Privacy Policy — Visual Sectors
This policy covers the Visual Sectors platform at visualsectors.com — the site, your account, and the product features on it: Workflows, the Screener, and the single-stock page. It also covers our campaign pages at lp.visualsectors.com.
It does not cover the Visual Sectors Data API and MCP server at api.visualsectors.com, which are a separate product with their own privacy policy, their own account and their own acceptance record. Some pages still served from our older platform carry their own arrangements too; as those are replaced they come under this policy.
1. Who is responsible for your data
Visual Sectors, Inc., Suite 305, 131 Continental Drive, Newark, Delaware 19713, United States, is the controller of the personal data described here.
Our representative in the United Kingdom and the European Union — because we are established in the United States but offer this Service to people in the UK and the EU — is Visual Sectors, Ltd., 20-22 Wenlock Road, London, N1 7GU, United Kingdom. You can contact the representative about anything in this policy, and you may prefer to, since it is closer to you.
Privacy contact: privacy@visualsectors.com.
We have not appointed a Data Protection Officer and, on the current scale and nature of processing, are not required to.
2. The short version
- We collect what an account needs to exist: your email, name, password (hashed), or your Google account identifier if you sign in with Google.
- We record how you found us (campaign tags on the link you arrived through) and what your account spends runs on, so we can count your allowance honestly and run the service.
- Nothing that measures or tracks you runs unless you accept it. If you decline, or never answer the banner, no measurement script loads at all.
- Visitor identification (RB2B) is off unless you tick it. If you are in the United States and tick it, RB2B tells us who you are so we can get in touch (§3.7a). Some US state laws count that as a sale. Apart from it, we do not sell your data or share it for anyone else's marketing.
- You can get a copy of your data, correct it, or have your account deleted.
3. What we collect
Everything below is a field that exists in our database. Nothing is collected that is not listed.
3.1 Your account
| Data | Where it comes from | Notes |
|---|---|---|
| Email address | You, at signup | The account identifier. Case-insensitively unique |
| Name | You, at signup | |
| Password | You, at signup | Stored only as a one-way hash. We never see or store the password itself |
| Google account identifier | Google, if you sign in with Google | An opaque subject id and the email address on it |
| Email domain | Derived from your email address | Used to recognise which organisations are evaluating the Service |
| Company | Derived from your email domain; you can edit it | |
| Country | Cloudflare's country header on your signup request | Country only. We do not store your IP address |
| Email verification timestamp | Our system | |
| Plan and status | Our system |
3.2 Sessions and sign-in
| Data | Notes |
|---|---|
| Session token | Stored as a hash, never in the clear. A stolen database backup does not hand over live sessions |
| Expiry and creation time | Sessions last 30 days |
| Browser user-agent string | To help you recognise your own sessions and to spot suspicious ones |
| Country of the session | Country only, again — no IP address |
| Email-verification and password-reset tokens | Hashed, single-use, and short-lived |
3.3 How you found us
Written once, when your account is created, from whatever the link you arrived through carried. It is never updated afterwards, so a later visit cannot rewrite how you were originally acquired. If you have accepted measurement, the tags are kept in your browser's session storage until you sign up or close the tab, so a sign-up later in the same visit is still credited; if you have not, nothing is kept (Cookie Policy).
| Data | Notes |
|---|---|
utm_source, utm_medium, utm_campaign, utm_content, utm_term | Campaign tags in the URL you arrived on |
| Google, Facebook and Yandex click identifiers | Ad-platform click ids, if present in the URL. These are what let a signup be matched back to advertising spend |
Meta pixel browser id (_fbp) | Only if you accepted measurement and the Meta pixel has set one. It lets Meta match the sign-up to its ads |
| Landing page and referring URL | |
| Country |
3.4 What your account spends runs on
A run is the unit of paid work (see Terms of Sale §2). To count your allowance honestly and to answer you when you ask why a run was spent, we record:
| Data | Notes |
|---|---|
| The kind of work and what it was about — a ticker, and the day | One row per piece of work produced. This is what makes "one run per ticker per day" true rather than a promise |
| Your allowance used this month, per kind of work | So the counter you see is the counter we bill against |
| A record of each paid action and whether it completed | So a failure is not charged twice, and so a dispute about a run has an answer |
| Your run balances, what you bought and what was spent | Bought runs never expire, so this record outlives any one month |
We do not keep a copy of what a reading said. We record that a reading was produced for a ticker on a day, not the output you read.
