Security and Privacy Policy
Last Updated: January 1, 2025
Introduction
Welcome to SharesSaver. We are committed to protecting your privacy and securing your personal information. This Security and Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our investment management platform and related services (collectively, the "Services").
By accessing or using our Services, you agree to this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services.
1. Information We Collect
We collect various types of information to provide and improve our Services:
1.1 Information You Provide
- Account information: Name, email address, password, company details
- Service usage: Data you create, upload, or share through our Services
- Contact information: Details you provide when contacting support
- Subscription information: Billing address, payment method details
- Survey responses: Feedback and opinions you share with us
1.2 Information Collected Automatically
- Usage data: Pages visited, features used, time spent, click patterns
- Device information: IP address, browser type, operating system, device identifiers
- Location data: General location based on IP address
- Log data: Server logs, error reports, performance metrics
- Cookies and tracking: Information collected through cookies and similar technologies
1.3 Information from Third Parties
- Authentication providers: Google, Facebook, Microsoft (if you use social login)
- Integration partners: Data from connected third-party services
- Analytics providers: Aggregated usage statistics
- Payment processors: Transaction verification data
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Service Delivery
- Provide, maintain, and improve our Services
- Process transactions and manage subscriptions
- Authenticate users and secure accounts
- Store and manage your investment data
- Enable collaboration features and integrations
2.2 Communication
- Send service notifications and updates
- Respond to support requests and inquiries
- Provide technical assistance and troubleshooting
- Send marketing communications (with your consent)
- Notify you of changes to our policies or Services
2.3 Analytics and Improvement
- Analyze usage patterns and trends
- Monitor performance and system health
- Identify and fix bugs and technical issues
- Develop new features and enhancements
- Conduct research and data analysis
2.4 Security and Compliance
- Detect and prevent fraud and abuse
- Investigate security incidents
- Comply with legal obligations
- Enforce our Terms and Conditions
- Protect the rights and safety of users
4. Data Security
We implement industry-leading security measures to protect your information:
4.1 Technical Safeguards
- Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
- Authentication: Multi-factor authentication (MFA) support
- Access controls: Role-based access control (RBAC) and least privilege principles
- Network security: Firewalls, intrusion detection, DDoS protection
- Monitoring: 24/7 security monitoring and incident response
4.2 Operational Safeguards
- Regular audits: Annual SOC 2 Type II audits
- Penetration testing: Quarterly security assessments
- Employee training: Security awareness programs
- Vendor management: Third-party security reviews
- Incident response: Documented procedures for security events
4.3 Backup and Recovery
- Automated daily backups with 30-day retention
- Geo-redundant storage across multiple data centers
- Disaster recovery plan with RTO of 4 hours
- Regular backup restoration testing
Important: While we implement robust security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.
5. Data Retention
We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
5.1 Account Data
- Active accounts: Retained for the duration of your subscription
- Inactive accounts: Deleted after 12 months of inactivity
- Canceled accounts: Data available for 30 days, then permanently deleted
5.2 Other Data
- Usage logs: Retained for 90 days for troubleshooting
- Financial records: Retained for 7 years for tax purposes
- Support tickets: Retained for 3 years for quality assurance
- Marketing data: Retained until you unsubscribe
6. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
6.1 Access and Portability
- Request access to your personal information
- Receive a copy of your data in a portable format
- Export your data from your account settings
6.2 Correction and Update
- Update your account information at any time
- Correct inaccurate or incomplete data
- Request changes through our support team
6.3 Deletion
- Request deletion of your account and data
- Delete specific data from your account
- Right to be forgotten (where applicable)
6.4 Marketing Communications
- Opt-out of marketing emails at any time
- Manage communication preferences in account settings
- Unsubscribe links in every marketing email
6.5 Regional Rights
GDPR Rights (European Union)
- Right to restriction of processing
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaint with supervisory authority
CCPA Rights (California)
- Right to know what information is collected
- Right to delete personal information
- Right to opt-out of sale (we don't sell data)
- Right to non-discrimination for exercising rights
To exercise any of these rights, please contact us at legal@sharessaver.com. We will respond to your request within 30 days.
8. International Data Transfers
SharesSaver operates globally, and your information may be transferred to, stored, and processed in countries other than your country of residence, including the United States.
8.1 Data Transfer Mechanisms
We use appropriate safeguards for international data transfers:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Privacy Shield certification (where applicable)
- Adequacy decisions by regulatory authorities
- Data processing agreements with all third-party processors
8.2 Data Residency
Enterprise customers may request data residency in specific regions. Contact our sales team for more information.
9. Children's Privacy
Our Services are not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
If we become aware that we have collected personal information from a child under 16 without parental consent, we will take steps to delete that information from our servers.
10. Third-Party Services and Links
Our Services may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
10.1 Integrations
When you connect third-party applications to SharesSaver, you authorize us to access and process data from those services as described in the integration permissions. Review each integration's permissions carefully before connecting.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via email to the address associated with your account
- Display a prominent notice within our Services
- Require your acceptance for material changes that affect your rights
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Officer
legal@sharessaver.comResponse Time
We aim to respond to all privacy inquiries within 5 business days and resolve requests within 30 days.
13. Compliance and Certifications
SharesSaver maintains compliance with major privacy and security standards:
SOC 2 Type II
Annual audits verify our security controls
GDPR Compliant
EU General Data Protection Regulation
CCPA Compliant
California Consumer Privacy Act
ISO 27001
Information security management