Bufetico Open Bufetico
Bufetico

Privacy Policy

Last updated: 3 September 2026

This policy explains what personal data Bufetico collects, why we have it, and what you can do about it. It is written to be read, not skimmed past.

1. Who is responsible for your data

Bufetico is operated by JH GRANDGERARD, an individual established in the United States (“we”, “us”). We are responsible for the personal data described below.

One thing here is not only ours, so we put it at the top instead of burying it. To measure our advertising we send purchase events to Meta Platforms, Inc., and Meta then uses them inside its own advertising system, for its own purposes. We decide what is sent and when, and we answer to you for it; what Meta does afterwards is governed by Meta’s privacy policy. Sections 3, 5 and 8 explain all of it, including the limit that matters most: we only do this when the country on your payment is the United States. From every other country (Canada, Australia, the United Kingdom, the European Union, everywhere) nothing is sent at all. Section 8 tells you how to stop it, and that works wherever you live.

For any privacy matter, write to support@bufetico.com.

2. What we collect

Data you give us, or that comes with your payment

DataWhy we have it
Email addressTo create your account, sign you in, and contact you about the service. If the country on your payment is the United States it has one more use: at the moment you pay, we make a one-way encrypted (SHA-256) copy of it and send that to Meta, so Meta can match your purchase to the ad you came from. Meta never receives your address in the clear. If you pay from any other country, or from a payment that carries no country, nothing is sent. Sections 3, 5 and 8 explain it, and the box in section 8 says how to stop it.
PasswordStored only as a cryptographic hash by our authentication provider. We never see it.
Google or Facebook sign-inIf you use social sign-in, we receive your email address and a basic profile identifier from that provider. We never receive your password. That is data coming to us. Data also goes the other way, and it has nothing to do with this button: if the country on your payment is the United States, we send Meta a purchase event whether or not you ever touched the Facebook button. See sections 3 and 5.
Portfolio holdings you enterTo show your positions and their metrics
Profile photo (optional)Shown only to you, inside your own account
Support messagesTo answer you, and to keep a record of what users ask
A hash of your email addressTo ensure the $1 first month is used once per person. See section 6. There is a second, separate hash of the same address, made for a completely different reason: the purchase event we send to Meta. Sections 3, 5, 6 and 8 cover that one. Two hashes, two purposes, and we keep them apart.
The country of your paymentStripe tells us the country of the billing address on your payment. Besides tax, it does one thing: it decides whether an advertising event is sent at all. The United States, and nothing from anywhere else. If your payment carries no country, we treat it as unknown and send nothing. If it is wrong, you can ask us to correct it, see section 8.

Data created by using the service

If you connect a broker (optional)

Broker connections are handled by SnapTrade. You authenticate in a window operated by SnapTrade, and we receive only a pair of identifiers plus your read-only positions.

We never receive or store your broker username, password, or any other broker credential. The connection is read-only: Bufetico cannot place trades, move money, or change anything in your brokerage account.

3. What we do not collect, and the one thing we do send

The one thing we do send

When you pay, we send Meta an advertising event, and several US state laws call that a “sale” and a “share”. We are not going to argue about the label, so here it is in plain words. When Stripe confirms that a payment went through, our server sends Meta six things: the amount, the currency, a one-way encrypted (SHA-256) copy of your email address, the identifier of the ad click that brought you if there is one, the campaign tag on the link you arrived through if there is one, and your Stripe invoice number, which is there so that Meta can discard the same confirmation if Stripe sends it twice. It does not carry your name, your IP address, your browser, or anything at all about your portfolio.

There are two kinds of event, and this is not a one-off. One is sent the first time you pay. The other is sent when your subscription renews. So for as long as you stay subscribed, an event about you goes to Meta each time you are charged.

And it only happens for one country. The code carries a list of the countries it is allowed to send from, and that list has one entry: the United States. The country comes from the billing address on your payment, as Stripe reports it. If it is anything else, or if your payment carries no country at all, nothing goes to Meta. It is a list of the countries we are allowed to send from, not a list of the ones we leave out, so everywhere else stays out by default and nobody has to remember to keep it up to date.

Nothing runs in your browser for this. There is no Meta pixel and no Meta advertising code on bufetico.com or in the app. The event travels from our server to Meta’s. If you choose the Facebook sign-in button you are taken to Meta’s own site to sign in, and there Meta sees you as its own visitor; that part is theirs, not ours.

Section 8 tells you how to switch this off, wherever you live.

