Skip to content
MARKET CONTEXT PLATFORMNOT FINANCIAL ADVICE

Privacy Policy

Last updated:

This Privacy Policy explains how MarketDepth Analytics OÜ ("we", "us", "Company"), the operator of DepthSignal, collects, uses, stores, and protects your personal data. We design our data-handling practices to support the General Data Protection Regulation (GDPR) and other applicable data protection laws.

1. Data Controller

The data controller responsible for your personal data is (GDPR Article 13(1)(a)):

  • Company: MarketDepth Analytics OÜ
  • Registration: Estonian Business Registry, reg. code 17549629
  • Registered: Republic of Estonia, European Union (full address: /legal/imprint)
  • Email: [email protected]

2. What We Collect

We collect the minimum data necessary to provide and improve our service:

Data CategorySpecific DataPurpose
Account informationEmail address, password hash, company name (optional)Account creation, authentication, communication
API credentialsAPI key identifier and secure credential record (raw API keys are not retrievable after issuance)API authentication, request attribution
API usage logsRequest timestamps, endpoints called, response codes, IP addressRate limiting, abuse prevention, service improvement
Subscription dataTier, billing cycle dates, subscription statusService delivery, billing management
Newsletter subscriptionEmail address, subscription source, confirmation statusSending product updates and market-context research notes (double opt-in)
Market context notificationsNotification name, condition, threshold, delivery channelDelivering the market-data and account notifications you configure
Connected accountsDiscord username, OAuth tokens (encrypted)Tier-gated Discord channel access, account linking
Feedback and bug reportsCategory, message text, browser metadata (voluntary)Product improvement and bug resolution
Two-factor authenticationEncrypted TOTP secret, hashed recovery codes, 2FA enablement status; phone number (E.164 format, hashed at rest) if SMS 2FA is enabled (transmitted to Twilio, Inc. for SMS delivery only)Account security, preventing unauthorised access
Session dataIP address, user agent, hashed session token, last active timestampSession management, security monitoring
Security audit logLogin attempts, key rotations, account changes, IP address (append-only)Security monitoring, fraud prevention (legitimate interest)
Consent recordsConsent action, IP address, timestampDemonstrating GDPR compliance (legal obligation)
Social account connectionsLinked platform IDs and usernames (Google, GitHub, Discord, X), only when you connect themOAuth account linking, tier-gated access (e.g. Discord)

DepthSignal is a market-data analytics service. We provide visible market context and supporting analytics. We do not handle funds, execute orders, or connect to your exchange accounts. We have no access to your exchange credentials, balances, or order history. Account credentials are stored using one-way cryptographic controls and cannot be recovered in plaintext.

3. Payment Data

There is no active payment provider currently proved. While that remains true, the published payment fallback is manual invoicing plus SEPA bank transfer after approval, and DepthSignal stores the customer, invoice, payment reference, settlement, refund, and tax records needed to operate that finance workflow.

DepthSignal's finance/tax system remains the system of record for payment references, invoice records, refund records, settlement tracking, and VAT/GST monitoring. Any future PSP, card processor, bank rail, or merchant-of-record path must attach to that system as an adapter before payment-provider data processing is republished.

5. How We Use Your Data

  • To create and manage your DepthSignal account.
  • To deliver the analytics service and platform access according to your subscription tier.
  • To enforce rate limits and prevent abuse.
  • To send service-related communications (billing confirmations, security alerts, maintenance notices).
  • To deliver market-data or account notifications you configure (including Discord webhooks).
  • To send newsletter content you have explicitly subscribed to (double opt-in, unsubscribe anytime).
  • To respond to your support requests and bug reports.
  • To improve the reliability and performance of our service through aggregated, anonymized usage analysis.

We do not sell your personal data to third parties (including for purposes of the California Consumer Privacy Act, CCPA). We do not use your data for advertising, profiling, or automated decision-making (GDPR Article 22).

