Privacy Policy
Data protection in accordance with GDPR (EU 2016/679) and Spanish LOPDGDD 3/2018
Data controller
The data controller is the operator of TheAlphaInsider (the service provider), with the contact details published on this website.
What data we process
Account data: email address, name (optional) and password (stored as a one-way cryptographic hash — never in plain text). Newsletter data: email address and subscription status. Technical data: cookies required for operation (session, language preference), anonymised visit statistics (page path, date, referrer, user agent). Payment data is processed by Stripe, our payment provider — we never see or store card numbers.
Purposes
To provide the service (user account, premium status); to send the newsletter where subscribed; to maintain security and prevent abuse; to produce anonymised usage statistics; to comply with legal obligations.
Legal basis
Contract performance (providing the service you requested); consent (newsletter subscription — you may unsubscribe at any time with one click); legitimate interest (security and anonymised analytics); legal obligation (tax and accounting records).
Retention
Account data is kept while the account is active and up to the legally required periods thereafter. Newsletter data is kept until you unsubscribe. Visit statistics are kept anonymised for up to 24 months.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, portability and object to the processing of your data, and the right to withdraw consent at any time. You may exercise these rights by contacting us through the contact channel of this website. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).
Third parties
Stripe (payments, privacy policy at stripe.com/privacy); Resend (transactional and newsletter email delivery); SEC EDGAR and market data providers (public data sources); hosting providers. We do not sell or share personal data with third parties for marketing purposes.
Security
We apply appropriate technical and organisational measures: HTTPS encryption, hashed passwords, access control to databases, and minimisation of personal data collection.
Contact
For any question about this policy or to exercise your rights, contact us through the contact channel published on this website.
Last updated: August 2026.