Privacy Policy
Last updated: March 2026
1. Who We Are
DipBuster ("we", "us", "our") operates the website at dipbuster.com. This privacy policy explains how we collect, use, store, and protect your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data We Collect
Account data: When you register, we collect your name, email address, and an encrypted version of your password. We never store passwords in plain text.
Usage data: We store your watchlist preferences, portfolio holdings, alert settings, and platform interaction history to provide our service.
Technical data: Our server automatically logs IP addresses, browser type, and access times for security and performance monitoring. This data is retained for a maximum of 90 days.
Cookie data: We use a single essential session cookie for authentication. We do not use advertising, tracking, or analytics cookies unless you explicitly opt in via our cookie consent banner.
3. How We Use Your Data
We use your data solely to: provide and improve our platform services; send transactional emails (account confirmation, alerts you have subscribed to); and maintain platform security. We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Data Storage & Security
Your data is stored on servers provided by our hosting provider within the EEA. Passwords are hashed using bcrypt. API communications use HTTPS encryption. We implement access controls and regular security reviews.
5. Third-Party Services
We use the following third-party services to operate our platform: Finnhub, Alpha Vantage, Financial Modeling Prep, and Twelve Data for market data; Resend.com for transactional emails. These providers process data in accordance with their own privacy policies. No personal user data is shared with these market data providers.
6. Your Rights
Under UK GDPR, you have the right to: access your personal data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict processing; data portability; and object to processing. To exercise any of these rights, email [email protected]. We will respond within 30 days.
7. Data Retention
We retain your account data for as long as your account is active. If you delete your account, all personal data is permanently removed within 30 days. Anonymised usage statistics may be retained indefinitely.
8. Children
Our service is not directed at individuals under 18 years of age. We do not knowingly collect data from minors.
9. Changes to This Policy
We may update this policy periodically. Material changes will be communicated via email to registered users. The "last updated" date at the top reflects the most recent revision.
10. Contact
For privacy-related enquiries: [email protected]