Who we are
Blue Ridge Banker LLC (“we”, “us”) runs The Market Terminal and is responsible for the personal information described here. This policy covers the website at themarketterminal.com, the terminal and the API behind it, and the emails we send. Our contact details are at the end.
The short version
- We collect what the service needs to work: your email address and password (held by our sign-in provider), what you save in the terminal, and references to your plan and billing.
- Stripe takes payments on its own pages. We never see or store your card number.
- We do not sell your personal information or share it for advertising. The site sets no cookies of its own and carries no advertising or cross-site tracking.
- Our page analytics are our own, store no IP addresses, and send nothing at all if your browser sends Global Privacy Control or Do Not Track.
- You can ask to see, correct, export or delete your information by emailing blueridgebanker@themarketterminal.com.
What we collect
Your account
When you create an account we collect your email address and a password, and your name if you give one. Supabase, which runs our sign-in, stores the password only as a hash, so nobody can read it, us included. It also records when you signed up and last signed in, and whether you confirmed your address. A profile photo added at signup stays in your browser, where it decorates your terminal pass; it is never uploaded.
Your plan and billing
Your profile records your plan, how you got it (for example a subscription or a Desk seat) and, if you subscribe, your Stripe customer and subscription IDs and the date your paid period ends. When you start a checkout we send Stripe your email address, your account ID, the plan and the number of seats. Stripe collects your card and billing details on its own page and keeps them; we receive only those IDs and the state of your subscription.
What you save in the terminal
When you are signed in, the terminal saves these to your account so they follow you from device to device: your watchlist; portfolios, transactions (with any notes) and portfolio settings; baskets; price alerts; theme, layout and chart preferences; and, in the Desk plan’s Charts workspace, your chart drawings and saved layouts. Signed out, they stay in your browser only.
On a Desk plan team we also keep the team’s name, its members and their roles, pending invitations (the invited email addresses), and the team’s shared watchlists with who created and last edited each. Everyone on the team can see the roster, including members’ email addresses and roles; the plan holder and admins also see pending invitations.
Push notifications
If you turn on push notifications with the bell in the watchlist sidebar, your browser creates a push subscription: an address at your browser maker’s push service and the keys to encrypt messages to it. We store that with the symbols on your watchlist, your email address if you are signed in, and your browser’s user-agent string, plus a log of which alerts we have sent to it so that the same alert is not sent twice.
Email lists
When you subscribe to the Market Intelligence Bulletin or to 13F filing alerts, we store your email address with your settings (the bulletin’s categories and threshold, or the funds you follow), when you subscribed and confirmed, and whether you have confirmed. No bulletin or alert is sent to an address until it is confirmed. So that no bulletin signal reaches you twice, we also keep a note of the signals already sent to each address.
The newsletter list on the Newsletter page is a form hosted by our email delivery provider. What you type into it goes straight to that provider and is kept in its contact list for the newsletter.
Usage analytics
We count page views and a few product events (opening the pricing page, meeting a feature your plan does not include, clicking to upgrade) with our own analytics, not a third-party tracker. Each record holds the event, the page path without its query string, the domain of the site that linked you (not the page), your plan, any campaign tags in the link you followed, and a visitor code: a one-way hash of your IP address and browser that changes every day. We do not store your IP address, and one day’s code cannot be linked to the next. For checkouts, trial conversions and cancellations, our server records the event against your account.
If your browser sends Global Privacy Control or Do Not Track, the site sends no analytics at all.
Error reports
When a page fails to load data it may send us an error report: the error message, the address of the request that failed, the page’s path, your browser’s user-agent string and the time. Our API adds your IP address and writes the report to its server logs.
Server logs
As on any website, the services that host the site and the API (GitHub Pages and Vercel) and our database and sign-in provider (Supabase) record technical details of each request in their logs, such as the IP address, the browser’s user-agent string, the address requested and the time. Our API also holds your IP address briefly, in memory, to limit how many requests one address can make.
Email you send us
If you write to us, we keep your message and our reply in our mailbox.
