Privacy Policy

Last updated: 15 June 2025

Stack Money (“we”, “our”, “us”) operates the website at stackmoney.in. This Privacy Policy explains what personal data we collect, how we use it, and the rights you have under India's Digital Personal Data Protection Act, 2023 (DPDP).

1. What we collect

  • Email address — only if you sign in (we use magic-link authentication, no passwords) or subscribe to the newsletter / morning digest.
  • Alert preferences — the metric, threshold, condition, channels (email, browser push) and cooldown you configure.
  • City preference — stored client-side in a cookie / localStorage to default the dashboard to your city.
  • Browser push subscription endpoint — if you enable push notifications, your browser hands us an endpoint we use to deliver alerts.
  • Aggregate, anonymous analytics — page views, country, device class, referrer (via Plausible & Microsoft Clarity). No cross-site tracking, no fingerprinting.

We do not collect your name, phone number, address, PAN, Aadhaar, bank details, or financial transactions. Stack Money is read-only — we never have access to any account.

2. How we use your data

  • To send you the magic sign-in link or the morning digest you requested.
  • To deliver alerts you configured, when their conditions match.
  • To remember your city preference between visits.
  • To understand how the site is used (in aggregate) so we can improve it.

3. Legal basis & consent (DPDP Act)

Under the DPDP Act, we process your personal data only on the basis of your free, specific, informed and unambiguous consent, expressed when you:

  • Submit your email to sign in / subscribe / configure an alert.
  • Click “Allow” on the browser-push permission prompt.

You can withdraw consent at any time (see “Your rights” below). Withdrawal does not affect processing already done lawfully.

4. Data we share

We do not sell or rent your personal data. We share the minimum required with sub-processors strictly to deliver the service:

  • Resend — sends transactional emails (magic links, alerts, digest). Email + content of the message only. Privacy.
  • Vercel — hosts the website. Receives standard request logs (IP, user-agent). Privacy.
  • Plausible Analytics — privacy-friendly, GDPR/DPDP-compliant analytics. No cookies, no personal data. Privacy.
  • Microsoft Clarity — session-level UX heatmaps. Anonymous; no PII collected. Privacy.

5. Where we store your data

Personal data (your email, alerts, digest preferences) is stored on servers located in Asia & Europe via our hosting provider. We retain it for as long as your account exists or your subscription is active. You can request deletion at any time.

6. Cookies & similar technologies

  • pp_session — an HTTP-only authentication cookie set after sign-in. 30-day expiry. Required for the alert / digest features.
  • pp_city — remembers your city preference. Optional; you can clear it without signing out.
  • No third-party tracking cookies. Plausible is cookie-less; Clarity drops a first-party UID with a 1-year expiry.

7. Your rights under DPDP

  • Right to access — ask us what personal data we hold about you.
  • Right to correction & erasure — ask us to correct, update, or delete your data.
  • Right to grievance redressal — complain about data handling.
  • Right to nominate — nominate another individual to exercise your rights in case of incapacity / death.
  • Right to withdraw consent — you can unsubscribe from emails (one-click link in every email), revoke browser push permission (browser settings), or delete your account.

To exercise any right, write to [email protected] from the email address on file. We respond within 30 days.

8. Data Protection Officer / Grievance Officer

As a Significant Data Fiduciary obligation does not yet apply to Stack Money given its scale, we currently route all data-related requests through:
Grievance Contact: [email protected]
We will appoint a formal DPO if and when our user-base / processing scale crosses the threshold notified by MeitY.

9. Children

Stack Money is not directed to children under 18. We do not knowingly collect data from minors. If you believe a child has provided us data, email us and we'll delete it.

10. Security

All traffic is HTTPS-only. Authentication uses one-time, 15-minute magic links — no passwords are stored. Alert and digest data is stored in encrypted form at rest by our hosting provider. We follow industry best practices, but no system is 100% secure; we cannot guarantee absolute security.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email (if you're a subscribed user) and a banner on the homepage for 14 days. Continued use after the effective date constitutes acceptance.

12. Contact

Stack Money
Email: [email protected]
Website: stackmoney.in


See also our Terms of Service. Stack Money is a free, ad-free, read-only information service. We are not a SEBI-registered advisor; nothing on this site is investment advice.