LEGAL

Privacy Policy

Last updated: May 2, 2026

1. Introduction

SmallCap Scanner (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website and services (collectively, “the Service”). By using the Service, you consent to the data practices described in this policy.

2. Information We Collect

Account Information. When you create an account, we collect your email address and any display name you choose to provide. Authentication is managed through Supabase Auth, which may support email/password login and third-party OAuth providers (such as Google). We store your user ID, email address, and authentication metadata.

Usage Data. We collect anonymized usage analytics to improve the Service. This may include pages visited, features used, time spent on the platform, browser type, device type, operating system, and referring URLs. This data is collected in aggregate and is not linked to your personal identity.

Watchlist and Preferences. We store the stocks you add to your personal watchlist, your screening filters, and other preference settings to provide a personalized experience.

3. How We Use Your Information

We use the information we collect to: (a) provide, operate, and maintain the Service; (b) personalize your experience, including your watchlist and saved preferences; (c) communicate with you about your account, including service updates and security alerts; (d) analyze usage patterns to improve the Service; (e) display advertising via Google AdSense; (f) detect, prevent, and address fraud, abuse, or technical issues; and (g) comply with legal obligations.

4. Data Sharing and Third Parties

We do not sell, rent, or trade your personal information to third parties. We share data only with the following service providers, who process data on our behalf:

Supabase — Authentication and database hosting. Your account data is stored in Supabase's infrastructure.

Google Analytics & AdSense — Analytics and advertising. Google may use cookies and similar technologies to deliver, measure, and personalize ads. Subject to your consent via our cookie banner. See our cookie policy for details.

Resend — Transactional and newsletter email delivery.

Vercel — Application hosting and edge delivery. Server logs may include IP addresses and request metadata.

We may also disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

5. Cookies and Tracking

We use essential cookies to maintain your authentication session and remember your preferences. With your consent, we also use analytics cookies (Google Analytics 4) and advertising cookies (Google AdSense). On your first visit, a cookie consent banner allows you to accept or reject non-essential cookies. Your choice is stored locally and respected on subsequent visits. See our cookie policy for the full breakdown.

6. Data Retention

We retain your account information for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes. Anonymized usage analytics may be retained indefinitely.

7. Data Security

We implement industry-standard security measures to protect your personal information, including encryption in transit (TLS/SSL), secure authentication through Supabase, and restricted access to production databases. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Your Rights

Depending on your jurisdiction, you may have the right to: (a) access the personal information we hold about you; (b) request correction of inaccurate data; (c) request deletion of your data; (d) object to or restrict certain processing of your data; (e) request data portability; and (f) withdraw consent at any time where processing is based on consent. To exercise any of these rights, please contact us at the email address below.

9. International Data Transfers

Your data may be processed and stored in the United States or other countries where our service providers operate. By using the Service, you consent to the transfer of your data to these jurisdictions, which may have different data protection laws than your country of residence.

10. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child under 18, we will take steps to delete that information promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated policy on this page and updating the “Last updated” date. Your continued use of the Service after any changes constitutes acceptance of the revised policy.

12. Contact

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at privacy@smallcapscanner.com.
Privacy Policy | SmallCap Scanner