6. Data Retention

We retain personal data only for as long as necessary for the purposes set out in this policy (GDPR Article 5(1)(e); storage limitation).

Data TypeRetention Period
Customer data (email, company, API keys)Retained until account deletion. Deleted within 30 days of deletion request via DELETE /v1/customer/me.
API usage logs90 days from the date of the request, then automatically purged.
Billing records7 years from the transaction date, as required by Estonian tax law.
Support correspondence2 years from the date of the last communication, or until account deletion.
Newsletter subscriptionUntil you unsubscribe. Email removed within 30 days of unsubscribe request.
Market context notificationsRetained until deleted by you or until account deletion.
Connected accounts (Discord)Retained until disconnected by you or until account deletion.

7. Your Rights Under GDPR

As a data subject, you have the following rights under the GDPR. Where possible, we provide self-service API endpoints so you can exercise these rights immediately:

  • Right of access (Article 15): You can view all personal data we hold about you via the customer portal at any time. (Article 15)
  • Right to rectification (Article 16): You can update your profile information (email, company name) directly via the customer portal profile settings. (Article 16)
  • Right to erasure (Article 17): You can delete your account and all associated data by calling DELETE /v1/customer/me. This permanently removes your account, API keys, and usage data. Billing records are retained for 7 years as required by Estonian tax law. EU Article 16(m) consent records (per-transaction audit trail for the 14-day withdrawal-right waiver) are retained 7 years under the legitimate-interest legal basis (Article 6(1)(f)) for the same Estonian Accounting Act + EU consumer-protection enforcement window. These records survive Article 17 erasure of the linked customer account: the customer link is set to NULL, the consent record itself remains so that, if a chargeback or consumer-protection claim is filed, the original consent can still be evidenced. (Article 17)
  • Right to data portability (Article 20): You can export all your data in a structured, machine-readable JSON format by calling GET /v1/customer/export. The export includes your profile, subscription details, API key metadata, and usage history. (Article 20)
  • Right to restriction (Article 18): You can request that we restrict processing of your data in certain circumstances. (Article 18)
  • Right to object (Article 21): You can object to processing based on legitimate interest. We will cease processing unless we demonstrate compelling legitimate grounds. (Article 21)

How to exercise your rights: For rights not available via self-service, send a request to [email protected] with the subject line "GDPR Data Request". We will verify your identity and respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority. (GDPR Article 77)

8. Cookies

We split cookies and comparable browser storage into three categories. The consent banner shown on your first visit lets you accept, reject, or customize them. Your choice is stored in the ds_consentcookie (and a localStorage mirror) for one year. You can revisit the banner any time via the Cookie Preferences link in the footer (ePrivacy Directive 2002/58/EC Article 5(3); GDPR Article 7(3)).

CategoryPurposeConsent requiredDuration
NecessaryLogin session, payment security, basic app functionalityNo (strictly necessary)Session or up to 24 hours
Analytics (opt-in)Optional product and public-site analytics, including PostHog plus public-site-only Microsoft Clarity and Google Analytics when configured (see section below)Yes (GDPR Art. 6(1)(a))Up to 90 days
Marketing (opt-in)Reserved for future campaign attribution. Not currently in use.Yes (GDPR Art. 6(1)(a))Up to 1 year when enabled
Consent recordStores your cookie choice so we do not prompt repeatedlyNo (record of consent, Art. 7(1))1 year

No third-party advertising networks or fingerprinting vendors are used. Optional analytics and behavioral analytics only run after consent.

9. Analytics

DepthSignal can run optional consent-gated analytics only when the relevant project identifiers are configured and public optional analytics is deliberately enabled at runtime. Analytics remains off by default until you grant consent through Cookie Preferences. Microsoft Clarity and Google Analytics are limited to public-site surfaces. First-party PostHog analytics may run on public pages and core product pages, while auth, billing, admin, account-settings, signup, and similar sensitive routes remain excluded by default.

