Privacy Policy
Cinco Peso Solution Ltd · Last updated 29 July 2026
This policy describes what personal data Smart-Money Radar collects, why we hold it, who else touches it, and the rights you have over it under the GDPR. It is written to describe what the system actually does rather than to cover every hypothetical.
1. Controller
The controller for the data described here is Cinco Peso Solution Ltd, UIC 207822484. Its registered address is published in our company details. For any privacy question or to exercise a right, write to support@smartmoneyradar.net. We have not appointed a data protection officer; we are not required to.
2. What we collect, and why
Your email address. Sign-in is through Google, and we request only the openid email scope. Google returns your verified email address and nothing else — no name, no profile picture, no contact list. We store the address, an account role, and the date the account was created. Lawful basis: performance of our contract with you.
Subscription state. When you subscribe, Paddle sends us webhooks from which we store the Paddle customer and subscription identifiers, your plan, its status, the current period end, and whether a cancellation is scheduled. We also retain the raw webhook payloads as a billing audit trail. We do not receive or store your card number, bank details or billing address — those stay with Paddle. Lawful basis: contract, and our legitimate interest in reconciling disputed charges.
Your watchlist. The securities you add, and the optional one-line note you can attach to each. Notes are free text — whatever you type is stored as you typed it, so treat the field as a research journal rather than a private diary. Lawful basis: contract.
Usage counters. A monthly count of AI summaries generated per account, to enforce the plan quota. It records how many, not which. Lawful basis: contract.
Server logs. Our hosting provider records ordinary request logs, which include IP addresses, for operating and securing the service. Lawful basis: legitimate interest in service security and reliability.
3. Analytics and email capture (opt-in)
Product analytics.We use PostHog, on PostHog's EU cloud, to see anonymously which parts of the dilution-check tool people actually use — for example, that a result was viewed or a feedback form was submitted. Analytics is off by default and stays off unless you actively grant consent through the on-screen prompt; declining, or leaving it unanswered, keeps it off. Your choice is stored in your browser under the key smr_analytics_consent (“granted” or “declined”). Only once you grant consent do we create a random, first-party anonymous identifier, stored under smr_anon_id, so repeat visits can be linked without identifying you. Events carry only a closed set of fields — the page path you're on, ticker, dilution state, facility count, a reason code, a traffic-source tag (which page sent you to pricing), a referral tag, an interval, a link's host, and (for the existing signal features) a signal type and a signal count — and never your portfolio holdings, trade direction, position size, free text you typed, or a filing's full URL. Lawful basis: consent (Art. 6(1)(a)).
Notify / alert / waitlist emails. If you ask to be notified when a ticker is covered, register interest in a future price-alert feature, or join the founding-price waitlist, we store the email address you give us server-side only — it is never sent to analytics or to any third party except where we are legally compelled to disclose it. We delete these emails no later than 90 days after the validation cohort window closes. To ask us to delete yours sooner, write to support@smartmoneyradar.net. Lawful basis: consent, for the specific request you made.
Feedback re-submission marker. If you submit feedback on a dilution-check result, your browser remembers that fact locally under the key smr_dilution_feedback, purely so we do not show you the same form again. It holds no content and is never transmitted to us or anyone else.
4. What we do not do
- · We do not sell personal data, and we never will.
- · We run no advertising, no ad pixels and no cross-site tracking. The only analytics we run is the opt-in product analytics described above, and it never sets a tracking cookie.
- · We do not build behavioural profiles of you, and we take no automated decisions with legal or similarly significant effects.
- · We do not send marketing email unless you ask us to.
5. Cookies
One cookie: a signed, HTTP-only session token set when you sign in, so the site knows you are logged in. It is strictly necessary to deliver a service you asked for. Clearing it, or signing out, ends the session. Paddle's checkout sets its own cookies during payment, governed by Paddle's privacy notice. The product-analytics prompt described above is not a cookie banner — it governs the opt-in browser-storage identifier discussed in Section 3, not this cookie.
