Privacy Policy
Effective date: June 13, 2026 · Last updated: June 13, 2026
This Privacy Policy explains what data SoloTerminal (“SoloTerminal,” “we,” “us”), operated by Howard Cheng Huang as an individual, collects when you use soloterminal.com, why, who we share it with, and the rights you have. We collect the minimum needed to run the Service.
1. Data we collect
- Account data: your email address and a one-way hashed (bcrypt) version of your password. We never store your password in plain text.
- Portfolio data you enter: the tickers, share counts, prices, accounts, notes, and theses you choose to add. You enter this manually — we do not connect to your brokerage and do not collect your brokerage or banking login credentials.
- Billing data: if you subscribe to Pro, payment is processed by Stripe. We receive subscription status and identifiers from Stripe; we do not store your full card number.
- Technical & usage data: IP address, request logs, and basic usage events, used for security, rate limiting, and debugging.
2. How we use data
- to provide the Service and compute your analytics, signals, and reports;
- to authenticate you and keep your account secure;
- to send transactional email (email verification, password resets, billing notices);
- to process subscriptions and prevent abuse;
- to comply with legal obligations.
We do not sell your personal data, and we do not use it for third-party advertising.
3. Who we share data with
We share data only with service providers that help us operate, under contract:
- Stripe — payment processing and subscription management.
- Email delivery providers — to send transactional emails.
- Hosting / infrastructure — to run the Service.
- Market-data providers — when computing analytics we send only the ticker symbols involved, not your identity or holdings quantities.
We may also disclose data if required by law or to protect rights and safety.
4. Cookies
We use a single essential, HTTP-only session cookie to keep you signed in. We do not use third-party advertising or cross-site tracking cookies.
5. Data retention & deletion
We keep your data while your account is active. You can request deletion of your account and associated data at any time by emailing us; we will delete it within a reasonable period, except where retention is required by law (e.g., billing records).
6. Your rights
Depending on where you live, you have some or all of the following rights. To exercise them, email [email protected]; we will verify your identity before acting.
EEA / UK (GDPR)
Access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent and to lodge a complaint with your supervisory authority. Our legal bases are contract performance, legitimate interests (security, service improvement), consent (where applicable), and legal obligation.
California (CCPA/CPRA)
The right to know, access, correct, and delete your personal information, and to opt out of its “sale” or “sharing” — we do not sell or share personal information as defined by the CPRA — without discrimination for exercising these rights.
Canada (PIPEDA)
The right to access your personal information and request corrections, and to withdraw consent subject to legal or contractual limits.
7. Security
We protect data with bcrypt password hashing, HTTPS in transit, HTTP-only session cookies, and rate limiting. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. International transfers
We and our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.
9. Children
The Service is not directed to anyone under 18, and we do not knowingly collect data from children.
10. Changes
We may update this Policy; material changes will be posted here with a new effective date and, where appropriate, notified by email.
11. Contact
Privacy questions or requests: [email protected].