Google Analytics and Microsoft Clarity bootstrap tags may appear in the pageheadin consent-denied mode so browser setup checks can recognize the installation. Analytics storage, page measurement, heatmaps, and replay remain denied unless the runtime enablement flag, route policy, vendor configuration, and user consent all allow them together.

  • PostHog: optional first-party product analytics and feature flags, self-hosted by Ravenna OÜ on EU infrastructure when configured and deliberately enabled. It is used for product and public-site measurement after consent, but not on blocked sensitive routes.
  • Microsoft Clarity: optional public-site behavioral analytics, including heatmaps, session replay, clicks, scrolls, page rendering diagnostics, page URLs, browser metadata, and masked page content. We use Clarity to understand how visitors use public pages, improve product presentation, debug page experience, and validate which public content is useful. Microsoft may receive this public-site usage data when you grant analytics consent. Platform, auth, billing, admin, signup, preview, demo, token, embed, and sensitive account routes are excluded by default, and Clarity masking must stay enabled on form-like collection surfaces. Learn more in the Microsoft Privacy Statement.
  • Google Analytics: optional public-site measurement for page views and aggregate acquisition/performance reporting when configured and deliberately enabled. Google may receive information such as the page URL, browser and device metadata, IP-derived coarse location, and analytics cookies or identifiers after consent. The current implementation is not used for platform heatmaps, session replay, Google Ads personalization, or remarketing. Learn how Google uses information from partner sites and apps in Google's partner-site notice.
  • Legal basis: consent (GDPR Article 6(1)(a)). Analytics stays off by default until you opt in and can be revoked through Cookie Preferences.
  • Retention: PostHog raw events are kept for up to 90 days before anonymization or deletion. Microsoft Clarity and Google Analytics retention is governed by their project settings and provider terms.
  • Third-party sharing: Microsoft and Google receive the consent-mode bootstrap requests needed for their configured public-site integrations. Active analytics storage, page measurement, heatmaps, and replay start only when those integrations are configured and you have granted analytics consent.
  • Opt-out controls: you can withdraw site consent from Cookie Preferences. Google also provides a Google Analytics browser add-on for users who want a browser-level Analytics opt-out.

Your rights: under GDPR you can access, rectify, erase, port, or object to this processing at any time. You can also exercise all of these from inside the app:

  • Reject or customize cookies from the banner or Cookie Preferences link in the footer.
  • Toggle analytics at any time from Account Settings → Privacy.
  • Download your data via GET /v1/customer/export (also linked from Privacy settings).
  • Delete your account (right to erasure). Account deletion also removes related first-party product analytics profiles where technically linked to your account.

10. Third-Party Processors

We share personal data with the following third-party processors only, each bound by data processing agreements (GDPR Article 28):

ProcessorPurposeData SharedLocation
Payment provider path inactiveNo current third-party payment processor is published as activeNo provider payment data is shared while the provider path is inactiveNot applicable until a future provider path is reactivated and republished
Hetzner Online GmbHCloud infrastructure hostingAll service data (stored on EU servers)European Union (Germany/Finland)
Resend, Inc.Transactional email deliveryEmail address, email contentUnited States (SCCs)
OpenAI, Inc.AI-assisted interpretation responses that summarize visible platform contextAI conversation messagesUnited States (SCCs)
Linear, Inc.Automatic bug report ticket creationBug report content, browser metadataUnited States (SCCs)
PostHog (self-hosted)Product and public-site analytics (opt-in only)Page views, clicks, session duration, user agent, pseudonymous analytics identifiers, and authenticated user ID where applicableEuropean Union (our own servers)
Microsoft ClarityPublic-site heatmaps and session replay (opt-in only)Page URLs, clicks, scrolls, mouse movement, page rendering data, browser metadata, and masked page contentThird-party provider infrastructure (Microsoft)
Google AnalyticsPublic-site traffic and acquisition measurement (opt-in only)Page views, referrer, browser metadata, device metadata, and aggregate usage eventsThird-party provider infrastructure (Google)
Beehiiv, Inc.Newsletter distribution (confirmed opt-in subscribers only)Subscriber email address

We do not use third-party advertising networks or fingerprinting vendors. PostHog, Microsoft Clarity, and Google Analytics are listed above because analytics can process personal data when configured and when you grant analytics consent. Clarity and Google Analytics are public-site only. PostHog is first-party analytics with sensitive routes excluded by default. We do not share your personal data with any other third parties except where required by law.

