Privacy
Privacy Policy
Last updated: 19 September 2026
Courtesy translation of version 2026-09-16.1. The Portuguese (Portugal) text is the only legally binding one and prevails if the two differ. Read the original in Portuguese
This policy explains what personal data we process, for what purpose and what your rights are, in accordance with the General Data Protection Regulation (GDPR).
1. Data controller
The controller of your data is José André Fernandes Dourado, sole trader (empresário em nome individual), NIF 242736440, with tax domicile at Rua Colégio Irmãs Dorotéias, n.º 76, Bloco 1, 4.º Esq., 4490-263 Póvoa de Varzim (Portugal), operating under the VetaFinance brand. Contact: geral@vetadev.pt.
2. What data we process
- Account: email, name and, if you log in with Google, the Google account identifier. Your real name does not appear in the community — it is used for your account and for billing.
- Public identity: the nickname you choose and your avatar. If you choose to upload a photo, it is hosted on our servers (Supabase, in the EU) and is visible to anyone who has the image address — that is how it appears next to what you write. The photo is optional: by default we use a drawn figure, with no data of yours. You can change or remove it at any time in your account, and it is deleted from disk when you delete your account.
- Subscription: subscription status and Stripe identifiers. We also tell Stripe the language you use the platform in, so invoices and receipts reach you in that language. We do not store your card details — Stripe handles them directly.
- Usage: watchlists, alerts, saved valuations and messages you post in the community.
- Technical: data strictly necessary for operation and security — session, error logs and your IP address, used to limit abuse (rate limiting) and as evidence of the circumstances in which you accepted the legal documents.
- Audience measurement: aggregated and without identifying you — which pages are viewed, which site you came from, the country, and the type of device and browser. We also measure the steps of the sign-up form and of logging in (page viewed, started filling in, documents accepted, submitted, which way in — email or Google —, and the category of whatever stopped you getting in), to understand where people drop off, and the prompt to install the platform on your home screen (whether it appeared, whether it was accepted or dismissed, and whether your browser allowed a one-tap install or required the instructions). We also count the conversion steps — account created and confirmed (and which way in), first visit during the trial, payment completed (and whether the plan is monthly or annual) — and language changes (to which language, and where on the page). These counts carry the platform language, never who you are. We do not send your email, your name, or what you type in the fields.
- Page performance: how long each page takes to appear and respond on your device (the so-called Core Web Vitals: LCP, INP, CLS). These are timings, aggregated and without identifying you, and they serve one purpose only — fixing what is slow, especially on mobile, which is where most people using the platform are. We do not see what you do on the page, or what you type.
- Mobile notifications (push): if you turn them on, we store for each device a delivery address generated by your browser and the encryption keys it gives us so the message can be encrypted. That address is issued by your system’s push service — Apple (iPhone/iPad/Safari), Google (Android/Chrome) or Mozilla (Firefox) — and that is where the notification is sent. We do not collect your location or the list of apps on your phone. We also store which types of notification you chose to receive. This is optional and can be turned off at any time in your account, device by device; when you turn it off, that device’s record is deleted.
- Language: the language you chose to see the platform in. When you are logged in it is saved to your account, so it applies on other devices and account emails (confirmation, password recovery) reach you in that language.
- Where you came from — only if you accept: when you arrive through a campaign or from another site, we show a notice asking whether we may save that origin. If you accept, we save the campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content), the domain of the site you came from (never the full address), the page you arrived on and the date. If you create an account, this is linked to your account, so we know which promotion brings people who sign up and subscribe. We never store click identifiers (such as gclid or fbclid). If you decline, we save none of this — only that you declined, so we don’t ask again.
- Consents: which legal documents you accepted, in which version, in which language, when and from which IP. We keep this record because the law requires us to be able to demonstrate it.
3. Purposes and legal basis
- Providing the service and managing your account — performance of the contract.
- Processing payments — performance of the contract.
- Security, abuse prevention and legal compliance — legitimate interest / legal obligation.
- Essential communications (e.g. confirmation, billing) — performance of the contract.
