Privacy Policy
Last updated: April 26, 2026
Who we are
StockDashes is operated by JH Financieel Advies (KvK: 34097836), based in Heemstede, the Netherlands. For the purposes of GDPR, JH Financieel Advies is the data controller responsible for personal data collected through stockdashes.com.
If you have any questions about this Privacy Policy or how your data is handled, contact: privacy@stockdashes.com.
What this policy covers
This Privacy Policy explains what personal data we collect when you use stockdashes.com, why we collect it, who we share it with, and what rights you have over your data.
Data we collect
We collect the following categories of data:
Account information. When you sign up, we collect your email address and basic profile details via Clerk (our authentication provider). If you sign up with Google OAuth, this includes your name and profile picture from your Google account.
Portfolio data. When you add stocks, share counts, cost basis, dates, and cash positions to your portfolio, we store this data so the application can display it back to you and generate analysis.
Usage analytics. We collect anonymized data about how you use the site — page views, clicks, scroll behavior, and session recordings — but only if you consent to analytics cookies via our cookie banner. This data does not personally identify you.
Technical information. When you visit the site, our hosting provider receives standard web request information (IP address, browser type, device type, referring URL). This is used to operate the service and is automatically discarded after a short period.
Why we collect it (legal basis)
Under GDPR, we collect and process your data on the following legal bases:
Performance of a contract — We process your account information and portfolio data because it is necessary to provide you the StockDashes service you signed up for.
Consent — We process analytics data only with your explicit consent, given via our cookie banner. You can withdraw this consent at any time.
Legitimate interests — We process technical request information (logs, IP addresses) to operate, secure, and debug the service.
Who we share data with
StockDashes uses the following third-party processors. Each processes data on our behalf under contractual agreements that meet GDPR requirements:
Clerk — Authentication and user identity. Stores email addresses, hashed passwords, and OAuth identifiers. Privacy policy
Supabase — Database. Stores your portfolio data (tickers, share counts, cost basis, cash positions) and links it to your account. Privacy policy
Vercel — Hosting and content delivery. Serves the website and may store anonymized request data via Vercel Web Analytics. Privacy policy
Anthropic — AI analysis. When you generate AI summaries of your portfolio or stocks, your portfolio data is sent to Anthropic's Claude API to produce analysis. Anthropic does not use this data to train their models. Privacy policy
PostHog — Product analytics (only if you consent). Tracks anonymized funnel events (e.g. sign-up, first portfolio save) to help us understand how users progress through the product. Data is stored on PostHog's EU servers. Privacy policy
Google Analytics — Website analytics (only if you consent). Tracks anonymized usage data to help us understand how the site is used. Privacy policy
Microsoft Clarity — Session recordings (only if you consent). Records anonymized session replays to help us identify usability issues. Privacy policy
Cloudflare — DNS, content delivery, and email routing. May process technical request information to deliver the service. Privacy policy
Market data providers — We retrieve stock prices, financial data, and market information from Financial Modeling Prep (FMP), Finnhub, SEC EDGAR, and Yahoo Finance. We send only the ticker symbols you have in your portfolio, never your personal data.
How long we keep your data
Account data is kept as long as your account is active. If you delete your account, your account information is removed from Clerk and Supabase within 30 days.
Portfolio data is kept as long as your account is active. You can delete individual positions at any time via Edit Portfolio, or delete your entire account to remove all stored data.
Analytics data is kept according to each provider's defaults (typically 14 months for Google Analytics, varies for Clarity).
Technical logs are kept for short periods by our hosting provider (typically less than 30 days) and used only for operations and security.
Cookies
stockdashes.com uses cookies and similar technologies. You can manage your preferences via the cookie banner that appears on your first visit. For a detailed list of cookies we use, see our cookie banner's "Cookie settings" option.
We use:
- Strictly necessary cookies — Required for the site to function (authentication, session management). These cannot be disabled
- Attribution cookies —
sd_attributionstores your first-visit UTM parameters (e.g.utm_source=google) to help us understand which marketing channels bring users to the site. This cookie is set server-side on your first visit if UTM parameters are present and is never updated. It does not contain personal data - Analytics cookies — Help us understand site usage (Google Analytics, PostHog). Only active with your consent
Your rights under GDPR
If you are in the European Union, United Kingdom, or another jurisdiction with comparable privacy laws, you have the following rights:
- Right of access — You can request a copy of the personal data we hold about you
- Right to rectification — You can request correction of inaccurate or incomplete data
- Right to erasure — You can request deletion of your data ("right to be forgotten")
- Right to restrict processing — You can request that we stop or limit how we use your data
- Right to data portability — You can request a machine-readable copy of your portfolio data
- Right to object — You can object to certain types of processing, including processing based on legitimate interests
- Right to withdraw consent — Where processing is based on consent, you can withdraw consent at any time
To exercise any of these rights, email privacy@stockdashes.com. We aim to respond within 30 days.
You also have the right to lodge a complaint with a data protection authority. In the Netherlands, that is the Autoriteit Persoonsgegevens.
Data transfers outside the EU
Some of our processors (Anthropic, Google, Microsoft, Vercel) may store or process data on servers located outside the European Economic Area, including in the United States. Where this occurs, transfers are protected by Standard Contractual Clauses or equivalent legal mechanisms approved under GDPR.
Security
We rely on industry-standard security practices from our processors to protect your data, including encryption in transit and at rest, access controls, and regular security audits performed by our providers. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
Children
StockDashes is not directed to anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact privacy@stockdashes.com.
Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent version. For material changes, we will notify users via email or a notice on the site before the changes take effect.
Contact
For questions about this policy or to exercise your rights:
Email: privacy@stockdashes.com
Data controller: JH Financieel Advies, KvK: 34097836, Heemstede, the Netherlands