Skip to the document
Visual Sectors

Privacy Policy — Visual Sectors

This policy covers the Visual Sectors platform at visualsectors.com — the site, your account, and the product features on it: Workflows, the Screener, and the single-stock page. It also covers our campaign pages at lp.visualsectors.com.

It does not cover the Visual Sectors Data API and MCP server at api.visualsectors.com, which are a separate product with their own privacy policy, their own account and their own acceptance record. Some pages still served from our older platform carry their own arrangements too; as those are replaced they come under this policy.


1. Who is responsible for your data

Visual Sectors, Inc., Suite 305, 131 Continental Drive, Newark, Delaware 19713, United States, is the controller of the personal data described here.

Our representative in the United Kingdom and the European Union — because we are established in the United States but offer this Service to people in the UK and the EU — is Visual Sectors, Ltd., 20-22 Wenlock Road, London, N1 7GU, United Kingdom. You can contact the representative about anything in this policy, and you may prefer to, since it is closer to you.

Privacy contact: privacy@visualsectors.com.

We have not appointed a Data Protection Officer and, on the current scale and nature of processing, are not required to.


2. The short version


3. What we collect

Everything below is a field that exists in our database. Nothing is collected that is not listed.

3.1 Your account

DataWhere it comes fromNotes
Email addressYou, at signupThe account identifier. Case-insensitively unique
NameYou, at signup
PasswordYou, at signupStored only as a one-way hash. We never see or store the password itself
Google account identifierGoogle, if you sign in with GoogleAn opaque subject id and the email address on it
Email domainDerived from your email addressUsed to recognise which organisations are evaluating the Service
CompanyDerived from your email domain; you can edit it
CountryCloudflare's country header on your signup requestCountry only. We do not store your IP address
Email verification timestampOur system
Plan and statusOur system

3.2 Sessions and sign-in

DataNotes
Session tokenStored as a hash, never in the clear. A stolen database backup does not hand over live sessions
Expiry and creation timeSessions last 30 days
Browser user-agent stringTo help you recognise your own sessions and to spot suspicious ones
Country of the sessionCountry only, again — no IP address
Email-verification and password-reset tokensHashed, single-use, and short-lived

3.3 How you found us

Written once, when your account is created, from whatever the link you arrived through carried. It is never updated afterwards, so a later visit cannot rewrite how you were originally acquired. If you have accepted measurement, the tags are kept in your browser's session storage until you sign up or close the tab, so a sign-up later in the same visit is still credited; if you have not, nothing is kept (Cookie Policy).

DataNotes
utm_source, utm_medium, utm_campaign, utm_content, utm_termCampaign tags in the URL you arrived on
Google, Facebook and Yandex click identifiersAd-platform click ids, if present in the URL. These are what let a signup be matched back to advertising spend
Meta pixel browser id (_fbp)Only if you accepted measurement and the Meta pixel has set one. It lets Meta match the sign-up to its ads
Landing page and referring URL
Country

3.4 What your account spends runs on

A run is the unit of paid work (see Terms of Sale §2). To count your allowance honestly and to answer you when you ask why a run was spent, we record:

DataNotes
The kind of work and what it was about — a ticker, and the dayOne row per piece of work produced. This is what makes "one run per ticker per day" true rather than a promise
Your allowance used this month, per kind of workSo the counter you see is the counter we bill against
A record of each paid action and whether it completedSo a failure is not charged twice, and so a dispute about a run has an answer
Your run balances, what you bought and what was spentBought runs never expire, so this record outlives any one month

We do not keep a copy of what a reading said. We record that a reading was produced for a ticker on a day, not the output you read.

3.5 Administrative actions

Every administrative action that changes what someone may access — granting an entitlement, changing a limit, closing an account — is recorded, with who did it, when, and what changed. Your email address is stored on that record alongside your account id. Section 8 explains why that record outlives your account.

3.6 Payments, if you buy something

Your card never reaches us. Payment is taken by Stripe, on Stripe's own pages and with Stripe's own forms. We never see, hold or store a card number, an expiry date or a security code, and we could not produce one if you asked us to.

What we do store, against your account, is what we need to know what you bought and what you are owed:

WhatWhy we hold it
Your Stripe customer identifierTo connect a payment Stripe tells us about to your account
Your subscription's state and dates — trialing, active, past due, cancelled; renewal and trial-end datesTo know what your account may do, and when to charge or stop
A history of changes to that stateSo that a dispute about what your account could do on a given day has an answer
Your run balances, and what they were spent onTo count your allowance honestly and to answer you when you ask why a run was spent
The last four digits and the brand of the card, as Stripe reports themSo your account page can say which card is about to be charged
Your billing country, and a VAT number if you give us oneTo charge the right tax
The consent you gave at checkout — that you asked us to begin supply immediately and accepted the consequence, with the version of the policies you were shownBecause Terms of Sale §6 turns on it. A record of consent that cannot say which text you were shown is not a record

Stripe processes your payment as a controller in its own right for fraud prevention and its own legal obligations, as well as a processor on our instructions for taking the payment. Its own privacy notice covers that part, and it is linked from Sub-processors.