4. Why we process it, and on what basis

PurposeWhy we are allowed to
Providing the service you signed up forBecause it is what you are paying us for
Billing and subscription managementBecause we have to charge you and keep the record of it
Security, abuse prevention, usage limitsBecause the service would not survive without it
Service email (alerts you configured, account notices)Because it is part of the service you signed up for
Marketing emailBecause you said yes, and you can say no at any time
Push notificationsBecause you turned them on, and you can turn them off at any time
Advertising measurement: telling Meta that a purchase or a renewal happened, so we can see which ads bring customersBecause we need to know whether our advertising works, and what leaves us is narrow, section 3 lists every field of it. It runs unless you tell us to stop, and you can tell us at any time; the box in section 8 says how, and it takes one line. We only do this for payments whose country is the United States, where these state laws allow exactly that. We do not do it anywhere else, so we are not relying on this anywhere else.
Loading the app’s typefacesBecause the app is drawn in them. They are served from bufetico.com itself, so opening Bufetico contacts nobody but us. Sections 5 and 10 describe it.

5. Service providers

We use a small number of providers to run Bufetico. Most of them receive only what they need to make the service work. Meta is the only one we send data to for advertising, and that is why it has two rows below: one for signing in, one for measurement. That second one is not needed to run Bufetico at all. It is there so we can see which ads bring customers, and it only happens when the country on your payment is the United States.

ProviderRoleWhat it sees
SupabaseDatabase, authentication, file storageAccount data, portfolios, profile photo, and your IP address: your browser talks to it directly, at auth.bufetico.com, on every request the app makes
GoogleSigning in, only if you choose that buttonThat you signed in to Bufetico; it passes us your name and email address
Meta (Facebook)Signing in, only if you choose that buttonThat you signed in to Bufetico; it passes us your name and email address
Meta (Facebook)Advertising measurement, and only when the country on your payment is the United States. It applies to everyone who pays from there, whether or not you ever used the Facebook button. From every other country, Canada and Australia included, nothing is sent.When Stripe confirms a payment, our server sends Meta the amount, the currency, a one-way encrypted (SHA-256) copy of your email address, the identifier of the ad click that brought you if there is one, the campaign tag you arrived through if there is one, and your Stripe invoice number so that duplicates can be discarded. Meta never sees your address in the clear. Be clear-eyed about what that means, though: Meta holds its own users’ addresses and can encrypt them the same way to see which one matches. The encryption stops anyone else from reading it; it does not hide you from Meta. Meta also uses the event inside its own advertising system.
RenderBackground jobsAccount data while processing
CloudflareDomain, hosting, email routing, visit countsNetwork traffic, inbound email, pages viewed
BrevoSending emailYour email address and the message content
StripePaymentsPayment and billing details, including the country of the billing address on your payment. Stripe’s confirmation that a payment went through is what sets off the event we send to Meta, and the country Stripe reports is what decides whether that event is sent at all.
SnapTradeBroker connection (optional)Broker authorization and positions
Your browser’s push service (Google, Apple or Mozilla, depending on the browser)Delivering push notifications (optional)An anonymous delivery address for your device, and the encrypted notification
Financial Modeling PrepMarket data supplierNo personal data

Most of these providers operate in the United States; some operate elsewhere, including in the European Union and Canada. That means your data crosses borders, and if you are in Australia this is the overseas disclosure that Australian Privacy Principle 8 is about. We rely on the contractual protections each provider offers, and we will send you a copy of the relevant terms if you ask. Using Bufetico is not your agreement to any of this: choosing these suppliers was our decision, and it is on us. If you would rather we did not process your data at all, write to us and delete your account, and we will remove everything except the few things listed in section 7, which we cannot take back.

6. How long we keep it

DataRetention
Sign-ups that were never confirmedOne reminder after 24 hours, then deleted after 30 days
Active accountsKept while the account exists
Deleted accountsRemoved at the moment you confirm the deletion, including portfolios, positions, preferences, devices, the broker connection and the profile photo. Some things do not go with them, and each one has its own row below.
Support messagesKept as a record of what users ask. Deleting your account unlinks the message from you, but your name, your email address and what you wrote stay in that record.
Billing recordsKept as long as accounting and tax rules require. They contain personal data, your email address, the amounts, the dates and the country of your payment, and they outlive your account, because the tax rules do not care that you left.
Server logsKept only while they are useful for security and for finding out why something broke, and never used for advertising. We are not going to name a number of days we have not measured. Our providers keep logs of their own, under their own terms and their own retention, and those are not ours to delete.
Request countsDeleted automatically: a daily job removes every counter older than a week. They are only ever used to enforce usage limits and detect abuse.
A one-way hash of your email address, for the $1 offerKept permanently, including after you delete your account, so the $1 first month can only be used once per person. We cannot turn it back into your address, it never leaves us, and it is never used to contact you or for anything else. It is not the hash we send to Meta.
The hash of your email address that goes to MetaWe do not store it. It is built at the moment of the payment, sent, and dropped. What Meta keeps afterwards is on Meta’s side.
The campaign tag and the ad click identifier you arrived withOn your device until you clear this site’s storage; on your account for as long as the account exists, and deleted with it
Purchase and renewal events already sent to MetaWhen you opt out or delete your account we stop sending, and the check runs before every event, so the next one is already covered. What has gone is on Meta’s side: we cannot reach in and delete it, and we are not going to pretend otherwise. If your payment country is not the United States, nothing was ever sent and there is nothing to undo.