11. International Data Transfers

Core DepthSignal infrastructure is hosted in the European Union. Most account and service operations run on EU-hosted systems.

Some processing involves US-based sub-processors for specialized services (for example, email delivery, AI processing, and issue tracking). No current third-party payment processor is published as active; any future payment-provider location, transfer basis, and safeguards must be republished before activation. Where personal data is transferred outside the EEA, we apply GDPR Chapter V safeguards, including Standard Contractual Clauses and additional contractual or technical protections where required.

For UK-restricted transfers, UK transfer addendum mechanisms are applied where legally required. For Switzerland-restricted transfers, Swiss transfer requirements are applied where legally required.

12. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • API keys are protected with one-way cryptographic controls and are not retrievable in plaintext.
  • Data in transit is encrypted using current industry-standard transport security controls.
  • Access to production data is restricted to authorized systems and personnel on a least-privilege basis.
  • Regular automated backups with encryption.
  • Access to production systems is limited to authorized personnel.

13. Children's Privacy

This service is intended for users aged 18 and over. By registering, you confirm you are at least 18 years of age. We do not actively collect date-of-birth information. If we become aware that a user is under 18, we will promptly delete their account and associated data.

14. Data Protection Contact

As a small company, we are not required to appoint a Data Protection Officer (DPO) under GDPR Article 37. However, for any data protection inquiries, you may contact us directly:

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) (GDPR Article 13(1)(a)-(b)):

15. AI Conversations

When you use AI chat features, the following applies to your conversation data:

  • Storage. Your messages and AI responses are stored in our database to provide chat history across sessions.
  • Third-party processing. Conversations are sent to a third-party AI provider for processing. Current provider: OpenAI.
  • No model training. AI providers process conversation data under contractual data processing commitments. Data Processing Agreements (DPAs) are in place with relevant sub-processors, including transfer safeguards where required.
  • Your control. You can delete all conversation history at any time from Settings.
  • Automatic deletion. Conversations are automatically deleted after 30 days (Trader plan), 90 days (Professional and Expert plans), or 1 year (Enterprise plan).

The legal basis for processing AI conversation data is contract performance (Art. 6(1)(b) GDPR): processing is necessary to deliver the AI feature you have requested as part of your subscription.

16. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make material changes, we will notify you via the email address associated with your account at least 14 days before the changes take effect.

The current version of this Privacy Policy is always available at this page. Minor clarifications or formatting changes may be made without notice.

17. Contact

For any privacy-related questions or concerns, contact us at:

18. Authoritative Legal References

The legal references used in this Privacy Policy are listed below with official sources.

  • GDPR (Regulation (EU) 2016/679): Articles 5(1)(e), 6(1)(a), 6(1)(b), 6(1)(c), 6(1)(f), 7(1), 7(3), 13, 15-22, 28, 44-49, 77 - official text.
  • ePrivacy Directive 2002/58/EC: Article 5(3) - official text.
  • UK transfer addendum regime (where UK-restricted transfers apply) - ICO guidance and templates.
  • Swiss FADP transfer regime (where Swiss-restricted transfers apply) - official text.

This policy was last updated July 4, 2026 and may be updated. We recommend consulting with legal counsel for specific compliance questions.

DEPTHSIGNAL | ESTONIA | MARKET CONTEXT PLATFORM | SECURITY | PRIVACY | MARKET DATA ONLY | NOT FINANCIAL ADVICE

Privacy Policy | DepthSignal