3.7 Measurement and advertising, only if you accept it

If you accept measurement in the cookie banner, Google Tag Manager loads and its tags run in your browser: analytics (how the site is used: pages viewed, clicks, scroll depth, which parts of a page were on screen and for how long, time on the page, and key actions such as sign-up and purchase — never your name, e-mail address, account id or anything you type), advertising tags from Google, Meta, TikTok, LinkedIn, X and Yandex (which ads bring visitors, and showing our ads to people who have visited), session recording and heatmaps (Hotjar), and social and referral measurement (Metricool, LinkMink). Those providers receive what their tags collect in your browser, and the advertising platforms can recognise you on other websites that use them. If you decline, or never answer, nothing loads and they receive nothing. The Cookie Policy lists each tag and what it is for.

Your answer itself is stored in your browser, not on our servers.

3.7a Visitor identification (RB2B), only if you tick it

The cookie banner and the cookie settings offer a separate choice, visitor identification: a tick box of its own, naming RB2B. It is off unless you tick it. Accepting measurement does not turn it on, and it counts only together with measurement, because RB2B loads through the same Tag Manager.

If you tick it and you are in the United States, a script from RB2B (GetEmails, LLC, Austin, Texas) runs in your browser. RB2B matches your visit against its own database of people in US business and tells us who you probably are: your name, job title, company and LinkedIn profile and, where RB2B has one, an e-mail address, with the pages you viewed here. We use it to get in touch about Visual Sectors for your work. Those details come from RB2B's database, not from you.

RB2B says it identifies people only in the United States and that its database excludes UK and EU residents. RB2B's terms make it an independent controller of what its script collects: it uses that under its own privacy policy, not only on our instructions.

Untick it in the cookie settings and it stops from then on. The "Do not sell or share my personal information" link in the footer stops it too, together with measurement and ads. To have us delete what RB2B sent us about you, write to privacy@visualsectors.com.

3.8 What we do not collect


4. Why we process it, and on what basis

WhatWhyLawful basis (UK/EU GDPR Art. 6)
Account, password, email verificationTo give you an account and let you sign inContract — Art. 6(1)(b)
SessionsTo keep you signed inContract
Bot check on forms that send mail (Turnstile)Without it, a script could send mail through us at willLegitimate interests — Art. 6(1)(f): protecting the Service from abuse
Run records and allowance countersTo give you what you paid for, to count it honestly, and to answer a dispute about itContract
Campaign attributionTo understand which channels bring people who find the Service usefulLegitimate interests — Art. 6(1)(f): measuring our own marketing
Administrative audit trailSo that a decision granting differential access is defensible laterLegitimate interests, and legal obligation where it applies
Service emails — verification, password reset, changes to the ServiceTo operate the accountContract
Marketing emails, if anyConsent — asked for separately, never bundled with signup, withdrawable at any time
MeasurementConsent — off until you accept, withdrawable at any time
Visitor identification (RB2B), if you tick itTo learn which people in US business visited, and get in touch about Visual Sectors for their workConsent — Art. 6(1)(a) where the GDPR applies; off until you tick it, withdrawable at any time
Office-hours bookings, if you make oneTo hold the session you booked and send you its detailsContract — Art. 6(1)(b)
Office-hours recordings, if a session you join is recordedSo people who could not attend can watch it later, on our site and on YouTube. You appear in it only if you speak or turn your camera onLegitimate interests — Art. 6(1)(f): open education about the product. You can object — write to privacy@visualsectors.com and we cut your part or take the recording down
Payments, subscription state and balancesTo sell you a plan, take the payment, and give you what you paid forContract — Art. 6(1)(b)
The checkout consent recordTo show what you agreed to and whenLegal obligation — Art. 6(1)(c), and legitimate interests
Records of payments, refunds and disputesTax and accounting records we are required to keep, and defending a chargebackLegal obligation — Art. 6(1)(c), and legitimate interests — Art. 6(1)(f)
Fraud checks on a paymentStopping stolen cards being used on the ServiceLegitimate interests — Art. 6(1)(f), and Stripe's own legal obligations

Where we rely on legitimate interests, we have considered your interests and rights against ours. You can object — see §9.

Company-level lead qualification. Deriving your company from your email domain, and looking at which organisations are evaluating the Service, is commercial research on our own users. We consider it a legitimate interest, and it is one you can object to.


5. Who we share it with

We do not sell personal data or share it for third-party marketing, with one exception you control: visitor identification (§3.7a), which is off unless you tick it.