People named in the research
The research content includes information about company executives and directors and about fund managers, taken from public sources such as SEC filings: names, roles, pay, trades and leadership changes. It is public-record business information, used to describe the companies and funds concerned.
What stays in your browser
The site sets no cookies of its own and uses no advertising or cross-site tracking cookies. It keeps these in your browser’s local and session storage:
- your sign-in session, so that you stay signed in;
- a working copy of what you save in the terminal (watchlist, alerts, portfolios, baskets, drawings), which syncs to your account while you are signed in and is removed from the browser when you sign out;
- display preferences such as theme, density, layout and chart type;
- your recent searches and tools, and copies of market data the pages have loaded, so that they open faster;
- the address and token of any bulletin or 13F alert subscription confirmed in this browser, so you can manage it from here;
- the profile photo you added at signup, if any, and a note of a checkout in progress.
The site’s service worker keeps copies of the site’s own files (a few pages, code, styles and images) so that pages open faster and work offline; it does not store your data or our API’s responses. You can clear all of this in your browser’s settings.
Pages run by others that you reach from the site, such as Stripe’s checkout and billing pages and the newsletter form on the Newsletter page, follow their providers’ own policies and may set their own cookies.
How we use it
- To run the service: sign you in, save and sync what you save, check your alerts and send the notifications you turned on, and give you your plan’s features.
- To bill you and manage your subscription through Stripe.
- To send email: the lists you subscribed to, account email (address confirmation, password reset), Desk plan invitations, and notices about the service and these policies.
- To keep the service working and secure: rate limits, preventing abuse and fraud, and finding and fixing errors.
- To understand, in aggregate, which pages are used and where people stop on the way to a paid plan, so that we can improve them.
- To comply with the law and enforce our terms.
We do not use your information for advertising, we do not build profiles of you for anyone else, and we make no decisions about you by automated means that have legal or similarly significant effects.
Service providers
These companies run parts of the service for us and receive personal information only to do that work:
- Supabase
- Our database and sign-in. Stores your account, profile, saved data, Desk plan team data, push subscriptions and analytics events; sends account email (address confirmation and password reset); runs the scheduled job that sends push notifications.
- Vercel
- Hosts our API, which serves the terminal its data, handles checkout and subscriptions, and sends our email through our email delivery provider. Its logs include request details.
- GitHub Pages
- Hosts the website today and logs requests to it.
- Stripe
- Checkout, subscriptions, invoices and the billing portal. Receives your email address, account ID, plan and seat count, and collects your payment details directly.
- Email delivery provider
- Currently SendGrid (Twilio). Sends the Market Intelligence Bulletin, 13F filing alerts, subscription confirmations and Desk plan invitations, so it receives each recipient’s address and the message. Also hosts the newsletter form and its list.
- Upstash (Vercel KV)
- Stores bulletin and 13F alert subscriptions and short-lived working data, such as limits on how often we email an address, and caches market data.
- Microsoft 365
- Our mailbox, for email you send us and our replies.
- Google Fonts
- Serves the site’s typefaces. Your browser downloads them from Google, which receives your IP address and browser details as part of that request.
- Plotly
- The Hyperliquid Funding page loads the Plotly charting library from Plotly’s content delivery network, which receives the same request details.
- Your browser’s push service
- Run by your browser’s maker (for example Google, Mozilla, Apple or Microsoft). Delivers push notifications if you turn them on; each message is encrypted for your browser.
- Market data sources
- Our servers fetch prices, filings and economic data from sources such as Yahoo Finance, FRED, SEC EDGAR and CoinGecko. Those requests come from our servers and carry no personal information about you.
When we share it
We share personal information only:
- with the service providers above, so that they can run the service for us;
- within a Desk plan team, as described above;
- when the law requires it, or to protect the rights, safety or property of our users, the public or us;
- as part of a merger, acquisition, financing or sale of assets, in which case this policy keeps applying to it; or
- with your consent.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in the California Consumer Privacy Act, as amended by the California Privacy Rights Act. We have not done so in the past 12 months.
