Privacy Policy
This Privacy Policy describes how your personal information is collected, used, and shared when you visit Pelosi Tracker.
Dernière mise à jour : 10 February 2026
Avis de confidentialité (résumé)
Nous traitons des données personnelles pour fournir votre compte (Firebase/Google), gérer les paiements et abonnements (Stripe), analyser l'utilisation du site (Google Analytics) et envoyer des e-mails (SendGrid/Twilio).
Pour toute demande (accès, rectification, suppression), contactez : [email protected]. Vous pouvez également déposer une plainte auprès de la CNIL (cnil.fr).
La version anglaise fait foi en cas de divergence.
Ce document est disponible en anglais uniquement. La version anglaise fait foi.
1. Introduction
At Pelosi Tracker, we respect your privacy and are committed to protecting your personal data. This privacy policy will inform you about how we look after your personal data when you visit our website and tell you about your privacy rights and how the law protects you.
This privacy policy applies to all users of our website at pelositracker.app.
We are based in the United Kingdom. If you are located in the European Economic Area (EEA), the EU General Data Protection Regulation (GDPR) applies to our processing of your personal data. If you are located in the United Kingdom, the UK GDPR and Data Protection Act 2018 apply.
2. Information We Collect
2.1. Personal Information
When you create an account or subscribe to our service, we collect:
- Name
- Email address
- Password (stored in encrypted/hashed form — we never store plain-text passwords)
- Account preferences and settings
2.2. Payment Information
When you subscribe to a paid plan, payment information (card number, billing address) is collected and processed directly by Stripe. We do not store your full card details on our servers. We receive from Stripe: a truncated card number (last 4 digits), card brand, billing country, and subscription status.
2.3. Usage Data
We automatically collect certain information when you visit, use, or navigate our website. This information does not reveal your specific identity but may include:
- IP address (anonymised where possible)
- Browser and device characteristics
- Operating system
- Referring URLs
- Pages viewed and time spent on pages
- Interactions with features (e.g. watchlist actions, portfolio views)
2.4. Cookies and Similar Technologies
We use cookies and similar tracking technologies to track activity on our website and store certain information.
Essential cookies are required for the website to function (e.g. authentication session, language preference). These do not require your consent.
Analytics cookies (Google Analytics) are used to understand how visitors interact with our website. These cookies are only set after you provide consent via our cookie banner.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept essential cookies, you may not be able to use some portions of our Service.
3. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Provide, operate, and maintain your account and the Service | Performance of a contract with you |
| Process subscription payments | Performance of a contract with you |
| Send transactional emails (account verification, password reset, subscription confirmations) | Performance of a contract with you |
| Send notification emails you have opted into (new filings, weekly summaries) | Your consent (you can unsubscribe at any time) |
| Analyse website usage to improve the Service | Legitimate interest (improving our product) |
| Detect and prevent fraud or abuse | Legitimate interest (security) |
| Comply with legal obligations | Legal obligation |
4. Third-Party Data Processors
We share your personal data with the following third-party service providers who process data on our behalf:
4.1. Firebase (Google Cloud)
- What they process: Email address, authentication credentials, account data, user-generated content (watchlists, portfolio settings, notification preferences)
- Purpose: User authentication, database storage, hosting
- Data location: United States and European Union
- Privacy policy: firebase.google.com/support/privacy
4.2. Stripe
- What they process: Name, email address, payment card details, billing address, transaction history
- Purpose: Payment processing, subscription management, invoicing
- Data location: United States and European Union
- Note: Stripe is the payment processor — we do not store your full card details. Stripe is PCI DSS Level 1 certified.
- Privacy policy: stripe.com/privacy
4.3. Google Analytics
- What they process: Anonymised IP address, device/browser information, pages viewed, session duration, referral source
- Purpose: Understanding how visitors use the website to improve the Service
- Data location: United States
- Note: Analytics cookies are only activated after you provide consent. We use IP anonymisation where available.
- Privacy policy: policies.google.com/privacy
4.4. SendGrid (Twilio)
- What they process: Email address, name, email content
- Purpose: Sending transactional and notification emails (account verification, password resets, filing alerts, weekly summaries)
- Data location: United States
- Privacy policy: twilio.com/legal/privacy
5. International Data Transfers
Your personal data may be transferred to and processed in the United States by our third-party processors listed above. These transfers are protected by:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- EU-US Data Privacy Framework (where the processor is certified)
- UK International Data Transfer Agreement (UK IDTA) or UK Addendum to SCCs
Each of our processors maintains appropriate safeguards for international data transfers in accordance with applicable data protection law.
6. Data Sharing and Disclosure
Beyond the processors listed in Section 4, we may share your information in the following situations:
6.1. Business Transfers
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your data may be transferred as part of that transaction. We will notify you before your personal data is transferred and becomes subject to a different privacy policy.
6.2. Legal Requirements
We may disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process.
6.3. With Your Consent
We may disclose your personal information for any other purpose with your consent.
We do not sell your personal data to third parties.
7. Data Security
We have implemented appropriate technical and organisational security measures designed to protect the security of any personal information we process, including:
- Encrypted data transmission (HTTPS/TLS)
- Hashed password storage
- Access controls and authentication for administrative systems
- Regular security reviews
However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure.
8. Data Retention
We retain your personal data for the following periods:
| Data Type | Retention Period |
|---|---|
| Account data (name, email, preferences) | Duration of your account, plus 30 days after deletion |
| Payment and subscription records | 7 years after the transaction (legal/accounting requirements) |
| Analytics data (Google Analytics) | 14 months (Google Analytics default retention) |
| Email delivery logs (SendGrid) | 30 days |
| Authentication logs | 90 days |
When you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required by law to retain certain records.
9. Your Data Protection Rights
Depending on your location, you have the following rights regarding your personal information:
- Right to Access: You have the right to request copies of your personal data.
- Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
- Right to Object to Processing: You have the right to object to our processing of your personal data, under certain conditions.
- Right to Data Portability: You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.
- Right to Withdraw Consent: Where we process your data based on consent (e.g. analytics cookies, notification emails), you may withdraw consent at any time.
If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us at: [email protected].
9.1. Right to Complain to a Supervisory Authority
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a data protection supervisory authority:
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- France: Commission Nationale de l'Informatique et des Libertés (CNIL) — cnil.fr
- Other EU/EEA countries: Your local data protection authority
10. Children's Privacy
Our Service does not address anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us.
11. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. For material changes, we will notify registered users by email.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
12. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Email: [email protected]