Privacy Policy
Your privacy choices
Optional product analytics are Unset for this request. Global Privacy Control always disables optional analytics.
TwinMarket Privacy Policy Effective date: July 22, 2026 1. Overview This policy describes the information TwinMarket handles when you browse the site, sign in with Google, save markets, or manage a subscription. It describes current product behavior; it is not a representation that every privacy law applies in the same way to every user. 2. Information Used to Provide the Service TwinMarket processes the information needed to operate features you request: - Account and authentication information: your email address, Google account identifier, TwinMarket username, account status, and terms-acceptance date. Google sign-in requests only OpenID and email scopes. Google's bearer credential is used only during the sign-in request and is not retained afterward. - Product information: saved market identifiers and the short-lived selections needed to render market comparisons. - Billing information: Stripe customer and subscription references, subscription state, renewal or cancellation state, and billing-period dates. Stripe handles payment-card details; TwinMarket does not store full card numbers or security codes. - Essential technical information: session cookies and security, hosting, CDN, and infrastructure records needed to deliver and protect the service. Infrastructure providers may temporarily process IP addresses, browser details, request timing, and security signals. TwinMarket does not request browser geolocation permission or collect precise device location through an in-app location flow. The application does not maintain a separate history of login IP addresses and user-agent strings. 3. Optional Product Analytics Optional product analytics are off unless you affirmatively choose Allow. Before opt-in, TwinMarket does not record product navigation, search, save, login, or checkout analytics. When enabled, analytics may contain a rotating analytics-session identifier, event type, pathname without a query string, same-site referrer pathname, general market type, performance measurements, query length, and result count. Search terms, OAuth codes and state, email addresses, Google identifiers, Stripe identifiers, access tokens, and external referrers are not retained in product analytics. An authenticated account preference overrides the choice stored for that browser. You may withdraw consent at any time through Privacy choices. A browser Global Privacy Control signal (Sec-GPC: 1) is treated as a denial of optional analytics. Raw opted-in product analytics have a 90-day retention period. Non-identifying daily event counts have a 24-month retention period. The daily cleanup process may complete deletion during the following 24 hours; failed cleanup is monitored as an operational incident. 4. Cookies and Browser Requests TwinMarket uses essential, HttpOnly cookies for session management, login, security, signup state, and privacy preferences. Optional analytics does not use advertising cookies. Application scripts, styles, icons, and fonts are hosted by TwinMarket. When a map is displayed, your browser requests map tiles from OpenStreetMap infrastructure, which may receive the technical request data needed to serve those tiles. Google receives data when you initiate Google sign-in, and Stripe receives data when you initiate or manage billing. 5. How Information Is Used Information is used to create and secure accounts, provide requested market and saved-market features, administer subscriptions, respond to support or verified privacy requests, maintain service reliability, investigate abuse, and meet applicable recordkeeping obligations. TwinMarket does not sell personal information and does not use product analytics for cross-context behavioral advertising. 6. Service Providers and Disclosures Information may be processed by Google for authentication, Stripe for subscriptions and payments, OpenStreetMap infrastructure for requested map tiles, and hosting, database, CDN, monitoring, and security providers that operate the service. Information may also be disclosed when reasonably necessary to respond to valid legal process, protect users or the service, enforce terms, or complete a business transfer subject to appropriate safeguards. The current field-level description, retention windows, deletion mechanisms, and recipient inventory is maintained in the engineering release record at `docs/production-tasks/privacy-data-inventory.md`. Cloudflare may process edge request metadata for proxy, TLS, and security functions; Render may process application data, PostgreSQL storage, backups, and operational logs. These provider-controlled logs and backups are explicit exceptions to application deletion timing and remain subject to provider settings, contractual limits, and applicable law. Application browser resources are self-hosted vendored Plotly, Bootstrap, Leaflet, jQuery, Lodash, and Inter font assets. YouTube and Google Fonts/CDN resources are not used by the runtime. Map views request tiles from OpenStreetMap, which receives the technical request data needed to serve those tiles. 7. Account Deactivation and Erasure You must first end an active paid subscription, and any unresolved Stripe state must be reconciled, before deactivating an account. Deactivation immediately disables the account, removes any legacy application OAuth credential, and signs the browser out. For 30 days after deactivation, signing in with the same Google account can reactivate the account. After that recovery period, TwinMarket deletes saved markets, OAuth records, and user-linked raw analytics, and anonymizes the account email, username, Google identifier, and last-seen information. A later sign-in creates a new account. Pseudonymous billing facts may be retained for seven years after the transaction or account closure, whichever is later, for bookkeeping, chargeback and subscription disputes, fraud prevention, tax, audit, and other recordkeeping needs. This is the proposed operational minimum and remains subject to counsel confirmation. Records can be retained longer when preservation is required for a specific dispute or valid legal obligation. Short-lived pending Checkout coordination records are removed after Stripe confirms completion or expiry. If a provider response is interrupted or delayed, the record remains restricted and account deactivation is paused until an operator safely reconciles the exact Stripe state; elapsed local time alone does not delete it. Pending-signup records expire after 15 minutes and are physically removed by the daily retention job. Infrastructure logs and backups are limited to approximately 30 days where provider controls permit. Deletion from rotating backups may take effect as those backups expire. Pseudonymous erasure tombstones are signed and exported to restricted storage; the restore procedure replays the latest export before traffic resumes so erased account data is not reintroduced from an older backup. 8. Your Choices and Requests You can allow or decline optional analytics through Privacy choices, cancel subscription renewal from Manage Subscription, and deactivate an eligible account online. To request a copy of account information or verified early erasure, email hello@twinmarket.ai. TwinMarket verifies the requester before an operator runs the restricted export or erasure process. Exports exclude OAuth tokens, credentials, provider secrets, and internal security information. 9. Security TwinMarket uses administrative and technical safeguards designed to reduce unauthorized access, disclosure, alteration, and loss. No transmission or storage system can be guaranteed completely secure. 10. Children's Privacy TwinMarket is intended for adults and is not directed to children under 18. 11. Changes This policy may change as the product, providers, or data practices change. Material changes will be reflected by an updated effective date and, when appropriate, an additional notice. 12. Contact Privacy questions and verified requests: hello@twinmarket.ai