Skip to content
K

SPZCO — Privacy Policy

Effective Date: July 27, 2026

Controller: SPZCO LLC, a Maine limited liability company ("SPZCO", "we", "us", or "our"), the owner and operator of the SPZCO investment-research service (the "Service").

This Privacy Policy (the "Policy") explains how SPZCO collects, uses, discloses, and protects the personal data of the individuals who create an account with, subscribe to, or otherwise use SPZCO. It forms part of, and should be read together with, our Terms of Use and the accompanying disclaimer.


1. Introduction & Scope

1.1 What this Policy covers. This Policy describes how we handle the personal data of our subscribers, prospective subscribers, and visitors to our website and web application (each, "you", "your", "Subscriber", or "User"). "Personal data" (also called "personal information") means information that identifies, relates to, or could reasonably be linked to an identifiable individual.

1.2 Whose data this concerns. This Policy concerns your personal data as a Subscriber — for example, your account email and the technical records generated when you use the Service. It does not concern the securities, market, filings, and financial datasets available inside the Service. That financial content is information about public companies, securities, prices, and public filings (for example, SEC/EDGAR disclosures) — it is the subject matter of the product, not personal data about you, and is governed by our Terms of Use rather than by this Policy.

1.3 Relationship to the Terms of Use. Your use of the Service is subject to our Terms of Use, into which this Policy is incorporated by reference. Capitalized terms not defined here have the meaning given in the Terms of Use.

1.4 Controller. For the purposes of the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and similar laws, SPZCO is the "controller" of the personal data described in this Policy. Our contact details are in Section 14.


2. Information We Collect

We collect only the personal data we need to operate a paid, account-based service. We do not build advertising or cross-site tracking profiles. The categories are:

2.1 Account data. When you register, we collect the information needed to create and secure your account. Authentication for the Service is handled by Supabase, which on our behalf stores your account email address, a hashed password (we never see or store your password in plain text) or, if you sign in with Google, your OAuth identity/identifier in place of a password, a unique user ID, and related timestamps (such as account creation and last sign-in). If you choose Google OAuth sign-in, Google confirms your identity to us and shares basic profile information (such as your email address and name) in accordance with your Google account settings and Google's privacy policy; we do not receive your Google password. You may also provide a name or display name.

2.2 Subscription & billing metadata. Payments and subscriptions are processed by Stripe, Inc. ("Stripe"), our payment processor; SPZCO is the merchant of record. Stripe — not SPZCO — collects and processes your payment-card details (such as card number, expiry, billing name, and billing address) as a PCI-DSS-compliant processor under Stripe's own privacy policy and terms. SPZCO does not receive, see, or store your full payment-card number. From Stripe we receive and store only limited billing metadata needed to provision and manage your access — for example, subscription status (active, past due, cancelled), plan and billing period, subscription and transaction identifiers, the card brand and last four digits, the billing country/region and currency used for tax, and the email and name associated with the purchase. Please review Stripe's privacy policy to understand how it handles the payment data it collects.

2.3 Usage & technical data. When you access the Service, our infrastructure automatically records certain technical information for security, reliability, and abuse-prevention purposes. Our API runs on a Hetzner server behind Cloudflare, and our website is served by Vercel. Through Cloudflare and our own server logs we collect data such as your IP address, approximate location derived from it, device and browser type (user-agent), the pages, endpoints, and requests you access, request and response metadata, rate-limiting and security signals, and timestamps. This data is used to operate the Service, enforce rate limiting, and protect against misuse (see Section 3).

2.4 Cookies & local storage. The Service uses essential cookies and browser local storage to keep you signed in — principally to store your Supabase authentication/session token so you are not logged out on every request. These are strictly necessary for the Service to function. We do not use third-party advertising cookies or cross-site ad-tracking. See Section 6 for details and how to control them.

2.5 Communications. If you contact us for support or otherwise correspond with us (for example, by email to support@spzco.com), we collect the information you choose to provide — such as your email address, the content of your message, and any attachments — so we can respond and keep a record of the request.

2.6 What we do not collect. We do not intentionally collect special-category / sensitive personal data (such as health, biometric, or precise-geolocation data), and we ask that you not send it to us. We do not collect payment-card numbers (Stripe does), and we do not track you across other websites for advertising.


3. How We Use Information

We use the personal data described above for the following purposes:

3.1 To provide and operate the Service. Create and maintain your account, deliver the web application and its content, remember your session, and provide the features you subscribe to.

3.2 To authenticate you. Verify your identity at sign-in (via Supabase, including Google OAuth if you choose it) and keep your account secure.

3.3 To process subscriptions and billing. Provision, renew, downgrade, suspend, or cancel your access based on the subscription status and billing metadata we receive from Stripe, our payment processor, and to reconcile our records.

3.4 For security, fraud, and abuse prevention, and rate limiting. Monitor for, detect, investigate, and prevent unauthorized access, credential sharing, scraping or bulk extraction, fraud, and other misuse; enforce our rate limits and technical protections; protect our intellectual property and the integrity, availability, and performance of the Service; and keep the Service and its users safe.

