Security and Privacy Policy

Last Updated: January 1, 2025

Your data security is our priority

Introduction

Welcome to SharesSaver. We are committed to protecting your privacy and securing your personal information. This Security and Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our investment management platform and related services (collectively, the "Services").

By accessing or using our Services, you agree to this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services.

1. Information We Collect

We collect various types of information to provide and improve our Services:

1.1 Information You Provide

  • Account information: Name, email address, password, company details
  • Service usage: Data you create, upload, or share through our Services
  • Contact information: Details you provide when contacting support
  • Subscription information: Billing address, payment method details
  • Survey responses: Feedback and opinions you share with us

1.2 Information Collected Automatically

  • Usage data: Pages visited, features used, time spent, click patterns
  • Device information: IP address, browser type, operating system, device identifiers
  • Location data: General location based on IP address
  • Log data: Server logs, error reports, performance metrics
  • Cookies and tracking: Information collected through cookies and similar technologies

1.3 Information from Third Parties

  • Authentication providers: Google, Facebook, Microsoft (if you use social login)
  • Integration partners: Data from connected third-party services
  • Analytics providers: Aggregated usage statistics
  • Payment processors: Transaction verification data

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 Service Delivery

  • Provide, maintain, and improve our Services
  • Process transactions and manage subscriptions
  • Authenticate users and secure accounts
  • Store and manage your investment data
  • Enable collaboration features and integrations

2.2 Communication

  • Send service notifications and updates
  • Respond to support requests and inquiries
  • Provide technical assistance and troubleshooting
  • Send marketing communications (with your consent)
  • Notify you of changes to our policies or Services

2.3 Analytics and Improvement

  • Analyze usage patterns and trends
  • Monitor performance and system health
  • Identify and fix bugs and technical issues
  • Develop new features and enhancements
  • Conduct research and data analysis

2.4 Security and Compliance

  • Detect and prevent fraud and abuse
  • Investigate security incidents
  • Comply with legal obligations
  • Enforce our Terms and Conditions
  • Protect the rights and safety of users

3. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

3.1 Service Providers

We share information with trusted third-party service providers who assist us in operating our Services:

  • Cloud hosting: AWS, Google Cloud for infrastructure
  • Payment processing: Stripe, PayPal for transaction handling
  • Email services: SendGrid, Mailchimp for communications
  • Analytics: Google Analytics, Mixpanel for usage insights
  • Support tools: Zendesk, Intercom for customer service

3.2 Business Transfers

If SharesSaver is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our Services of any change in ownership.

3.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities, including to:

  • Comply with legal obligations or court orders
  • Protect and defend our rights or property
  • Prevent or investigate possible wrongdoing
  • Protect the personal safety of users or the public
  • Protect against legal liability

3.4 With Your Consent

We may share your information with third parties when you have given us explicit consent to do so, such as when enabling integrations with third-party applications.

4. Data Security

We implement industry-leading security measures to protect your information:

4.1 Technical Safeguards

  • Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
  • Authentication: Multi-factor authentication (MFA) support
  • Access controls: Role-based access control (RBAC) and least privilege principles
  • Network security: Firewalls, intrusion detection, DDoS protection
  • Monitoring: 24/7 security monitoring and incident response

4.2 Operational Safeguards

  • Regular audits: Annual SOC 2 Type II audits
  • Penetration testing: Quarterly security assessments
  • Employee training: Security awareness programs
  • Vendor management: Third-party security reviews
  • Incident response: Documented procedures for security events

4.3 Backup and Recovery

  • Automated daily backups with 30-day retention
  • Geo-redundant storage across multiple data centers
  • Disaster recovery plan with RTO of 4 hours
  • Regular backup restoration testing

Important: While we implement robust security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.

5. Data Retention

We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

5.1 Account Data

  • Active accounts: Retained for the duration of your subscription
  • Inactive accounts: Deleted after 12 months of inactivity
  • Canceled accounts: Data available for 30 days, then permanently deleted

5.2 Other Data

  • Usage logs: Retained for 90 days for troubleshooting
  • Financial records: Retained for 7 years for tax purposes
  • Support tickets: Retained for 3 years for quality assurance
  • Marketing data: Retained until you unsubscribe

6. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

6.1 Access and Portability

  • Request access to your personal information
  • Receive a copy of your data in a portable format
  • Export your data from your account settings

6.2 Correction and Update

  • Update your account information at any time
  • Correct inaccurate or incomplete data
  • Request changes through our support team

6.3 Deletion

  • Request deletion of your account and data
  • Delete specific data from your account
  • Right to be forgotten (where applicable)

6.4 Marketing Communications

  • Opt-out of marketing emails at any time
  • Manage communication preferences in account settings
  • Unsubscribe links in every marketing email

6.5 Regional Rights

GDPR Rights (European Union)

  • Right to restriction of processing
  • Right to object to processing
  • Right to withdraw consent
  • Right to lodge a complaint with supervisory authority

CCPA Rights (California)

  • Right to know what information is collected
  • Right to delete personal information
  • Right to opt-out of sale (we don't sell data)
  • Right to non-discrimination for exercising rights

To exercise any of these rights, please contact us at legal@sharessaver.com. We will respond to your request within 30 days.

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience and analyze usage patterns.

7.1 Types of Cookies

Essential Cookies

Required for the Services to function. These cannot be disabled.

Examples: Session management, authentication, security

Functional Cookies

Enable enhanced functionality and personalization.

Examples: Language preferences, theme settings, recent searches

Analytics Cookies

Help us understand how users interact with our Services.

Examples: Page views, click tracking, user flows

Marketing Cookies

Used to deliver relevant advertisements and track campaign effectiveness.

Examples: Ad retargeting, conversion tracking

7.2 Managing Cookies

You can control cookies through:

  • Browser settings (most browsers allow you to refuse or delete cookies)
  • Our cookie preference center (accessible in account settings)
  • Third-party opt-out tools (e.g., Google Analytics opt-out)

Note: Disabling certain cookies may limit your ability to use some features of our Services.

8. International Data Transfers

SharesSaver operates globally, and your information may be transferred to, stored, and processed in countries other than your country of residence, including the United States.

8.1 Data Transfer Mechanisms

We use appropriate safeguards for international data transfers:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Privacy Shield certification (where applicable)
  • Adequacy decisions by regulatory authorities
  • Data processing agreements with all third-party processors

8.2 Data Residency

Enterprise customers may request data residency in specific regions. Contact our sales team for more information.

9. Children's Privacy

Our Services are not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

If we become aware that we have collected personal information from a child under 16 without parental consent, we will take steps to delete that information from our servers.

10. Third-Party Services and Links

Our Services may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.

10.1 Integrations

When you connect third-party applications to SharesSaver, you authorize us to access and process data from those services as described in the integration permissions. Review each integration's permissions carefully before connecting.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you via email to the address associated with your account
  • Display a prominent notice within our Services
  • Require your acceptance for material changes that affect your rights

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Protection Officer

legal@sharessaver.com

Response Time

We aim to respond to all privacy inquiries within 5 business days and resolve requests within 30 days.

13. Compliance and Certifications

SharesSaver maintains compliance with major privacy and security standards:

SOC 2 Type II

Annual audits verify our security controls

GDPR Compliant

EU General Data Protection Regulation

CCPA Compliant

California Consumer Privacy Act

ISO 27001

Information security management

Shares Saver | An Easy Way to Buy and Own Stocks and Shares