How long we keep it
- Your account and what you save
- For as long as your account is open. When you ask us to delete your account, we delete your sign-in record and the data tied to it (profile, saved data, alerts, chart drawings and layouts, Desk plan team membership, and any push subscription under your address) from our database. Copies in our providers’ backups are overwritten on their schedules. Email list subscriptions are separate from your account: unsubscribing deletes them.
- Billing records
- Stripe keeps records of payments for as long as the law requires.
- Email list subscriptions
- Until you unsubscribe, which deletes the record. An address that is never confirmed is never mailed; ask and we will delete it. The note of bulletin signals sent to an address expires 30 days after it was last updated.
- Push subscriptions
- Until the push service tells us the subscription has ended, when we stop sending to it. Ask and we will delete it sooner.
- Analytics events
- Up to 24 months from when they are recorded, after which they are deleted. An event recorded against an account loses that link when the account is deleted.
- Error reports and server logs
- For our hosting and database providers’ standard log-retention periods.
- Email you send us
- As long as we need it to deal with your message and keep business records.
Security
The site, the API and our providers use HTTPS. Passwords are hashed by our sign-in provider. In the database, row-level security limits each account to its own records, and a Desk plan team to its team’s; the keys that bypass it are kept on our servers. Payment details go straight to Stripe. The links in our emails that confirm or cancel a subscription are signed, so each works only for the address it was sent to.
No system is completely secure. If a breach affects your information, we will tell you as the law requires.
Your rights and choices
Wherever you live, you can ask us to:
- tell you what personal information we hold about you, and give you a copy;
- correct it;
- delete it, with your account;
- export what you have saved, in a portable format.
Email blueridgebanker@themarketterminal.com from the address on your account, or tell us enough to find the records, such as the address you subscribed with. We may need to confirm that the request comes from you. We reply within 30 days; if we cannot do all of what you ask, we will say why, and you can ask us to reconsider. Using these rights will never change the service or the price you get.
Some of this you can do yourself:
- Export: on the Account page, Export data downloads your watchlist and alerts.
- Correct: edit what you save in the terminal; reset your password from the sign-in page.
- Unsubscribe: use the link in any bulletin or 13F alert email, or the forms on the Newsletter and Allocators pages.
- Push notifications: turn them off with the bell in the watchlist sidebar, or in your browser’s settings.
- Analytics: turn on Global Privacy Control or Do Not Track in your browser.
- Browser storage: sign out to remove your saved data from the browser, or clear the site’s data in your browser’s settings.
California residents
If you live in California, the California Consumer Privacy Act, as amended, gives you the rights above (to know, correct and delete, and to opt out of the sale or sharing of personal information, which we do not do) and the right not to be treated differently for using them.
In the past 12 months we have collected these categories of personal information, from you, your browser and our providers, for the purposes in How we use it: identifiers (such as your email address, account ID and IP address); commercial information (your plan and subscription); internet activity (page views, error reports and request logs); and, as sensitive personal information, only your account sign-in, which we use only to provide the service. We disclosed them for business purposes only to the service providers listed above. You may make a request through an authorized agent; we will ask for proof that the agent acts for you.
Outside the United States
The Market Terminal is run from the United States, and your information is stored and processed in the United States and wherever our service providers operate.
If you are in the European Economic Area, the United Kingdom or Switzerland, we process your information: to perform our contract with you (your account, subscription, saved data, alerts and the email you asked for); for our legitimate interests in running, securing and improving the service (logs, rate limits, error reports and our analytics, which store no IP address); with your consent (push notifications, and the email lists, which you confirm); and to meet legal obligations. You also have the right to object to or restrict processing, to withdraw consent at any time, and to complain to your data protection authority. Where the law requires it, transfers rely on safeguards our providers offer, such as the European Commission’s standard contractual clauses.
Children
The service is not for anyone under 18, and we do not knowingly collect personal information from children. If you think a child has given us information, email blueridgebanker@themarketterminal.com and we will delete it.
Changes
We may update this policy. The “Last updated” date at the top shows the current version. If a change is material, we will tell account holders by email or in the service before it takes effect.
Contact
For privacy questions and requests:
Blue Ridge Banker LLCblueridgebanker@themarketterminal.com