3.5 Administrative actions
Every administrative action that changes what someone may access — granting an entitlement, changing a limit, closing an account — is recorded, with who did it, when, and what changed. Your email address is stored on that record alongside your account id. Section 8 explains why that record outlives your account.
3.6 Payments, if you buy something
Your card never reaches us. Payment is taken by Stripe, on Stripe's own pages and with Stripe's own forms. We never see, hold or store a card number, an expiry date or a security code, and we could not produce one if you asked us to.
What we do store, against your account, is what we need to know what you bought and what you are owed:
| What | Why we hold it |
|---|---|
| Your Stripe customer identifier | To connect a payment Stripe tells us about to your account |
| Your subscription's state and dates — trialing, active, past due, cancelled; renewal and trial-end dates | To know what your account may do, and when to charge or stop |
| A history of changes to that state | So that a dispute about what your account could do on a given day has an answer |
| Your run balances, and what they were spent on | To count your allowance honestly and to answer you when you ask why a run was spent |
| The last four digits and the brand of the card, as Stripe reports them | So your account page can say which card is about to be charged |
| Your billing country, and a VAT number if you give us one | To charge the right tax |
| The consent you gave at checkout — that you asked us to begin supply immediately and accepted the consequence, with the version of the policies you were shown | Because Terms of Sale §6 turns on it. A record of consent that cannot say which text you were shown is not a record |
Stripe processes your payment as a controller in its own right for fraud prevention and its own legal obligations, as well as a processor on our instructions for taking the payment. Its own privacy notice covers that part, and it is linked from Sub-processors.
3.7 Measurement and advertising, only if you accept it
If you accept measurement in the cookie banner, Google Tag Manager loads and its tags run in your browser: analytics (how the site is used: pages viewed, clicks, scroll depth, which parts of a page were on screen and for how long, time on the page, and key actions such as sign-up and purchase — never your name, e-mail address, account id or anything you type), advertising tags from Google, Meta, TikTok, LinkedIn, X and Yandex (which ads bring visitors, and showing our ads to people who have visited), session recording and heatmaps (Hotjar), and social and referral measurement (Metricool, LinkMink). Those providers receive what their tags collect in your browser, and the advertising platforms can recognise you on other websites that use them. If you decline, or never answer, nothing loads and they receive nothing. The Cookie Policy lists each tag and what it is for.
Your answer itself is stored in your browser, not on our servers.
3.7a Visitor identification (RB2B), only if you tick it
The cookie banner and the cookie settings offer a separate choice, visitor identification: a tick box of its own, naming RB2B. It is off unless you tick it. Accepting measurement does not turn it on, and it counts only together with measurement, because RB2B loads through the same Tag Manager.
If you tick it and you are in the United States, a script from RB2B (GetEmails, LLC, Austin, Texas) runs in your browser. RB2B matches your visit against its own database of people in US business and tells us who you probably are: your name, job title, company and LinkedIn profile and, where RB2B has one, an e-mail address, with the pages you viewed here. We use it to get in touch about Visual Sectors for your work. Those details come from RB2B's database, not from you.
RB2B says it identifies people only in the United States and that its database excludes UK and EU residents. RB2B's terms make it an independent controller of what its script collects: it uses that under its own privacy policy, not only on our instructions.
Untick it in the cookie settings and it stops from then on. The "Do not sell or share my personal information" link in the footer stops it too, together with measurement and ads. To have us delete what RB2B sent us about you, write to privacy@visualsectors.com.
3.8 What we do not collect
- No IP addresses in our database. Country only.
- No behavioural tracking without consent. Nothing measures you, records your session or tracks you for advertising until you say yes (§3.7).
- No email open or click tracking. It is switched off explicitly on our sending domain: a password-reset link rewritten through a third-party tracking domain reads as phishing to filters and to people, and an invisible pixel is behavioural tracking without consent.
- No special-category data. Do not send us any.
- No copy of the readings you look at beyond what §3.4 lists.
