Privacy Policy
How Assets Bulletin collects, uses, shares, and protects personal data — including your rights under the California Consumer Privacy Act (CCPA/CPRA) and other applicable U.S. privacy laws.
Last updated: July 2026
1. Who we are
Assets Bulletin LLC is the data controller for personal data processed through this website, its dashboards, newsletters, and e-mails (together, the "Service"). Contact us through your account or the support address published on the Service.
2. Data we collect
- Account data — name, e-mail address, hashed password, subscription tier, and preferences you set.
- Billing data — subscription and transaction records. Card details are processed by our payment processor (Stripe); we never store full card numbers.
- Usage data — pages and dashboard modules viewed, feature interactions, log data (IP address, browser type, device identifiers, timestamps), and error diagnostics.
- Communications — e-mails you send us, newsletter delivery and open/click events (via our e-mail provider), and support requests.
- Cookies and similar technologies — see our Cookie Policy. Non-essential cookies are only set with your consent where required.
3. Purposes and legal bases
- Providing the Service (account, dashboards, newsletters, billing) — performance of a contract.
- Service e-mails (bulletins you subscribed to, receipts, security notices) — performance of a contract / legitimate interests.
- Improving and securing the Service (diagnostics, abuse prevention, aggregated analytics) — legitimate interests.
- Marketing communications — consent, withdrawable at any time via the unsubscribe link.
- Legal compliance (tax, accounting, lawful requests) — legal obligation.
4. Sharing and processors
We do not sell personal data and do not share it for cross-context behavioural advertising. We share data only with service providers acting on our instructions — payment processing (Stripe), e-mail delivery (e.g., Resend), cloud hosting and databases, and error monitoring — and where required by law, or in connection with a corporate transaction subject to equivalent protections. We also use Google Ads conversion measurement (the Google tag) to understand whether our own advertising leads to visits and signups; this is limited to measuring campaign performance and is not used for remarketing or to build cross-site behavioural profiles.
5. International transfers
Our service providers may process data in the United States and other countries. Where personal data is transferred internationally, we require our processors to protect it under contractual safeguards consistent with this Policy.
6. Retention
Account data is kept while your account is active and for a reasonable period thereafter to support reactivation and defend legal claims. Billing records are retained as required by tax and accounting law. Log and diagnostic data is kept for shorter operational windows. We delete or anonymise data when it is no longer needed.
7. Your rights
Depending on where you live, you may request access, correction, deletion, restriction, or portability of your personal data, object to processing based on legitimate interests, and withdraw consent at any time (without affecting prior processing). To exercise rights, contact us via the Service; we will respond within a reasonable period and any window required by applicable law.
8. Your rights (California — CCPA/CPRA)
California residents have the right to know, correct, and delete the personal information we hold, to opt out of "sale" or "sharing" (we do neither), to limit use of sensitive personal information (we do not use it for inference), and to non-discrimination for exercising these rights. Submit requests via the Service; we will verify your identity before responding within the statutory window.
9. Security
We use industry-standard safeguards: encrypted transport (TLS), hashed passwords, scoped access controls, and segregated production credentials. No system is perfectly secure; notify us immediately of any suspected account compromise.
10. Children
The Service is not directed at children under 18, and we do not knowingly collect their data. If you believe a child provided data, contact us and we will delete it.
11. Changes
We may update this Policy; material changes will be announced on the Service or by e-mail with the new effective date. The latest version always lives at this page.