- Understanding whether the site is found, where sign-up and log-in fail, and which pages are slow — in order to improve them. Legitimate interest, with aggregated measurement and no profiling.
- Saving where you came from and linking it to your account, so we know which promotion works — consent, asked for in a notice before anything is saved, which you can decline without losing anything on the platform.
- Sending you the mobile notifications you asked for (replies to what you wrote, and stocks reaching the price you set) — consent, which you can withdraw at any time without losing anything else on the platform.
4. Processors
We use providers that process data on our behalf, with appropriate safeguards:
- Supabase — authentication and database (hosted in the EU).
- Stripe — payments.
- Vercel — application hosting and aggregated audience measurement.
- Upstash — cache and abuse limiting; processes your IP and user identifier.
- Sentry — application error detection; receives technical request data when something fails.
- Cloudflare — anti-bot protection on the sign-up and log-in pages.
- Apple, Google and Mozilla — push notification delivery services, and only if you have turned notifications on. They receive the notification encrypted and your device’s delivery address; the key that decrypts it stays on your device and is not given to them.
- Marketstack and EODHD — quotes and market data. They receive no data of yours, only the symbols looked up.
Some of these providers are based outside the European Economic Area (namely Stripe, Sentry, Upstash, Cloudflare and, if you turn on mobile notifications, Apple, Google and Mozilla). In those cases, transfers rely on the standard contractual clauses approved by the European Commission and/or the EU-US Data Privacy Framework, as applicable to each provider.
5. Retention
We keep your data while your account is active. After the account is closed, the data is deleted or anonymised, unless there is a legal obligation to keep it (e.g. billing).
6. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability of your data, as well as the right to withdraw consent.
Access and portability without waiting for us: in Account → Your data you download, as a JSON file, everything we hold about you. On the same screen you can delete your account. For the other rights, or if you would rather we handle it, contact geral@vetadev.pt — we reply within the legal period of one month.
You can also lodge a complaint with the supervisory authority (in Portugal, the CNPD).
7. Deleting your account
You can request deletion of your account at any time. This cancels the subscription and deletes your personal data, except the minimum required by law.
8. Cookies and similar technologies
We do not use advertising or profiling cookies, and we do not share data with advertising networks. We do not use Google Analytics, we do not build profiles of you, and we do not track you across other sites.
Since 25 August 2026 we use Vercel audience measurement — the same provider that hosts the site. It answers two questions: whether people find the platform, and at which step of sign-up or log-in they give up. The data is aggregated: counts by page, country, device type and visit source. We do not send it your email, your name, or anything you write.
Since 31 August 2026 we also measure, through the same provider, page performance on your device — how long pages take to appear and respond. These are timings, nothing more, and they exist so we can fix what is slow. There is no new recipient here and no data of yours that was not already described above.
Without asking for your consent, we only use what is strictly necessary for operation:
- Authentication session (Supabase) — keeps you logged in. Without it there is no log-in.
- Preferences — the light/dark theme stays in your browser and does not leave your device. The language is also kept in a cookie (NEXT_LOCALE), which is only set when you choose a language and lasts one year, so the app opens in your language next time; when you are logged in, it is also kept in your account — as described in section 2.
- Cloudflare Turnstile — on the sign-up and log-in pages, to tell people from bots.
- Sentry — application error detection, with reduced sampling. We do not use it to track you between sessions, and we do not deliberately collect personally identifiable information in the reports.
- Audience measurement (Vercel) — aggregated counts of page views, of the sign-up and log-in steps, and of the install prompt, as described above.
- Performance measurement (Vercel) — aggregated page load and response times. It does not identify you or record what you do on them.
With your consent, and only if you accept the notice about where your visit came from:
- vf_atribuicao_consentimento — stores your answer to the notice (accepted or declined), so we don’t ask again. It lasts 180 days.
- vf_primeiro_contacto — only exists if you accept: it stores the origin described in section 2 until you create an account. It lasts 180 days, and is deleted once that origin moves to your account.
9. Changes
We may update this policy. Each legal document has a version number: when there is a substantive change, we will ask you to read and confirm it again when you open the app, and we keep that confirmation with the date and version.