Privacy Policy
1. Data controller
The data controller is the operator of the "Pullback Radar" platform (referred to as the "Service"). For any request regarding your data, you can write to the email address indicated in official communications.
2. Data collected and purposes
We collect exclusively the data provided via Google authentication:
- Email address โ unique account identifier
- Display name โ shown in the interface
- Avatar URL (Google profile picture) โ shown in the header
- Google provider ID โ to link future sessions to the same account
We use this data to:
- Authenticate the user and keep the session active
- Send email notifications about detected investment opportunities (only if the user has added instruments)
- Assign the administrator role (only to the email configured by the operator)
3. Cookies used
The Service uses a single technical cookie, strictly necessary for it to function:
- pullbackradar_session โ cryptographically signed session cookie (HttpOnly, SameSite=Lax). It contains only the session identifier; it expires 30 days after the last access. It does not contain personal data in clear text.
We do not use profiling cookies, third-party cookies, Google Analytics, or other tracking systems. Typefaces (Google Fonts) and JavaScript libraries (jsDelivr/cdnjs) are loaded from third-party CDNs: their use is subject to their respective privacy policies.
4. Legal basis for processing
- Performance of a contract (Art. 6(1)(b) GDPR) โ authentication and operation of the Service
- Legitimate interest (Art. 6(1)(f) GDPR) โ sending notifications about monitored instruments, system security
5. Data retention
- Account data is retained until explicit deletion by the user
- Recorded investment opportunities are automatically deleted after 365 days
- Per-user notification logs are not automatically deleted (used for anti-spam purposes)
6. Sharing with third parties
Your data is never sold, transferred, or disclosed to third parties. The only exception is Google LLC as the OAuth 2.0 authentication provider, whose operations are governed by the Google Privacy Policy.
7. Your rights (GDPR Art. 12โ22)
As a data subject you have the right to:
- Access โ receive a copy of the data we process about you
- Rectification โ correct inaccurate data
- Erasure ("right to be forgotten") โ request deletion of your account and all associated data
- Portability โ receive your data in a structured format
- Objection โ object to processing based on legitimate interest
- Restriction โ request the restriction of processing under certain circumstances
To exercise these rights, log out and remove your data directly from the interface, or contact the data controller by email. You also have the right to lodge a complaint with the Data Protection Authority (www.garanteprivacy.it).
8. Security
Data is protected by: session encryption (HMAC), HTTPS in production, HTTP security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy), and parameterized queries to prevent SQL injection. Passwords are never collected โ authentication happens exclusively through Google OAuth.
9. Changes to this policy
Any changes will be published on this page with the date at the top updated. Continued use of the Service after changes are published constitutes acceptance of them.