Privacy policy
This policy explains what [The operating business. "Pholon Solutions LLC" appears in the site footer — confirm it is the entity that contracts with members] ("we", "us") collects when you visit app.blindspotsandsignals.com or use the Blind Spots & Signals member site, and how we use it.
What we collect
- Account details: your email address, a display name you choose, and your password. The password is stored only as a bcrypt hash — never the password itself, and it is never written to a log or returned by any part of the site. We also record when the account was created and when it last signed in.
- Subscription details: which desks and tiers you hold and when they started. No payment provider is connected to this service yet, so nothing has been charged. We hold no card details and there is no field anywhere in the system that could store a card number, expiry or security code; when a provider is added it will collect those on its own site and tell us only the result. [Name the provider here once one is connected]
- Sign-in and device information: the browser and device you sign in from, the time you last used it, and the IP address. You can see and end each session from your account page.
- Activity on your account: things your account did, such as tickers you looked up, with the IP address they came from. This log is visible to you on your account page, and entries are deleted automatically after 180 days.
- Messages you send us: feedback and bug reports sent from inside the member site, and anything you send through the contact form on our public pages. A contact message stores the name, email address, reason and text you type, together with your IP address and browser, so we can reply and so the form can be protected from abuse.
Cookies
The member site sets one cookie, bman_session, which keeps you signed in. It is necessary for the service to work, it cannot be read by scripts in your browser, and it expires after 14 days. We use no analytics, advertising or tracking cookies of any kind, and no third-party tracking scripts run on any page.
Our public pages load fonts from Google Fonts, which means your browser contacts Google when you visit. That request is not something we control or receive. [Optional: serving the fonts from our own site would remove this]
How we use it
- To run your account, show the desks you subscribe to, and keep your sign-in secure.
- To reply to you when you write to us.
- To fix problems and improve the product.
Who we share it with
We share data only with the services that help us run the site. Today that is hosting alone: the service runs on DigitalOcean. No payment processor and no email provider is connected, so nothing is shared with either. Market data and news come from third-party providers, but we send them nothing about you — we ask about companies, never about members. We may disclose information if the law requires it. [Confirm you do not sell personal information, and say so here]
Security
Connections to the site use HTTPS. Your password is stored only as a bcrypt hash, and the token behind your session is stored only as a SHA-256 hash, so read access to our database would not let someone sign in as you. You can see every device holding a session, end any one of them, or sign out everywhere at once; changing your password also signs out every other device. No system is perfectly secure. [Attorney to review this wording]
How long we keep it
Activity entries are deleted after 180 days. A session expires 14 days after it was last used. Database backups are taken nightly and kept for 14 days, with one backup a week kept for eight weeks, so anything deleted can still be present in a backup for up to that long.
Your account details and subscription history are kept while the account exists. Subscription records are not deleted when you cancel — they are what answers a billing question later. [Decide how long to keep an account and its history after it is closed]
Your choices
You can ask to see, correct or delete your information through our contact form. Your account page already shows you your own activity, your sign-in history and the tickers you have looked up. [Attorney: add state-specific rights, such as California, once you know where members live]
Children
The service is not for anyone under 18. [Confirm the minimum age you want to require]
Changes
If we change this policy, we'll update the date above. [Decide how members are told about a significant change. This service cannot send email today, so a notice inside the member site is the only channel that exists]
Contact
Questions about this policy: use our contact form. [Add a published email address here if you want one] See also our terms.