3.5 To improve the Service. Understand how the Service is used in aggregate, diagnose problems, and maintain and improve reliability, performance, and features.

3.6 For legal compliance. Comply with applicable laws and regulations, respond to lawful requests and legal process, enforce our Terms of Use, and establish, exercise, or defend legal claims.

3.7 To communicate with you. Send you service and transactional communications — for example, account, security, billing, and subscription notices, and responses to your support requests — and, where permitted, important updates about the Service or changes to our terms or this Policy. These service messages are part of the Service and are generally not "marketing."


4. Legal Bases for Processing (GDPR / UK-GDPR)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

4.1 Performance of a contract. To create and operate your account, authenticate you, deliver the Service, and process your subscription — this processing is necessary to perform our contract with you (the Terms of Use) or to take steps at your request before entering into it (Article 6(1)(b)).

4.2 Legitimate interests. To secure and operate the Service, enforce rate limits, prevent and investigate fraud, credential sharing, scraping, intellectual-property theft, and other misuse, maintain and improve the Service, and keep records — these serve our legitimate interests (and those of our users) in running a safe, reliable, and sustainable service, balanced against your rights and freedoms (Article 6(1)(f)). You may object to processing based on legitimate interests (see Section 10).

4.3 Consent. Where we rely on consent — for example, for any non-essential communications where required — you may withdraw it at any time without affecting the lawfulness of processing before withdrawal (Article 6(1)(a)).

4.4 Legal obligation. To comply with legal, tax, accounting, and regulatory obligations and lawful requests (Article 6(1)(c)). Note that tax on your purchase is handled by SPZCO, as merchant of record, using Stripe Tax or an equivalent facility.


5. How We Share Information

We share personal data only as described below. We do not sell your personal information, and we do not use it for third-party advertising or cross-context behavioral advertising.

5.1 Service providers / sub-processors. We share personal data with vetted vendors that process it on our behalf, under contract and only for the purposes described in this Policy. Our principal providers are:

  • Supabase — authentication and identity (account email, hashed password or OAuth identity, user ID, session/auth tokens).
  • Stripe — payment processing and subscription billing (collects and processes payment-card and billing data under its own privacy policy; returns limited billing metadata to us). SPZCO is the merchant of record.
  • Hetzner — hosting and infrastructure for our API and databases (processes data stored and transmitted through our servers, including server logs).
  • Cloudflare — content delivery, network security, WAF, and rate limiting for our API (processes IP addresses and request metadata).
  • Vercel — hosting of our website and web front end (processes request and delivery metadata).

Each provider processes data in accordance with its own terms and privacy policy; we encourage you to review them.

5.2 Disclosures required by law. We may disclose personal data where we believe in good faith that it is necessary to comply with a law, regulation, legal process, or enforceable governmental or lawful request; to enforce our Terms of Use; or to protect the rights, property, safety, or security of SPZCO, our users, or the public, and to detect, prevent, or address fraud, security, or technical issues.

5.3 Business transfers. If SPZCO is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, personal data may be transferred as part of that transaction, subject to the surviving or acquiring entity honoring this Policy or providing notice of any material change.

5.4 With your direction. We may share personal data at your direction or with your consent.

5.5 No sale; no ad-tracking. We do not sell personal information for money or other valuable consideration, we do not "share" it for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws, and we do not disclose it to third-party advertising networks.


6. Cookies & Local Storage

6.1 Essential only. The Service uses only strictly necessary cookies and browser local storage. Their primary purpose is to store your Supabase authentication/session token so that you remain signed in as you navigate the Service, and to support core security functions such as rate limiting and fraud prevention.

6.2 No advertising cookies. We do not use advertising, marketing, or cross-site tracking cookies, and we do not embed third-party ad-network trackers.

6.3 How to control cookies. You can view, block, or delete cookies and clear local storage through your browser settings. Please note that because our cookies/local storage are essential to authentication, disabling or blocking them will prevent you from signing in and will break core functionality of the Service.

6.4 Do Not Track and Global Privacy Control. Because we do not sell or "share" personal information, do not engage in cross-context behavioral advertising, and use only strictly necessary cookies, there is no tracking for a "Do Not Track" or "Global Privacy Control" (GPC) signal to switch off; to the extent applicable law treats a GPC signal as a valid opt-out request, we honor it, and it does not affect the essential authentication cookies described above.


7. Data Retention

7.1 Account data. We retain your account data (such as your email and user ID held via Supabase) for as long as your account is active, and for a reasonable period afterward to wind down the account, meet legal, tax, and accounting obligations, resolve disputes, and enforce our agreements.

7.2 Log and technical data. IP addresses, request metadata, and other log data collected for security and rate limiting are retained for a limited period appropriate to those security and operational purposes, after which they are deleted or aggregated/anonymized, except where a longer period is needed to investigate an incident or comply with law.

