1. Introduction
This Privacy Policy explains how InsiderClue (“InsiderClue”, “we”, “us”) collects, uses and protects personal data when you visit or use our website insiderclue.com (the “Website”).
InsiderClue is based in Amsterdam, the Netherlands, and aims to comply with applicable data protection laws, including the EU General Data Protection Regulation (“GDPR”) and relevant national laws in EU Member States.
This Privacy Policy should be read together with our Terms of Use & Disclaimer, which govern your use of the Website.
If you do not agree with this Privacy Policy, you should not use the Website.
2. Who We Are
InsiderClue operates the Website insiderclue.com and presents publicly available financial and market data, including data retrieved via the US Securities and Exchange Commission (SEC) API.
The Website is currently operated on an informal basis and not yet through an incorporated legal entity. Once InsiderClue is incorporated, we may update this Policy to include the legal entity details.
3. What Data We Collect
The Website is free and can be read in full without an account. For visitors who do not create one, we generally collect limited personal data, although visiting a website inherently involves some processing, such as IP addresses. If you do create an account, we additionally process the details you give us for it, as set out in section 3.3.
We may collect the following categories of data:
3.1. Technical and usage data
- IP address and other identifiers assigned to your device;
- browser type and version;
- operating system and device type;
- referral URL and pages visited;
- date and time of access.
Not what you do on a page. Clicks, scrolls and how long you stayed are things a script in your browser has to report, and there is no such script; the server knows only that a page was asked for.
This comes from the web server's own logs. We run no analytics product, on our own servers or anybody else's, and no page on the Website loads a script, a font or an image from a third party. The Website's content security policy allows it to load nothing but its own files, so it could not do so accidentally. If we ever add an analytics tool, this Policy will say which one before it runs.
3.2. Cookies
The Website sets one cookie, insiderclue_member, and it is the session cookie that keeps you
signed in. It is set when you open the sign‑in or registration page and while you are signed in. It
holds a random identifier and nothing about you.
If you never sign in, the Website sets no cookie at all: reading the dashboard, the transactions, a company or these legal pages leaves nothing on your device. There is no analytics cookie, no advertising cookie and no third‑party cookie of any kind, because no third‑party code runs on the Website.
If tracking cookies are ever introduced, we will obtain your prior consent in accordance with applicable laws and update this Policy accordingly.
3.3. Account data (optional)
You can create an account, but you never have to: everything on the Website is readable without one. If you do create one, we process:
- Your name, as you enter it, so that the Website can address you. It is not shown to other users.
- Your email address, to confirm the account, to let you reset a forgotten password, to tell you when the security settings on your account change, and, for the saved views you switch an alert on, to tell you when a filing matches one of them. No marketing, and nothing you did not ask for: an alert exists because you pressed a bell, and the same bell stops it.
- Your country, as chosen from a list.
- Your password, stored only as a one‑way hash. We cannot read it, and a forgotten password is reset rather than recovered.
- Two‑factor authentication details, if you switch it on: a secret shared with your authenticator app, and the recovery codes issued with it, stored hashed.
- Sign‑in records: when you last signed in, how many attempts have failed, and the IP addresses from which sign‑in attempts failed. This last one exists to limit brute‑force attempts and is kept for at most seven days.
Saved views. A saved view is a filter you built on the transactions page, kept under a name you chose: which companies, which window, which minimum. It is a description of what you wanted to look at and not a record of what you looked at. We do not attach a history of your reading to your account. A view is deleted when you delete it, and all of them go when the account does.
A view with its alert switched on keeps two things more: how far through the filings it has already told you, so that the same filing is not sent twice, and when the last message went out. Both are shown to you beside the view on your account page.
Messages we have sent you. One line per email that left: which kind it was — a confirmation, a password reset, an alert — and when. Not the subject, not what was in it, and not the address it went to, which is on your account already. Two reasons, and neither is about you personally: it is what holds an alert to one message a day, and it is how we know how much mail this site sends before there is any question of charging for it. It goes when the account goes.
An account is stored until you close it. Closing it, from the account page, deletes your name, country, email address, password hash, two‑factor secret and recovery codes immediately; we keep no copy to restore from. We do not attach a record of what you read on the Website to your account.
Emails to your address are sent on our behalf by Mailjet (Mailgun Technologies / Sinch), acting as a processor. See section 7 on recipients and transfers.
3.4. Contact data (optional)
At this time we do not provide formal contact forms or newsletters. If you contact us voluntarily (e.g., via email in the future), we will process the data you provide (such as your name, email address and message content) solely to respond to your inquiry.
4. Purposes of Processing
We process personal data for the following purposes:
- Website operation: enabling you to access and use the Website, including displaying content and ensuring technical delivery of web pages.
- Website security: monitoring and protecting the Website against abuse, unauthorised access and other security incidents.
- Keeping it working and making it better: reading the server's own logs to see what is slow, what is broken and what is being asked for, so that stability, performance and usability can be maintained and improved.
- Telling you what you asked to be told: sending the email alerts for the saved views you have switched a bell on for, and the messages an account needs to work at all, such as confirming an address or resetting a password.
- Communication (if applicable in the future): responding to messages or inquiries that you send us.
We do not use personal data to provide personalised investment advice, behavioural advertising or profiling for marketing purposes at this stage.
5. Legal Bases for Processing (GDPR)
Under the GDPR, we must have a legal basis for each processing activity. Depending on the specific context, we rely on:
5.1. Legitimate interests (Article 6(1)(f) GDPR)
For:
- processing technical and usage data necessary to operate, secure and improve the Website;
- keeping an account you asked us to create, and the sign‑in records that stop somebody else guessing their way into it.