We use a small number of service providers who process data on our instructions. They are listed in full, with what each one receives, in Sub-processors. If you buy a plan, Stripe is one of them, and it is the only one that touches a payment. If you book an office-hours session, Calendly receives what you type into its booking form. We send it nothing about you. If a session you join is recorded, the recording is published on our site and on YouTube (§4).

We may also disclose data where we are legally required to, or to establish, exercise or defend legal claims.


6. Where your data is held

Your account data is stored in the United Kingdom. It sits in a PostgreSQL database that is not reachable from the internet — it listens only on its own loopback interface and is reached through a private tunnel.

The Service itself runs on Cloudflare's global edge network, which means a request you make is handled at whichever Cloudflare location is nearest to you.

Transfers to the United States. We are a US company, so our staff access UK-held data from the United States. For that transfer we rely on the UK International Data Transfer Agreement and the EU Standard Contractual Clauses, entered into between our UK entity and our US entity, together with the additional measures described in §10. You can ask us for a copy of the relevant clauses at privacy@visualsectors.com.

Our providers may also process data outside the UK and EEA under their own equivalent safeguards; each is named in Sub-processors.


7. How long we keep it

DataRetention
Account recordWhile your account exists
Sessions30 days, then expired and removed
Verification and reset tokensHours, and single-use
Run records and monthly countersWhile your account exists
Campaign attributionWhile your account exists
Administrative audit trailRetained after account deletion — see §8
Payment and subscription recordsKept after your account is deleted — see §8. Held for the period our tax and accounting obligations require
The checkout consent recordKept with the payment record it belongs to
Office-hours recordingsWhile published. If you object, we cut your part or take the recording down
What RB2B tells us about a visitor12 months from the visit if we have not been in touch; deleted sooner if you ask
Card brand and last four digitsWhile the card is on file; removed when you remove the card or close the account

8. Deleting your account, and what survives it

Ask us to delete your account and we delete it. Your sessions, tokens and attribution record are removed with it automatically — the database is built so that deletion cascades rather than leaving working credentials behind.

Five records are deliberately kept, and here is each one with its reason.

What is keptWhy
The administrative audit trail — who granted or revoked what, when, and the account and email it concernedAn audit log that disappears along with the thing it audits is not an audit log. Kept under Article 17(3)(e), establishing and defending legal claims
The unsubscribe list — your email address, marked as not to be emailedSo that an unsubscribe is honoured. If we deleted this, the next time your address entered our system you would start receiving email again, which is the opposite of what you asked for. Article 17(3)(b)
Your subscription records — what you bought, when, and for how muchPayment, tax and accounting records we are required to keep. Article 17(3)(b)
The history of changes to your subscription's stateSo that a later question about what you were entitled to on a given day — including a chargeback — has an answer. Article 17(3)(e)
Any paid entitlement carried over from our earlier platformSo that a right you paid for can still be honoured if you come back. Article 17(3)(e)

We keep only what each record needs, and nothing in these five is used for marketing or analysis.

If you object to any of these being kept in your particular circumstances, tell us at privacy@visualsectors.com and we will consider it on its facts.


9. Your rights

Under the UK GDPR and the EU GDPR you can ask us to:

Write to privacy@visualsectors.com, or to our UK/EU representative (§1). We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

These requests are currently handled by a person, not by a button. There is no self-service export or delete in your account yet. That does not change the deadline: ask, and it gets done within the month.

If you are unhappy with how we handle your data, please tell us first. You also have the right to complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113), or to the supervisory authority in your EU member state.


9a. If you live in the United States

We are a Delaware company, so this is worth stating plainly:

If a state law starts to apply to us as we grow, we will say so here before it does.


10. Security

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the ICO within 72 hours and, where the risk is high, tell you directly.


11. Children

The Service is not for under-18s and we do not knowingly collect their data. If you believe a child has given us data, write to privacy@visualsectors.com and we will delete it.


12. Cookies

One cookie keeps you signed in; our security provider sets two more; the office-hours booking calendar sets Calendly's own, only if you open it; nothing that measures you runs unless you accept it. It is all in the Cookie Policy.


13. Changes to this policy

The current version is always at this address with the version it carries and the date it was last updated. If we change it materially — a new purpose, a new recipient, a new kind of data — we will email the address on your account before the change takes effect.

This policy and the Data API's carry separate version numbers. A change here never re-prompts a Data API client, and a change there never re-prompts you.


14. Contact

Privacy: privacy@visualsectors.com Everything else: support@visualsectors.com

Controller — by post: Visual Sectors, Inc., Suite 305, 131 Continental Drive, Newark, Delaware 19713, United States

UK and EU representative — by post: Visual Sectors, Ltd., 20-22 Wenlock Road, London, N1 7GU, United Kingdom