4. Why we process it, and on what basis
| What | Why | Lawful basis (UK/EU GDPR Art. 6) |
|---|---|---|
| Account, password, email verification | To give you an account and let you sign in | Contract — Art. 6(1)(b) |
| Sessions | To keep you signed in | Contract |
| Bot check on forms that send mail (Turnstile) | Without it, a script could send mail through us at will | Legitimate interests — Art. 6(1)(f): protecting the Service from abuse |
| Run records and allowance counters | To give you what you paid for, to count it honestly, and to answer a dispute about it | Contract |
| Campaign attribution | To understand which channels bring people who find the Service useful | Legitimate interests — Art. 6(1)(f): measuring our own marketing |
| Administrative audit trail | So that a decision granting differential access is defensible later | Legitimate interests, and legal obligation where it applies |
| Service emails — verification, password reset, changes to the Service | To operate the account | Contract |
| Marketing emails, if any | Consent — asked for separately, never bundled with signup, withdrawable at any time | |
| Measurement | Consent — off until you accept, withdrawable at any time | |
| Visitor identification (RB2B), if you tick it | To learn which people in US business visited, and get in touch about Visual Sectors for their work | Consent — Art. 6(1)(a) where the GDPR applies; off until you tick it, withdrawable at any time |
| Office-hours bookings, if you make one | To hold the session you booked and send you its details | Contract — Art. 6(1)(b) |
| Office-hours recordings, if a session you join is recorded | So people who could not attend can watch it later, on our site and on YouTube. You appear in it only if you speak or turn your camera on | Legitimate interests — Art. 6(1)(f): open education about the product. You can object — write to privacy@visualsectors.com and we cut your part or take the recording down |
| Payments, subscription state and balances | To sell you a plan, take the payment, and give you what you paid for | Contract — Art. 6(1)(b) |
| The checkout consent record | To show what you agreed to and when | Legal obligation — Art. 6(1)(c), and legitimate interests |
| Records of payments, refunds and disputes | Tax and accounting records we are required to keep, and defending a chargeback | Legal obligation — Art. 6(1)(c), and legitimate interests — Art. 6(1)(f) |
| Fraud checks on a payment | Stopping stolen cards being used on the Service | Legitimate interests — Art. 6(1)(f), and Stripe's own legal obligations |
Where we rely on legitimate interests, we have considered your interests and rights against ours. You can object — see §9.
Company-level lead qualification. Deriving your company from your email domain, and looking at which organisations are evaluating the Service, is commercial research on our own users. We consider it a legitimate interest, and it is one you can object to.
5. Who we share it with
We do not sell personal data or share it for third-party marketing, with one exception you control: visitor identification (§3.7a), which is off unless you tick it.
We use a small number of service providers who process data on our instructions. They are listed in full, with what each one receives, in Sub-processors. If you buy a plan, Stripe is one of them, and it is the only one that touches a payment. If you book an office-hours session, Calendly receives what you type into its booking form. We send it nothing about you. If a session you join is recorded, the recording is published on our site and on YouTube (§4).
We may also disclose data where we are legally required to, or to establish, exercise or defend legal claims.
6. Where your data is held
Your account data is stored in the United Kingdom. It sits in a PostgreSQL database that is not reachable from the internet — it listens only on its own loopback interface and is reached through a private tunnel.
The Service itself runs on Cloudflare's global edge network, which means a request you make is handled at whichever Cloudflare location is nearest to you.
Transfers to the United States. We are a US company, so our staff access UK-held data from the United States. For that transfer we rely on the UK International Data Transfer Agreement and the EU Standard Contractual Clauses, entered into between our UK entity and our US entity, together with the additional measures described in §10. You can ask us for a copy of the relevant clauses at privacy@visualsectors.com.
Our providers may also process data outside the UK and EEA under their own equivalent safeguards; each is named in Sub-processors.
7. How long we keep it
| Data | Retention |
|---|---|
| Account record | While your account exists |
| Sessions | 30 days, then expired and removed |
| Verification and reset tokens | Hours, and single-use |
| Run records and monthly counters | While your account exists |
| Campaign attribution | While your account exists |
| Administrative audit trail | Retained after account deletion — see §8 |
| Payment and subscription records | Kept after your account is deleted — see §8. Held for the period our tax and accounting obligations require |
| The checkout consent record | Kept with the payment record it belongs to |
| Office-hours recordings | While published. If you object, we cut your part or take the recording down |
| What RB2B tells us about a visitor | 12 months from the visit if we have not been in touch; deleted sooner if you ask |
| Card brand and last four digits | While the card is on file; removed when you remove the card or close the account |
8. Deleting your account, and what survives it
Ask us to delete your account and we delete it. Your sessions, tokens and attribution record are removed with it automatically — the database is built so that deletion cascades rather than leaving working credentials behind.
