Draft for legal review: not yet in force. This template describes the data flows we can see in the product today. A privacy specialist must confirm the lawful bases, the processor list and transfer mechanisms, retention periods, the controller identity, and whether a representative or DPO is required, and must complete every [bracketed] item before this is published.
Privacy Policy
Last updated: [DATE] · Draft v0.1
1. Who is responsible for your data
MetalAlert is operated by Alert Technologies AB (a Swedish limited company, organisation number [ORG. NR.]), registered office [REGISTERED ADDRESS]. For the purposes of the EU General Data Protection Regulation (GDPR) and the Swedish Data Protection Act (dataskyddslagen, 2018:218), we are the controller of the personal information described here.
Because we are established in the EU, we are not required to appoint an Article 27 representative. [A Data Protection Officer is not mandatory for a service of this kind; if one is appointed voluntarily, give their contact details here.] You can reach our privacy contact at privacy@metalalert.ai.
2. The information we collect
We collect the following categories of personal information:
- Account information: your email address and a securely hashed version of your password. We never store your password in readable form.
- Subscription and billing information: your plan, trial and subscription status, renewal date, and identifiers from our payment processor (Stripe), such as a customer ID and subscription ID. Card payments are handled by Stripe; we do not receive or store your full card number. To prevent repeated abuse of the free trial we store a limited, non-reversible payment-method fingerprint provided by Stripe and, where a duplicate is detected, a record linking the affected email addresses.
- Usage information: which metals and pages you view in the app and when, and the alert rules you configure (metal, direction, magnitude, horizon, and thresholds). We use this to operate the Service and to understand which features are used.
- Alert records: a log of the alert emails we send you, including timestamp and the delivery provider's message identifier.
- Security and sign-in information: for each login, date and time, IP address, approximate location derived from that IP address (city, region, country, and coarse latitude/longitude), and browser/device information (user-agent). We also record failed login attempts (email and IP address) and may flag logins that appear geographically implausible relative to a previous one. This supports the single-active-session control and account-takeover protection.
- Referral information: if you use or share a referral link, a record connecting the referring and referred accounts and the reward status.
- Support and other communications: messages you send us and our replies.
- Diagnostic logs: technical error reports that may include your email address, the page URL, browser information, and IP address, used to diagnose and fix faults.
We do not intentionally collect special category data. Please do not send it to us.
3. How and why we use it
Under the GDPR, we rely on the lawful bases shown in brackets (to be confirmed by counsel):
- Create and administer your Account, provide the Service, and send the alert emails you configure [performance of a contract].
- Take payment, manage trials, renewals and cancellations, and keep billing records [performance of a contract; legal obligation for tax and accounting].
- Secure the Service and accounts: enforce the single-session limit, detect and investigate suspicious logins, prevent fraud and trial abuse, and keep audit logs [legitimate interests in protecting our users and our business; legal obligation where applicable].
- Understand feature usage and improve the Service, methodology and models [legitimate interests in operating and improving a product you have chosen to use].
- Provide support and respond to your requests [performance of a contract; legitimate interests].
- Operate the referral programme [performance of a contract; consent where required].
- Comply with law, enforce our terms, and establish, exercise or defend legal claims [legal obligation; legitimate interests].
- Send service and administrative messages (for example billing notices, security alerts, material changes to terms) [performance of a contract; legitimate interests]. See section 11 for marketing.
Where we rely on legitimate interests, we have considered the impact on you and do not use your information in ways you would not reasonably expect or that override your rights. Contact us for more detail on this balancing.
4. Cookies and similar technologies
The application uses a single strictly necessary cookie
(metalalert_auth) to keep you signed in. It is an httpOnly session
cookie and is not used for advertising or cross-site tracking.
We do not currently use advertising or third-party analytics cookies. [If any analytics, product-analytics, or marketing tags are added, list them here and implement a compliant consent mechanism.] The marketing site loads a web font from Google Fonts; this causes your browser to make a request to Google's servers, which involves your IP address. [Confirm whether to self-host the font to avoid this.]
5. Who we share it with
We do not sell your personal information. We share it with service providers who process it on our behalf under contract, and only as needed to run the Service:
- Stripe: payment processing, billing, and the customer billing portal.
