Privacy Policy
Last updated: 14 August 2026
Traeva is operated by Simonas Tamkevicius, a sole proprietorship based in Ontario, Canada ("Traeva", "we", "us"). This policy explains what personal information we collect, why, who we share it with, and what you can do about it.
It is written to be read. Where a term has a specific legal meaning we say so plainly rather than hiding it.
Contact for any privacy question, including access and deletion requests: privacy@traeva.ca
1. The short version
- We collect your email address, your name and profile picture from whichever provider you sign in with, the companies you save, and the notes you write.
- We do not sell your personal information. We never have and the business model does not depend on it.
- We do not see or store your card details. Stripe handles payment and we only keep a customer reference.
- Analytics do not load until you agree to them.
- You can export or delete everything from your account settings.
2. What we collect
2.1 Information you give us
| What | When | Why |
|---|---|---|
| Email address | Sign-up, newsletter subscription | To identify your account, send the receipt Stripe generates, and send the weekly email if you asked for it |
| Name and profile image | Sign-in via Google, Apple or GitHub | Displayed in the header so you know whose account you are in |
| Watchlist tickers and your notes | When you add a company | To show you your own list. Notes are free text — please do not put anything sensitive in them |
| Average purchase price, if you enter one | Exit monitor | Used in your browser and in the request that computes exit boundaries. It is not stored |
2.2 Information collected automatically
| What | Purpose | Consent |
|---|---|---|
| Session cookie | Keeps you signed in | Strictly necessary — no consent required |
| Cookie-consent preference | Remembers your answer so we stop asking | Strictly necessary |
| Aggregate page views per company | Powers the "most viewed" list | Counted per company, not per person — we do not record who viewed what |
| Vercel Analytics and Speed Insights | Traffic volume and page performance | Only loaded if you accept. Decline and these never run |
| Server logs (IP address, user agent, timestamps) | Security, abuse prevention, debugging | Legitimate interest; retained ~30 days |
2.3 Information we deliberately do not collect
- Card numbers, expiry dates, CVCs. Payment happens entirely on Stripe's hosted page. We receive a customer ID and a subscription status; the card never touches our servers.
- Brokerage credentials or account balances. Traeva has no connection to any broker and never asks for one.
- Your actual holdings. A watchlist is a list of companies you are watching. It is not a portfolio, we do not ask what you own, and we do not infer it.
3. Why we are allowed to hold it
Under PIPEDA our basis is your consent, given when you create an account or subscribe to the newsletter. Where GDPR applies, our lawful bases are:
- Contract — account data and subscription status. We cannot provide a paid service without knowing who has paid.
- Legitimate interest — server logs and security measures, balanced against your interest in not being logged. We minimise retention accordingly.
- Consent — analytics and the weekly email. Both are optional and revocable at any time.
- Legal obligation — transaction records we are required to retain for tax.
4. Who else processes your information
We use third parties to run the service. Each receives only what it needs.
| Processor | What it receives | Where | Why |
|---|---|---|---|
| Vercel | Requests, IP addresses, logs; analytics only with consent | USA / global edge | Hosting |
| MongoDB Atlas | Account, watchlist, subscriber records | Configured region | Database |
| Stripe | Email, name, payment details you enter on their page | USA / global | Payment processing |
| Resend | Email address and message content | USA | Sending the weekly email |
| Sign-in only, if you choose it | USA | Authentication | |
| Apple | Sign-in only, if you choose it | USA | Authentication |
| GitHub | Sign-in only, if you choose it | USA | Authentication |
We do not send personal information to our market-data sources. Alpha Vantage, Financial Modeling Prep and the SEC receive only ticker symbols — they have no way to know which of our users, if any, was interested.
International transfers
We are in Canada; several processors are in the United States. Where GDPR applies, these transfers rely on Standard Contractual Clauses in the relevant processor's terms. You should know that information stored in or transiting the United States may be accessible to US authorities under their law.
5. How long we keep it
| Data | Retention |
|---|---|
| Account and watchlist | Until you delete your account |
| Newsletter subscription | Until you unsubscribe. We keep the unsubscribe record so we do not email you again by mistake |
| Payment and transaction records | 7 years after the transaction — Canadian tax law requires it, and this survives account deletion |
| Server logs | Approximately 30 days |
| Aggregate view counts | Indefinitely — they contain no personal information |
6. Your rights
Under PIPEDA, and under GDPR if you are in the EU or UK, you may:
- Access what we hold about you. Settings → Export my data returns it as JSON, immediately.
- Correct anything inaccurate.
- Delete your account and personal data. Settings → Delete my account does this. It cannot remove transaction records we are legally required to keep.
- Withdraw consent for analytics or the newsletter at any time, without losing access to anything you have paid for.
- Object to processing based on legitimate interest.
- Port your data — the export is machine-readable JSON for this reason.
We respond within 30 days. There is no charge.
If you are unhappy with our response you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca), or to your local supervisory authority if you are in the EU or UK.
7. Security
- All traffic is served over HTTPS.
- Sessions use signed, HTTP-only cookies.
- We store no passwords. Sign-in is delegated to Google, Apple or GitHub, or uses a one-time link sent to your email. There is no password database to breach because there is no password database.
- Database access is restricted and credentials are held as environment secrets, never in source control.
- Administrative actions are limited to an explicit allowlist.
No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your information we will notify you and the Privacy Commissioner as required, without undue delay.
8. Children
Traeva is not intended for anyone under 18 and we do not knowingly collect information from children. If you believe a child has given us information, write to privacy@traeva.ca and we will delete it.
9. Changes
We will post any change here and update the date at the top. If a change materially affects your rights we will email registered users before it takes effect. Continuing to use Traeva after that means you accept the revised policy.
10. Contact
Simonas Tamkevicius, sole proprietor Ontario, Canada