscription status from our payment provider, technical data such as your IP address and browser, and — if you join the waitlist — the brokers you pick and the country of your connection.
  • Who receives it. Only the service providers listed in §4, and only to run the service: Vercel (hosting, including cookieless visitor statistics), Supabase (database and login), Stripe (payments, including the fraud-prevention signals Stripe collects), Resend (email), Proton (our team mailbox) and Upstash (rate limiting).
  • No selling, no sharing, no targeted advertising. We do not sell your personal information and do not share it for cross-context behavioral advertising, as those terms are used in California law. We show no ads and build no advertising profiles.
  • Do Not Track and Global Privacy Control. We do not track you across other websites and do not let third parties do so on ours, so there is nothing for these signals to switch off. If your browser sends one, we respect it; the service works the same either way.
  • Age. StockQuarters is not intended for anyone under 18, or under the age of majority where you live if that is higher. We do not knowingly collect information from children under 13.
  • Your choices. You can ask to see, correct or delete the personal information we hold about you by emailing privacy@stockquarters.nl. We respond within 30 days and will not treat you differently for asking. You can also delete your account yourself in Settings, and leave the waitlist through the link in every waitlist email.
  • Changes. When we change this policy we update the version number and date at the top of this page; for material changes we email you a summary first (see §10).
Terms and Conditions·Cookie Policy··Back to StockQuarters