Five records are deliberately kept, and here is each one with its reason.
| What is kept | Why |
|---|---|
| The administrative audit trail — who granted or revoked what, when, and the account and email it concerned | An audit log that disappears along with the thing it audits is not an audit log. Kept under Article 17(3)(e), establishing and defending legal claims |
| The unsubscribe list — your email address, marked as not to be emailed | So that an unsubscribe is honoured. If we deleted this, the next time your address entered our system you would start receiving email again, which is the opposite of what you asked for. Article 17(3)(b) |
| Your subscription records — what you bought, when, and for how much | Payment, tax and accounting records we are required to keep. Article 17(3)(b) |
| The history of changes to your subscription's state | So that a later question about what you were entitled to on a given day — including a chargeback — has an answer. Article 17(3)(e) |
| Any paid entitlement carried over from our earlier platform | So that a right you paid for can still be honoured if you come back. Article 17(3)(e) |
We keep only what each record needs, and nothing in these five is used for marketing or analysis.
If you object to any of these being kept in your particular circumstances, tell us at privacy@visualsectors.com and we will consider it on its facts.
9. Your rights
Under the UK GDPR and the EU GDPR you can ask us to:
- give you a copy of your personal data, in a portable form;
- correct anything inaccurate;
- delete your account and data (§8);
- restrict or object to processing we base on legitimate interests — including campaign attribution and company-level lead research;
- withdraw consent for marketing or for measurement, at any time, without affecting anything done before;
- not be subject to a solely automated decision with legal or similarly significant effect. We do not make any.
Write to privacy@visualsectors.com, or to our UK/EU representative (§1). We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
These requests are currently handled by a person, not by a button. There is no self-service export or delete in your account yet. That does not change the deadline: ask, and it gets done within the month.
If you are unhappy with how we handle your data, please tell us first. You also have the right to complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113), or to the supervisory authority in your EU member state.
9a. If you live in the United States
We are a Delaware company, so this is worth stating plainly:
- Visitor identification is the one thing that may count as a sale. If you tick it (§3.7a), RB2B receives what its script collects in your browser and uses it under its own terms, so California and some other states may treat it as a sale or sharing. It is off unless you tick it. To opt out, use the "Do not sell or share my personal information" link in the footer: it turns off visitor identification and measurement and ads together. Leaving the box unticked does the same for RB2B alone. If your browser sends a Global Privacy Control signal, we treat it as that opt-out and RB2B does not load.
- Apart from that, we do not sell your personal information. If you accept measurement, the advertising tags in §3.7 run in your browser, and some state laws treat that as "sharing" for cross-context behavioural advertising. It happens only after you accept: declining, or never answering the banner, prevents it, and you can withdraw at any time from the cookie settings link in the footer or the "Do not sell or share my personal information" link beside it.
- Apart from visitor identification (§3.7a), we do not use your data for profiling, and we make no automated decisions about you. Advertising is shown to you only through those tags, and only if you have accepted them.
- California's CCPA/CPRA, and comparable laws in other states, apply to businesses above revenue and volume thresholds we do not currently meet. We follow the substance of them anyway — the rights in §9 are available to you on the same terms, whichever state you live in.
- California residents may also designate an authorised agent to make a request for them.
If a state law starts to apply to us as we grow, we will say so here before it does.
10. Security
- Passwords are stored only as one-way hashes.
- Session and reset tokens are stored as hashes, never in the clear, and the session cookie is signed against a secret only our Worker holds.
- The account database is not exposed to the internet.
- The application's database role holds no schema-modification rights, so a bug in the product cannot alter the database structure.
- Every administrative action that changes access is logged.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the ICO within 72 hours and, where the risk is high, tell you directly.
11. Children
The Service is not for under-18s and we do not knowingly collect their data. If you believe a child has given us data, write to privacy@visualsectors.com and we will delete it.
12. Cookies
One cookie keeps you signed in; our security provider sets two more; the office-hours booking calendar sets Calendly's own, only if you open it; nothing that measures you runs unless you accept it. It is all in the Cookie Policy.
13. Changes to this policy
The current version is always at this address with the version it carries and the date it was last updated. If we change it materially — a new purpose, a new recipient, a new kind of data — we will email the address on your account before the change takes effect.
This policy and the Data API's carry separate version numbers. A change here never re-prompts a Data API client, and a change there never re-prompts you.
14. Contact
Privacy: privacy@visualsectors.com Everything else: support@visualsectors.com
Controller — by post: Visual Sectors, Inc., Suite 305, 131 Continental Drive, Newark, Delaware 19713, United States
UK and EU representative — by post: Visual Sectors, Ltd., 20-22 Wenlock Road, London, N1 7GU, United Kingdom