Privacy & Cookies

What we collect, why, and how to get rid of it

Legal

Privacy & Cookies Policy

This policy describes exactly what BensTrack stores, what leaves your browser, and who else is involved. It is written to be read, not to be skimmed past.

Last updated: August 2026

1. Who is responsible

BensTrack is operated by [Operator legal name β€” set SITE_OPERATOR], [Registered address β€” set SITE_ADDRESS]. For any privacy question or request, write to benstrackportfolio@gmail.com. We respond to data requests within 30 days.

2. What we collect

We collect the minimum needed to make the tools work, and nothing for profiling.

Account data
Username, email address and a salted one-way hash of your password. The password itself is never stored and cannot be recovered by us. If you sign in with Google we store the Google account identifier and the email address that Google returns; we never receive your Google password.
Portfolio data
The tickers, quantities, prices, dates, currencies, sales, watchlist targets and display preferences that you type in. This is the content of your account and belongs to you.
Session data
A signed session cookie that keeps you logged in. If you use the app without an account, we store an anonymous guest identifier in the same cookie so your positions survive a reload.
Browser storage
Your colour scheme, interface language and preferred display currency are kept in localStorage on your own device. They never reach our server.
Server logs
Standard web-server request logs, including IP address, kept only for security and abuse prevention (our rate limiter needs them) and rotated regularly.

We do not sell personal data, we do not build advertising profiles from your portfolio, and your holdings are never shared with any third party.

3. Cookies

The only cookie BensTrack sets itself is the session cookie described above. It is strictly necessary: without it the application cannot tell one visitor from another. It is marked HttpOnly and SameSite=Lax, and Secure in production.

4. Third parties your browser contacts

Using BensTrack causes your browser to make requests to the services below. Each of them therefore sees your IP address. None of them receives your account details or your holdings β€” only public identifiers such as a ticker symbol.

  • TwelveData twelvedata.com β€” Primary source of real-time and historical stock and ETF prices. Requested by our server, not your browser.
  • Yahoo Finance finance.yahoo.com β€” Fallback price data and the sole source of FX rates, dividends and company fundamentals. Requested by our server.
  • CoinGecko api.coingecko.com β€” Cryptocurrency search, prices and coin logos.
  • Google Fonts fonts.googleapis.com β€” The Inter and JetBrains Mono typefaces, loaded directly by your browser.
  • jsDelivr cdn.jsdelivr.net β€” The Chart.js charting library.
  • Google Sign-In accounts.google.com β€” Only if you choose to sign in with Google.

5. Where your data lives

Account and portfolio data are stored in our own database on the server that runs this application. They are not copied to analytics platforms, ad networks or data brokers.

6. How long we keep it

Portfolio and account data are kept while your account exists. Guest data is tied to a session cookie and disappears when that cookie expires. Delete your account and the associated rows are removed; write to benstrackportfolio@gmail.com and we will do it for you.

7. Your rights

If you are in the European Economic Area or the United Kingdom you have the right to access, rectify, erase, restrict and port your data, and to object to processing. Exercise any of them by writing to benstrackportfolio@gmail.com. You may also lodge a complaint with your national data-protection authority.

8. Children

BensTrack is not directed at anyone under 16 and we do not knowingly collect their data. If you believe a minor has created an account, contact us and we will delete it.

9. Changes

We may update this policy. Material changes will be reflected in the "last updated" date at the top of this page. Continued use after an update means you accept the revised policy.