Privacy Policy
Cinco Peso Solution Ltd · Last updated 28 July 2026
This policy describes what personal data Smart-Money Radar collects, why we hold it, who else touches it, and the rights you have over it under the GDPR. It is written to describe what the system actually does rather than to cover every hypothetical.
1. Controller
The controller for the data described here is Cinco Peso Solution Ltd, UIC 207822484, Bul. Vasil Levski 46, Sofia, Bulgaria. For any privacy question or to exercise a right, write to support@smartmoneyradar.net. We have not appointed a data protection officer; we are not required to.
2. What we collect, and why
Your email address. Sign-in is through Google, and we request only the openid email scope. Google returns your verified email address and nothing else — no name, no profile picture, no contact list. We store the address, an account role, and the date the account was created. Lawful basis: performance of our contract with you.
Subscription state. When you subscribe, Paddle sends us webhooks from which we store the Paddle customer and subscription identifiers, your plan, its status, the current period end, and whether a cancellation is scheduled. We also retain the raw webhook payloads as a billing audit trail. We do not receive or store your card number, bank details or billing address — those stay with Paddle. Lawful basis: contract, and our legitimate interest in reconciling disputed charges.
Your watchlist. The securities you add, and the optional one-line note you can attach to each. Notes are free text — whatever you type is stored as you typed it, so treat the field as a research journal rather than a private diary. Lawful basis: contract.
Usage counters. A monthly count of AI summaries generated per account, to enforce the plan quota. It records how many, not which. Lawful basis: contract.
Server logs. Our hosting provider records ordinary request logs, which include IP addresses, for operating and securing the service. Lawful basis: legitimate interest in service security and reliability.
3. What we do not do
- · We do not sell personal data, and we never will.
- · We run no advertising, no ad pixels, no third-party analytics or tracking scripts.
- · We do not build behavioural profiles of you, and we take no automated decisions with legal or similarly significant effects.
- · We do not send marketing email unless you ask us to.
4. Cookies
One cookie: a signed, HTTP-only session token set when you sign in, so the site knows you are logged in. It is strictly necessary to deliver a service you asked for, which is why there is no consent banner on this site. Clearing it, or signing out, ends the session. Paddle's checkout sets its own cookies during payment, governed by Paddle's privacy notice.
5. Who processes data on our behalf
- · Google Ireland/LLC— sign-in. Google authenticates you and tells us your verified email address. Your relationship with Google is governed by Google's own privacy policy.
- · Paddle.com Market Ltd — payments. Paddle is the merchant of record and an independent controller of the payment data you give it, not merely our processor. Its privacy notice governs that data.
- · Render Services, Inc. — application and database hosting.
- · Anthropic PBC — AI summaries. The prompt contains only ticker and signal data drawn from public filings. No account identifier, email or watchlist content is sent.
We will also disclose data where we are legally compelled to, or where it is necessary to establish or defend a legal claim.
6. International transfers
Some of these providers are established in, or process data in, the United States. Those transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses.
7. How long we keep it
- · Account data and watchlists: for as long as your account exists. Ask us to delete the account and it goes, along with the watchlist and usage counters.
- · Billing records and webhook payloads: kept after account closure for as long as needed to handle refunds, chargebacks and disputes, and to satisfy accounting and tax record-keeping obligations.
- · Server logs: short-lived, on our hosting provider's standard retention.
8. Your rights
You have the right to access your data, to correct it, to erase it, to restrict or object to processing, and to receive it in a portable format. Where we rely on legitimate interest, you may object and we will stop unless we have compelling grounds to continue.
Write to support@smartmoneyradar.net from your account address. We answer within one month. There is no charge, and we will not make the account worse for you because you asked.
If you think we have handled your data badly, you can complain to your local supervisory authority. Ours is the Commission for Personal Data Protection of the Republic of Bulgaria (Комисия за защита на личните данни), Sofia.
9. Personal data inside the dataset itself
This is the unusual part, and it deserves a plain explanation rather than a footnote. The Service analyses public regulatory disclosures, and those disclosures name people: company officers and directors who file insider-transaction reports, legislators whose transactions are published under transparency rules, and fund managers named in institutional holdings filings. Processing their data is the entire point of a financial-transparency tool.
Our lawful basis is legitimate interest under Article 6(1)(f). The balancing runs as follows: every record comes from an official public register; the individuals were legally required to publish it, in a public-accountability regime designed to be read; we process only the disclosed transaction facts and no special-category data; and the purpose — making already-public financial disclosure legible — is the purpose the disclosure regime exists to serve. We add no inference about anyone's private life.
If you are named in this data and want to object, write to us. We will consider the objection on its merits, but note that we cannot alter or withdraw the underlying public record, and a request to suppress a lawfully published disclosure will usually be refused with reasons.
10. Security
Sessions use signed, HTTP-only tokens over HTTPS; entitlements are enforced server-side rather than in the browser; billing webhooks are signature-verified before they are trusted; and secrets are held in the hosting provider's secret store, never in the codebase. No system is perfectly secure, and we do not claim otherwise. If a breach is likely to put your rights at risk, we will tell you and the supervisory authority as the GDPR requires.
11. Children
The Service is not intended for anyone under 18, and we do not knowingly hold data about children. If you believe we do, tell us and we will delete it.
12. Changes
If we change this policy materially we will say so in the Service and update the revision date at the top of this page.
Provider identity
- · Company: Cinco Peso Solution Ltd
- · UIC (ЕИК): 207822484
- · Registered address: Bul. Vasil Levski 46, Sofia, Bulgaria
- · VAT: not VAT-registered. Paddle, as merchant of record, charges and remits any VAT or sales tax due in your country.
- · Contact: support@smartmoneyradar.net