Back

Privacy Notice

Updated April 12, 2026

This privacy notice explains the type, scope, and purpose of processing personal data (hereinafter referred to as "data") in connection with the provision of our services, as well as within our online offering and its related websites, functions, and content, including external online presences such as our social media profiles (collectively referred to as the "Online Offering"). The terminology used, such as "processing" or "controller," is based on the definitions in Article 4 of the General Data Protection Regulation (GDPR).

Controller

Robinson Guerra (for DREAVERR Digital Solutions LLP)
Email: [email protected]

Types of Data Processed

  • Inventory Data: e.g., names, addresses.
  • Contact Data: e.g., email addresses.
  • Content Data: e.g., watchlists, saved searches, alert configurations.
  • Usage Data: e.g., visited pages, screener interactions, access times.
  • Meta/Communication Data: e.g., device information, IP addresses.
  • Payment Data: e.g., credit card details, billing address, transaction details (processed by Paddle).

Categories of Data Subjects

Visitors and users of the Online Offering (hereinafter collectively referred to as "users").

Purpose of Processing

  • To provide the Online Offering, its functions, and content including screeners, charts, pattern detection, and API access.
  • To process payments and deliver services related to the payment provider Paddle.
  • To respond to contact inquiries and communicate with users.
  • To send pattern alert notifications and email reports.
  • To implement security measures and rate limiting.
  • For reach measurement and service improvement.

Use of the Payment Provider Paddle

To process payments, we use the payment provider Paddle, which acts as a "reseller" on our behalf. Paddle collects and processes payment data such as credit card details, transaction information, and billing addresses to handle transactions and comply with legal obligations.

Use of Google OAuth

If you choose to sign in with Google, we receive your name, email address, and profile image from Google. We do not receive or store your Google password. Google's privacy policy applies to the authentication process.

Legal Bases

The processing of personal data is based on the GDPR:

  • Consent under Article 6(1)(a) GDPR.
  • Fulfillment of contractual obligations under Article 6(1)(b) GDPR (e.g., payment processing through Paddle).
  • Compliance with legal obligations under Article 6(1)(c) GDPR.
  • Protection of legitimate interests under Article 6(1)(f) GDPR (e.g., fraud prevention, security).

Security Measures

We implement technical and organizational measures to ensure an appropriate level of security, taking into account the risks to the rights and freedoms of natural persons. Passwords are hashed using industry-standard algorithms (bcrypt). All data transmission is encrypted via HTTPS/TLS. Paddle employs its own security measures to safeguard payment data confidentiality and integrity.

Data Sharing

Personal data is shared with Paddle only to the extent necessary for payment processing. Paddle processes this data in compliance with legal requirements. Further sharing occurs only when legally required or necessary for fulfilling contractual obligations. We do not sell, rent, or share your personal data with third parties for marketing purposes.

Data Transfers to Third Countries

Data may be transferred to third countries (outside the EU, EEA, or Switzerland) as part of payment processing through Paddle. Paddle ensures that all data transfers comply with GDPR, for example, through Standard Contractual Clauses.

Data Subject Rights

Under applicable data protection laws, you have the following rights:

  • Access your processed data and obtain copies.
  • Rectify inaccurate data.
  • Request deletion of your data. You can delete your account at any time from the settings page.
  • Restrict the processing of your data.
  • Transfer your data to another controller (data portability).
  • Withdraw your consent at any time with future effect.
  • Object to data processing for direct marketing or based on legitimate interests.
  • File a complaint with a supervisory authority.

Cookies & Tracking

StockMarketScan uses essential cookies required for authentication and session management, as well as analytics and advertising cookies with your consent. Cookies set by Paddle for payment processing are necessary. Users can disable cookies in their browser settings, which may limit the functionality of the Online Offering.

We use the following third-party services:

  • Google Analytics 4 (GA4) — We use GA4 to analyze website traffic and user behavior. GA4 collects data such as page views, session duration, device information, and approximate location (based on IP address). Google may transfer data to servers in the United States. For more information, see Google's Privacy Policy.
  • Google Ads Conversion Tracking — We use Google Ads to measure the effectiveness of our advertising campaigns. When you interact with an ad and visit our site, a conversion cookie may be set to track whether a specific action was completed.
  • Google Tag Manager (GTM) — GTM is a tag management system that allows us to manage analytics and marketing tags. GTM itself does not collect personal data but triggers other tags that may.
  • Resend — We use Resend (powered by Amazon SES) to send transactional emails such as account verification, password resets, and pattern alerts. Your email address is shared with Resend solely for email delivery purposes.

For visitors in the European Union, analytics and advertising cookies are only activated after you provide consent via our cookie banner (Google Consent Mode v2). You can withdraw consent at any time by clearing your browser cookies.

Data Retention

Data is deleted in accordance with legal requirements when it is no longer necessary for the purposes for which it was collected. When you delete your account, all personal data is permanently removed within 30 days. For data processed by Paddle, Paddle's retention policies apply.

MCP Server (Model Context Protocol)

StockMarketScan provides an MCP server at mcp.stockmarketscan.com that allows third-party AI clients (such as Cursor, Continue, and similar tools) to access our stock screener, chart pattern, and options flow tools on your behalf.

Data processed via MCP:

  • API Key: Your personal sms_* API key is transmitted by your MCP client to authenticate requests. The server validates the key per session but does not store it beyond the session lifetime.
  • Tool Requests: The queries you submit (e.g., stock symbols, screener names, date ranges) are forwarded to our API to generate results. These are subject to the same processing purposes and retention policies as direct API usage.
  • OAuth Tokens: If you connect via OAuth 2.1 (e.g., through a browser-based MCP client), we issue a bearer token linked to your existing account. No additional personal data is collected beyond what is already stored in your account.

Data not collected via MCP:

  • We do not receive, store, or process the prompts you send to your AI client.
  • We do not receive or store the AI-generated responses.
  • We have no access to your conversations, chat history, or any data held by the AI client.

The MCP server acts as a pass-through: it receives structured tool calls, fetches the requested market data from our API, and returns the result. All data transmitted between your MCP client and our server is encrypted via HTTPS/TLS.

Changes to This Privacy Notice

We reserve the right to update this privacy notice to reflect changes in legal requirements or our services. Users will be notified of significant changes.

Contact Information

For privacy-related questions or requests, contact us:

Email: [email protected]

DREAVERR Digital Solutions LLP
1103 - 11871 Horseshoe Way
Richmond, British Columbia, Canada V7A 5H5