Privacy Policy
How we collect, use, and protect your information
Fortfolio.io Privacy Policy
Effective Date: November 3, 2025
Last Updated: November 3, 2025
At Fortfolio.io ("Fortfolio," "we," "us," or "our"), we are committed to protecting your privacy. This Privacy Policy ("Policy") explains how we collect, use, disclose, and safeguard your information when you use our website (fortfolio.io), services, including our proprietary options screener, investment strategies, educational resources, alerts, and private Discord community (collectively, the "Services"). This Policy applies to all users, including subscribers. By using the Services, you consent to the practices described herein. If you do not agree, please do not use the Services.
We comply with applicable data protection laws, including the California Consumer Privacy Act (CCPA), General Data Protection Regulation (GDPR) where applicable, and Federal Trade Commission (FTC) guidelines. We do not sell your personal information.
1. Information We Collect
We collect information to provide and improve the Services. This includes:
- Personal Information: Name, email address, billing address, and contact details provided during account creation, subscription, or inquiries.
- Payment Information: For subscriptions, we collect details such as credit card numbers, expiration dates, and CVV via secure third-party processors (e.g., Stripe). We do not store full payment details on our servers; only tokenized references are retained.
- Usage Data: IP address, browser type, device information, pages visited, and interaction data (e.g., screener usage) collected via cookies and analytics tools.
- Financial Data: Non-sensitive preferences or strategy inputs you provide; we do not collect sensitive financial account details.
- Community Data: Usernames, posts, and interactions in our Discord community.
We collect this minimally, only as necessary, to reduce breach risks.
2. How We Use Your Information
We use your information to:
- Provide Services: Process subscriptions, deliver screener alerts, and facilitate community access.
- Handle Payments: Transmit necessary data to third-party processors for transaction fulfillment.
- Improve and Personalize: Analyze usage for enhancements, with anonymized data where possible.
- Communicate: Send updates, newsletters, or support responses (with opt-out options).
- Ensure Security: Detect fraud or unauthorized access.
- Comply with Law: Respond to legal requests or audits.
3. Sharing Your Information
We do not sell or rent your information. We share it only as follows:
- Third-Party Service Providers: With vetted partners for essential functions, such as payment processors (e.g., Stripe) who handle billing securely under their own privacy policies (linked: stripe.com/privacy). We share only minimal data (e.g., name, address, payment method) and require contractual safeguards like encryption and compliance audits.
- Affiliates and Business Transfers: In mergers or acquisitions, with notice.
- Legal Requirements: If compelled by law, subpoena, or to protect rights (e.g., fraud prevention).
- Aggregated Data: Anonymized insights shared for research, without identifying you.
4. Third-Party Payment Processing
We use secure third-party processors like Stripe for all transactions. Your payment information is transmitted directly to them via encrypted channels (e.g., SSL/TLS). We receive only confirmation and tokenized data, minimizing our exposure. Review the processor's policy for details on their handling. This approach complies with PCI DSS standards, avoiding direct storage pitfalls that led to $100M+ fines in 2025 breaches.
5. Data Security
We employ industry-standard measures:
- Encryption for data in transit and at rest.
- Tokenization for payment info.
- Access controls, firewalls, and regular audits.
- Vetting of third parties for compliance (e.g., SOC 2 certification).
Despite this, no system is infallible; breaches could occur. We notify affected users per CCPA/GDPR timelines.
6. Cookies and Tracking Technologies
We use cookies for functionality (e.g., session management) and analytics (e.g., Google Analytics). You can manage preferences via browser settings or our consent banner. Third-party tools may track usage; opt-out via their policies.
7. Your Rights and Choices
Depending on your location:
- Access, correct, or delete your data.
- Opt-out of marketing or data sharing (CCPA "Do Not Sell").
- Withdraw consent (GDPR).
Email requests to support@fortfolio.io; we respond within 30-45 days. For payments, contact the processor directly.
8. Children's Privacy
Services are not for users under 18; we do not knowingly collect their data. If discovered, we delete it immediately.
9. International Transfers
Data is stored in the US; for EU users, we use Standard Contractual Clauses for transfers, ensuring GDPR compliance.
10. Changes to This Policy
We may update this Policy; changes are posted with the "Last Updated" date. Continued use constitutes acceptance. Major changes trigger email notices.
11. Contact Us
For questions or requests: support@fortfolio.io or [mailing address]. For California residents, toll-free: [number].
This Policy integrates with our Terms and Conditions. By using Fortfolio.io, you acknowledge understanding these practices.