Skip to main content

How We Handle Your Data

We know you’re trusting us with important information—including investment data. This page explains how we handle your data in plain language. For complete legal details, see our Privacy Policy.

Our Data Philosophy

  1. Collect only what we need — No data hoarding “just in case”
  2. Protect everything we have — Your security is a priority
  3. Be transparent — You should understand what happens with your information

What Data We Collect

Data You Give Us

Data TypeWhy We Need It
Email addressAccount login, communications
PasswordSecure access (stored encrypted)
Name (optional)Personalization
WatchlistsSave and display your watchlists
Portfolio entriesShow holdings and performance
AI conversationsProvide research assistance
Support messagesHelp you when needed

Data We Collect Automatically

Data TypeWhy We Need It
Device typeOptimize experience
Browser infoEnsure compatibility
IP addressSecurity, fraud prevention
Usage patternsImprove the product
Error logsFix bugs

Data from Connected Services

Brokerage via Plaid: [REVIEW REQUIRED: Confirm Plaid data fields]
  • Holdings/positions — Display portfolio
  • Cost basis — Calculate gains/losses
  • Transaction history — Track performance
Important: We NEVER receive or store your brokerage password.

What We DON’T Collect

  • Social Security numbers
  • Full credit card numbers (Stripe handles payments)
  • Brokerage login credentials
  • Bank account numbers
  • Tax identification numbers
  • Government IDs

How We Protect Your Data

Encryption

  • In Transit: TLS/HTTPS encryption (same as banks)
  • At Rest: AES-256 encryption in databases

Access Controls

  • Only authorized employees access user data
  • Access limited to job necessity
  • All access logged and audited

Infrastructure Security [REVIEW REQUIRED: List certifications]

  • Secure cloud infrastructure
  • Regular security audits
  • Automated threat detection
  • DDoS protection

Password Security

  • Never stored in plain text
  • Hashed using bcrypt
  • Two-factor authentication supported

How We Use Your Data

  • Provide Service: Display portfolios/watchlists, power AI, send alerts, process payments
  • Improve Service: Analyze usage (anonymized), fix bugs, develop features
  • Communicate: Updates, support, marketing (opt-in only), security alerts
We may use anonymized conversation data to improve AI. Before training:
  • PII is removed
  • Data is aggregated
  • Safeguards prevent memorization
Opt out by emailing [email protected].

Who Can Access Your Data

Our Team

  • Customer support (to help you)
  • Engineering (to fix issues)
  • Security (to protect against threats)

Service Providers [REVIEW REQUIRED: List all processors]

PartnerPurposeAccess
StripePaymentsBilling info
PlaidBrokerageAuth tokens only
Cloud hostingInfrastructureEncrypted data
Email serviceNotificationsEmail addresses
All partners contractually required to protect your data.

We Never Sell Your Data

We do not sell, rent, or trade your personal information.

Brokerage Connection Security

How Plaid Works

  1. You enter credentials directly with Plaid (not us)
  2. Plaid verifies identity with your brokerage
  3. Plaid gives us a secure token
  4. We fetch read-only portfolio information
We never see your brokerage password.

What We CAN’T Do

  • Make trades in your account
  • Transfer money
  • Change brokerage settings
  • Access your password

Disconnecting

Disconnect your brokerage anytime in Portfolio settings. [REVIEW REQUIRED: Add link]

Payment Data Security

How Stripe Works

  • Card details go directly to Stripe
  • We only see last 4 digits
  • Stripe is PCI DSS Level 1 certified

What We Store

  • Billing name/address (for invoices)
  • Card type and last 4 digits (for display)
  • Transaction history

What We Don’t Store

  • Full card numbers
  • CVV/security codes
  • Bank account numbers

Your Data Rights


Data Retention [REVIEW REQUIRED: Verify periods]

Data TypeRetention After Deletion
Personal data30 days
Backups90 days
Anonymized usageIndefinite (not linked to you)
Payment recordsAs required by law

International Users

Rallies is US-based. Data from outside the US is transferred to and processed in the US. [REVIEW REQUIRED: Add EU provisions if applicable]

Children’s Privacy

Rallies is for adults only (18+). Contact us if you believe a child created an account.

Questions?

Email: [email protected] Response time: Within 30 days.

Quick Reference

QuestionAnswer
Do you sell my data?No, never
Can you see my brokerage password?No
Is my data encrypted?Yes, in transit and at rest
Can I delete my data?Yes, anytime
Can I download my data?Yes, through settings
Who accesses my data?Only authorized team and necessary providers