7.3 Billing metadata. Subscription and billing metadata is retained as needed to manage your subscription and to meet financial and legal-retention requirements. Payment-card data is held by Stripe, not by us, under Stripe's retention practices.

7.4 Deletion on account closure. When you close your account (or ask us to delete your data), we will delete or anonymize your personal data within a reasonable time, except where we are required or permitted by law to retain it (for example, for tax, accounting, fraud-prevention, security, or dispute-resolution purposes), in which case we retain only what is necessary and for only as long as necessary.


8. Security

8.1 Our measures. We maintain reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. These include encryption in transit (HTTPS/TLS), reliance on reputable providers (Supabase for authentication with hashed passwords; Cloudflare for network security, WAF, and rate limiting), access controls limiting who can access data, and monitoring and logging.

8.2 No absolute security. Despite these measures, no method of transmission over the internet or of electronic storage is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and for the security of your own devices (see the Account Security provisions of the Terms of Use). Please notify us promptly at support@spzco.com if you believe your account has been compromised.


9. International Data Transfers

9.1 Cross-border processing. SPZCO and its providers may store and process personal data in countries other than the one in which you reside, including in the United States and the European Union / European Economic Area. Data-protection laws in those countries may differ from those in your jurisdiction.

9.2 Transfer safeguards. Where we transfer personal data from the EEA, the UK, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), or on an applicable adequacy decision or other lawful transfer mechanism. You may contact us at support@spzco.com for more information about the safeguards we use.


10. Your Privacy Rights

Depending on where you live, you may have some or all of the rights below. We will honor rights required by applicable law and will not discriminate against you for exercising them.

10.1 GDPR / UK-GDPR rights. If you are in the EEA, the UK, or Switzerland, you have the right to: (a) access the personal data we hold about you; (b) request rectification of inaccurate or incomplete data; (c) request erasure ("right to be forgotten"); (d) request restriction of processing; (e) data portability (receive certain data in a portable format); (f) object to processing based on legitimate interests or to direct marketing; (g) withdraw consent at any time where processing is based on consent; and (h) lodge a complaint with a supervisory authority (your local data-protection authority; in the UK, the Information Commissioner's Office). We would appreciate the chance to address your concerns before you do so.

10.2 CCPA / CPRA rights (California) and similar U.S. state laws. If you are a California resident (or a resident of another U.S. state with comparable rights), you may have the right to: (a) know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; (b) delete personal information we collected from you; (c) correct inaccurate personal information; and (d) opt out of the "sale" or "sharing" of personal information and of certain targeted advertising. As stated in Section 5, we do not sell or "share" personal information and do not use it for cross-context behavioral advertising, so there is nothing to opt out of. You also have the right to non-discrimination for exercising your rights. You may use an authorized agent to submit a request where the law permits.

10.3 How to exercise your rights. To make a request, contact us at support@spzco.com. To protect your privacy and security, we will take reasonable steps to verify your identity before acting — typically by confirming control of the email address associated with your account — and may decline or limit a request where we cannot verify you or where an exception applies under law. We will respond within the timeframes required by applicable law.

10.4 Third-party processors. Some of your rights (for example, regarding payment data) may need to be exercised with the relevant provider — most notably Stripe for payment-card and billing data. We will help direct you where appropriate.


11. Children's Privacy

The Service is intended for adults and is not directed to, and not intended for use by, anyone under 18 years of age (and in no event by anyone under the minimum age of digital consent in their jurisdiction, such as 16 under the GDPR or 13 under U.S. law where applicable). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@spzco.com and we will take appropriate steps to delete it.


12. Third-Party Links & Services

The Service and our communications may contain links to, or interoperate with, third-party websites and services — for example, links to original SEC/EDGAR filings or other public sources, or the sign-in and payment flows operated by Google, Supabase, and Stripe. We do not control and are not responsible for the privacy practices or content of those third parties. Their handling of your data is governed by their own privacy policies, which we encourage you to review.


13. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide reasonable notice — for example, by posting the updated Policy with a new Effective Date and/or by notifying you through the Service or by email. Changes are effective when posted or on the stated effective date. Your continued use of the Service after the changes take effect constitutes your acceptance of the revised Policy, except where additional consent is required by law.


14. Contact / How to Reach Us

For any questions, concerns, or requests regarding this Policy or your personal data, contact:

SPZCO LLC A postal address is available on request by emailing us at the address below. Email: support@spzco.com

Data Protection Officer / EU–UK Representative: SPZCO does not have an establishment in the EU or UK and has not appointed an Article 27 representative; EEA and UK users may contact us using the email above. Paid subscriptions are offered only to residents of the United States (see Terms of Use §1.3).

Governing jurisdiction for privacy matters: State of Maine, United States

If you are in the EEA or the UK and are not satisfied with our response, you have the right to lodge a complaint with your local data-protection supervisory authority (see Section 10.1).


This Privacy Policy should be read together with the Terms of Use and the disclaimer. By using SPZCO, you acknowledge that you have read and understood this Policy.