We balance our interest in providing a functional, secure and improved Website against your privacy rights. We minimise the data collected and, where possible, use appropriate safeguards (such as IP address truncation, aggregation of statistics, and limited retention).
5.2. Consent (Article 6(1)(a) GDPR)
For the email alerts on a saved view. Nothing is sent until you switch one on, one view at a time, and switching it off is the same button in the same place. No alert is on by default and none can be turned on by us.
If we use non‑essential cookies or similar technologies (such as tracking cookies or marketing analytics) in the future, we will first obtain your explicit consent through a clear choice mechanism (e.g., a cookie banner with opt‑in options), in line with supervisory guidance and case law regarding tracking cookies.
5.3. Legal obligation (Article 6(1)(c) GDPR)
In specific situations, we may process or share data to comply with legal obligations, for example if required by a competent authority or court order.
6. Cookies and Similar Technologies
6.1. The one we set
As set out in section 3.2: a single session cookie, insiderclue_member, which keeps you signed in
and is set only on the pages where you sign in or register and while you are signed in. It is strictly
necessary for that purpose and so does not require consent; we tell you about it anyway. We set no analytical
cookie and no third‑party cookie.
6.2. Future tracking cookies
If we ever introduce third‑party tracking cookies or similar tools that follow users across websites and build detailed profiles for advertising, we will:
- obtain prior consent via a clear opt‑in mechanism;
- provide detailed information about the tools used, their purposes and involved third parties;
- offer options to withdraw consent at any time.
6.3. Managing cookies
You can manage cookie preferences through your browser settings (e.g., blocking or deleting cookies) and, where applicable, through our cookie banner or tools we may implement in the future.
7. Data Sharing and Transfers
7.1. Internal use
We do not sell personal data to third parties. Personal data is used only for the purposes described in this Policy.
7.2. Service providers
We may use third‑party service providers (for example: hosting and email delivery) to operate the Website. These providers may process personal data on our behalf and only in accordance with our instructions. Where required, we enter into data processing agreements that reflect GDPR requirements.
The provider we currently use for personal data is Mailjet (Mailgun Technologies, part of Sinch), which delivers the emails sent to account holders: address confirmations, password resets, notices about changes to an account's security settings, and the alerts somebody has switched on for a saved view. It receives the recipient's email address and name for that purpose. It is used for no other kind of message, and we do not send marketing email.
7.3. Legal requirements
We may disclose personal data if required to do so by law or in response to valid requests by public authorities (e.g., courts, supervisory authorities), to the minimum extent necessary.
7.4. International transfers
If personal data is transferred outside the European Economic Area (EEA), we will ensure that appropriate safeguards are in place, such as:
- adequacy decisions by the European Commission;
- standard contractual clauses approved by the European Commission;
- other appropriate safeguards recognised under the GDPR.
7.5. Access by us
An administrator of the Website can open it signed in as an account, so that a problem somebody reports can be seen the way they see it. Three things are true of that access and are built into the Website rather than promised about it:
- it can only look. It cannot change the password, the email address, the country, the name, the second factor, or close the account. Every one of those is refused while it is in use;
- it cannot read your password. Passwords are stored as a one‑way hash, so there is nothing there to read, and nothing in the Website can set one either;
- it is recorded. Each use is written to the server log with the account it opened and the administrator who opened it.
It does not change when you last signed in, because you did not.
8. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. This generally means:
- Server logs and technical data: kept for a limited period (e.g., a few months) for security, troubleshooting and performance monitoring, unless longer retention is necessary in case of specific incidents.
- Analytics data: none is collected; see section 3.1.
- Saved views: kept until you delete the view, or until the account is closed.
- Account data: kept for as long as the account exists. You can close your account at any time from the account page, which deletes it immediately and without a copy kept for restoration.
- Failed sign‑in records: the IP address and the address that was tried, kept for at most seven days, solely to limit brute‑force attempts.
- Confirmation and password‑reset links: valid for 24 hours and one hour respectively, and recorded as spent once used.
When data is no longer needed, we will anonymise or delete it in a secure way.
9. Data Security
We take reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction. These measures may include:
- secure hosting environment;
- restricted access to logs and analytics;
- encryption or pseudonymisation where appropriate;
- regular monitoring of the Website’s security.
No system can be guaranteed as completely secure, but we continually strive to maintain an appropriate level of security.
10. Your Rights
Under the GDPR and applicable national laws, you may have the following rights with respect to your personal data:
- Right of access: to request confirmation whether we process your personal data and to receive a copy of such data.
- Right to rectification: to request correction of inaccurate or incomplete personal data.
- Right to erasure (“right to be forgotten”): to request deletion of your personal data where legal conditions are met.
- Right to restriction of processing: to request that we restrict processing in certain circumstances.
- Right to data portability: to receive your personal data in a structured, commonly used and machine‑readable format, where legally applicable.
- Right to object: to object to processing based on legitimate interests, including basic analytics, on grounds relating to your particular situation.
- Right to withdraw consent: where processing is based on your consent (e.g., future tracking cookies), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
To exercise these rights, you can contact us as described below. We may need to verify your identity before responding to your request.
You also have the right to lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.
11. Contact
At this stage, InsiderClue does not publish formal contact details on the Website. If and when a dedicated contact email or form is introduced, this section will be updated to reflect how you can reach us for privacy‑related inquiries or to exercise your rights.
In the meantime, you may contact us through any official contact channel that becomes available on the Website.
12. Changes to This Privacy Policy
We may update or modify this Privacy Policy from time to time, with or without prior notice, for example to reflect changes in the Website, legal requirements or guidance from data protection authorities.
The most current version of this Privacy Policy will always be available on the Website. Your continued use of the Website after any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the updated Policy, you must stop using the Website.