- [Email delivery provider, e.g. Twilio SendGrid]: sending your alert and account emails.
- [IP geolocation provider, e.g. ip-api.com]: converting a login IP address into an approximate location for the security features described in section 2. Your IP address is sent to this provider for that lookup.
- [Cloud hosting / infrastructure provider]: hosting the application and database.
- [Error-monitoring provider, if used]: collecting diagnostic logs.
We may also disclose information to professional advisers, to authorities where required by law or to protect rights and safety, and to a buyer or successor in connection with a merger, acquisition, or sale of assets (subject to this policy). The market and reference data underpinning the probability estimates does not include your personal information.
[Maintain a current sub-processor list and link it here.]
6. International transfers
Some of our providers are located outside the EU/EEA, including in the United States. Where we transfer personal information outside the EU/EEA, we rely on an appropriate safeguard such as the European Commission's Standard Contractual Clauses, an adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified), or another mechanism permitted under Chapter V of the GDPR, together with additional measures where needed. Contact privacy@metalalert.ai for details or a copy of the relevant safeguards.
7. How long we keep it
We keep personal information only as long as needed for the purposes above:
- Account and subscription data: for the life of your Account and then for [period] after closure.
- Billing and accounting records: for 7 years, as required by the Swedish Bookkeeping Act (bokföringslagen).
- Security and sign-in logs, failed-login records, and diagnostic logs: for [period, e.g. 12 months], unless needed longer for an investigation.
- Trial-abuse fingerprints and related records: for [period].
- Support communications: for [period].
After the applicable period we delete or anonymise the information. Backups are overwritten on a rolling [period] cycle.
8. How we protect it
We use technical and organisational measures appropriate to the risk, including encryption of traffic in transit (HTTPS), storage of passwords using a strong one-way hashing algorithm, optional two-factor authentication (TOTP), a single-active-session control, screening of new passwords against known-breached credential lists, session-token revocation on password reset, access controls and logging for administrative actions, and least-privilege access for staff. No system is completely secure; we cannot guarantee absolute security.
9. Automated checks
To protect the Service we run automated checks that can affect access without a person reviewing each case first (for example flagging a login as geographically implausible, or blocking a sign-up that appears to reuse a payment method from a previous free trial). These checks are limited to fraud and abuse prevention and account security. If a check affects you and you believe it is wrong, contact support@metalalert.ai and a person will review it. [Confirm with counsel whether any of these constitute automated decision-making with legal or similarly significant effect and adjust safeguards and disclosures accordingly.]
10. Your rights
Depending on where you live, you may have some or all of the following rights: to access a copy of your personal information; to correct inaccurate information; to delete information; to restrict or object to certain processing (including processing based on legitimate interests); to data portability; and to withdraw consent where processing is based on consent, without affecting prior processing.
To exercise a right, contact privacy@metalalert.ai. We will respond within the time the law allows and may need to verify your identity. These rights have limits and exceptions (for example we may keep information needed for legal compliance, billing records, or fraud prevention).
[If serving California or other US-state residents, add the required state-specific disclosures: categories collected/disclosed, the right to know, delete, correct and opt out of "sale"/"sharing" and targeted advertising, and how to appeal a refused request. We do not sell personal information as defined by those laws.]
11. Marketing and email preferences
Alert emails and account/service emails are part of the Service you have signed up for. Any promotional email we send will include an unsubscribe link and our postal address, and you can opt out at any time without affecting your Subscription or the alert emails you have configured. We honour list-unsubscribe requests.
12. Children
The Service is for business use by adults. It is not directed to children and we do not knowingly collect information from anyone under 18. If you believe a child has provided us information, contact privacy@metalalert.ai and we will delete it.
13. Changes to this policy
We may update this policy. If changes are material we will give reasonable notice (for example by email or an in-product notice). The "last updated" date above shows the current version.
14. How to contact us or complain
Alert Technologies AB
[TRADING / CORRESPONDENCE ADDRESS]
Privacy contact: privacy@metalalert.ai
You may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, "IMY", imy.se), which is our lead supervisory authority, or with the supervisory authority in your own EU/EEA country of residence or work. We would appreciate the chance to address your concern first.