This policy says exactly what finostat.com collects, why, where it lives and how to get it deleted. It is written to be read, not skimmed past.
Who is responsible
Finostat is operated by Zico Karmakar from India. For anything about your data — questions, corrections, deletion — write to zico@finostat.com. Zico Karmakar is also the grievance officer for the purposes of India's Digital Personal Data Protection Act, 2023.
What we collect, and why
| Data | When | Why |
|---|---|---|
| Email address | You sign in or sign up | Passwordless sign-in links; alert emails you ask for; upgrade requests. It is your account identifier. |
| Name, email, mobile number, city, your answers | You complete the trader assessment | To score the assessment, show your result, and — only if you ticked the consent box — to contact you about it. Answers are stored so you can be shown the same result again and so we can improve the questions. |
| Watchlist and layout preferences | You use the terminal signed in | So they follow your account between devices. Signed out, the same data stays in your browser only. |
| Alert rules and the events they fire | You create alerts signed in | To evaluate them on the server and email you when they trigger. |
| A feedback line and whether we may quote it | You choose to write one after the assessment | Product feedback. We publish a quote on the site only if you ticked “you may quote me”, and only as first name and city. |
| IP address | Every request, briefly | Rate-limiting sign-in links and assessment submissions to stop abuse. Kept with sign-in links (15 minutes) and assessment rows; not used for tracking. |
Payments for Desk and Pro are taken by Razorpay or Cashfree on their own checkout pages: your card, UPI or bank details go to the payment gateway and never to Finostat. Cashfree requires a mobile number on every order, which we keep on your account for that purpose only. We keep the order id, payment id, plan, period and amount, which is what a receipt and a refund need. We do not run advertising trackers or third-party analytics, and we never sell or rent personal data.
Cookies and browser storage
- fino_session — one cookie, set only when you sign in. It holds a random session id (not your email), is HttpOnly and Secure, and expires after 30 days or when you sign out. It is strictly necessary for sign-in; there is no consent banner because there is nothing else to consent to.
- Local storage — signed-out watchlist, layout, browser-side alert rules, and a flag noting whether you have seen the assessment. This never leaves your browser and can be cleared from your browser settings.
Emails we send
Only the ones you trigger: sign-in links, alert notifications for rules you created, and a reply if you write to us. No newsletters or marketing emails unless you opt in explicitly later; if we ever add them, every one will have an unsubscribe link. Email is sent through our own mailbox; delivery providers see the address and the message in transit, as any email provider does.
Market data and third parties
- Market data comes from Upstox's market feed under our own subscription. Nothing about you is sent to Upstox.
- Hosting: the server and database run on Fly.io in Singapore, with encrypted storage. Your personal data is therefore stored outside India; the categories are those listed above and no more.
- Fonts load from Google Fonts, which sees your IP address and browser details when the page loads, as with any web font. No other third-party scripts run on the site.
- Search engines: public pages are indexable; your account data is never public.
How long we keep it
- Sign-in links: 15 minutes. Sessions: 30 days of inactivity.
- Account, preferences and alerts: for as long as the account exists. Ask and we delete the account and everything attached to it.
- Assessment submissions: until you ask us to delete them.
- Backups: daily copies of the database are kept for seven days, then overwritten. A deletion request removes you from the live database at once and from backups within seven days.
Your rights
Under the DPDP Act and as a matter of plain decency you can ask for a copy of what we hold about you, correct it, withdraw consent, or have it deleted. Email zico@finostat.com from the address on the account; we respond within seven days and delete within thirty. If you are unhappy with the response you may approach the Data Protection Board of India.
Security
Sign-in tokens and session ids are stored only as SHA-256 hashes; links are single-use; all traffic is HTTPS; the database lives on an encrypted volume and is backed up daily. No system is perfect — if we discover a breach affecting your data we will tell you by email without undue delay.
Children
The site is for adults. We do not knowingly collect data from anyone under 18; if you believe we have, tell us and it will be deleted.
Changes
If this policy changes materially we update the date at the top and, for signed-in users, say so by email. The current version always lives at finostat.com/privacy.