6. Who processes data on our behalf
- · Google Ireland/LLC— sign-in. Google authenticates you and tells us your verified email address. Your relationship with Google is governed by Google's own privacy policy.
- · Paddle.com Market Ltd — payments. Paddle is the merchant of record and an independent controller of the payment data you give it, not merely our processor. Its privacy notice governs that data.
- · Render Services, Inc. — application and database hosting.
- · Anthropic PBC — AI summaries. The prompt contains only ticker and signal data drawn from public filings. No account identifier, email or watchlist content is sent.
- · PostHog— opt-in product analytics, on PostHog's EU cloud, and only once you grant consent. Processes the anonymous identifier and the closed event set described in Section 3.
We will also disclose data where we are legally compelled to, or where it is necessary to establish or defend a legal claim.
7. International transfers
Some of these providers are established in, or process data in, the United States. Those transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses. PostHog's EU cloud keeps opt-in analytics data in the EU.
8. How long we keep it
- · Account data and watchlists: for as long as your account exists. Ask us to delete the account and it goes, along with the watchlist and usage counters.
- · Billing records and webhook payloads: kept after account closure for as long as needed to handle refunds, chargebacks and disputes, and to satisfy accounting and tax record-keeping obligations.
- · Notify/alert/waitlist emails: no later than 90 days after the validation cohort window closes.
- · Server logs: short-lived, on our hosting provider's standard retention.
9. Your rights
You have the right to access your data, to correct it, to erase it, to restrict or object to processing, and to receive it in a portable format. Where we rely on legitimate interest, you may object and we will stop unless we have compelling grounds to continue. Where we rely on consent — analytics and the email captures in Section 3 — you can withdraw it at any time. If you have not yet decided, declining (or simply not answering) the on-screen prompt keeps analytics off. If you have already granted analytics consent, withdraw it below; for an email capture you already gave us, write to us.
Write to support@smartmoneyradar.net from your account address. We answer within one month. There is no charge, and we will not make the account worse for you because you asked.
If you think we have handled your data badly, you can complain to your local supervisory authority. Ours is the Commission for Personal Data Protection of the Republic of Bulgaria (Комисия за защита на личните данни), Sofia.
10. Personal data inside the dataset itself
This is the unusual part, and it deserves a plain explanation rather than a footnote. The Service analyses public regulatory disclosures, and those disclosures name people: company officers and directors who file insider-transaction reports, legislators whose transactions are published under transparency rules, and fund managers named in institutional holdings filings. Processing their data is the entire point of a financial-transparency tool.
Our lawful basis is legitimate interest under Article 6(1)(f). The balancing runs as follows: every record comes from an official public register; the individuals were legally required to publish it, in a public-accountability regime designed to be read; we process only the disclosed transaction facts and no special-category data; and the purpose — making already-public financial disclosure legible — is the purpose the disclosure regime exists to serve. We add no inference about anyone's private life.
If you are named in this data and want to object, write to us. We will consider the objection on its merits, but note that we cannot alter or withdraw the underlying public record, and a request to suppress a lawfully published disclosure will usually be refused with reasons.
11. Security
Sessions use signed, HTTP-only tokens over HTTPS; entitlements are enforced server-side rather than in the browser; billing webhooks are signature-verified before they are trusted; and secrets are held in the hosting provider's secret store, never in the codebase. No system is perfectly secure, and we do not claim otherwise. If a breach is likely to put your rights at risk, we will tell you and the supervisory authority as the GDPR requires.
12. Children
The Service is not intended for anyone under 18, and we do not knowingly hold data about children. If you believe we do, tell us and we will delete it.
13. Changes
If we change this policy materially we will say so in the Service and update the revision date at the top of this page.
Provider identity
See our permanently accessible company details for the operator's registered identity, address and contact information.