A confirmed account is never deleted for inactivity alone.

7. Your rights

You can ask us to:

Some things survive deletion, and here they are. When you delete your account we remove your personal data at that moment, profile, portfolios, positions, preferences, devices, the broker connection. These are the ones that stay behind, and we would rather list them than let you discover them.

The anti-abuse hash. We keep a one-way hash of your email address. It is what stops the same person from taking the $1 first month again and again, and that is the only reason we keep it. We cannot turn it back into your email address, it never leaves us, and it is never used to contact you. It is not the hash we send to Meta: that one is built at the moment of a payment and is not stored at all.

Your opt-out. If you asked us not to share your purchases for advertising, that request stays even after the account is gone. It is stored as a one-way hash of your email address, never the address itself. We keep it on purpose: if it disappeared with the account, anyone who deleted and came back would silently have the sharing switched on again, and we would have undone the one thing you asked for.

The billing records. Invoices and payment history contain your email address, the amounts, the dates and the country of your payment. Accounting and tax rules make us keep them for years, whether you are still a customer or not. Section 6 has the row.

The support messages you sent us. Deleting your account unlinks them from you, but your name, your email address and what you wrote stay in that record, because it is also our record of what people ask us for.

Whatever has already gone to Meta. If your payment country is the United States, any events already sent are on Meta’s side. Deleting your account stops the next one (the check runs before every event), but we cannot reach into Meta and delete the ones that went, and we are not going to pretend otherwise. If you paid from anywhere else, nothing was ever sent and there is nothing to undo.

Write to support@bufetico.com. A person reads it, and we answer in writing within 30 days. If our answer does not satisfy you, you can take it further: in the United States, to your state Attorney General; in Canada, to the Office of the Privacy Commissioner; in Australia, to the Office of the Australian Information Commissioner. If you are in the European Union or the United Kingdom, you may complain to your national data protection authority.

8. Advertising measurement, and your privacy rights

Most of this section is about US state law. If you live somewhere else, your part is further down: there is a heading for Canada and Australia, and another for the European Union and the United Kingdom.

Bufetico is operated from Florida. Several US states give their residents specific privacy rights, including California, Colorado, Connecticut, Florida, Montana, Oregon, Texas, Utah and Virginia. If you live in one of them, you may ask us to:

Do Not Sell or Share My Personal Information

We do sell and share personal information, in the sense these laws use the words. When you pay, our server sends Meta the amount, the currency, a one-way encrypted copy of your email address, the identifier of the ad click that brought you, the campaign tag you arrived through, and your Stripe invoice number, which lets Meta discard duplicates. Nobody hands us money for it, but getting better advertising in return is enough for California law, and for the laws of the other states listed above, to call it a sale, a share for cross-context behavioral advertising, and targeted advertising. We are not going to argue about the label.

It only happens when the country on your payment is the United States. That country is the one Stripe reports from the billing address on your payment. If it is anything else, or if your payment carries no country at all, no event is sent and there is nothing to opt out of.

How to opt out. None of these ways asks you to prove who you are. There is a form at bufetico.com/do-not-sell that works without an account and without signing in: you type the email address you paid with and press the button. There is a switch in Settings inside the app, under Privacy, reading “Do not share my purchases for advertising”, that one is simply already inside your account, which is not the same as asking you to prove anything. And you can send one line to support@bufetico.com telling us the address you paid with, and we do it by hand.

What happens then. The form and the switch take effect straight away: from that moment the check runs before every event, so a new payment and every renewal after it are both stopped. An email to support takes as long as it takes us to read it. Nothing about your subscription, your price or your features changes because you opted out, and we will not treat you differently for it. Someone else can do it on your behalf. And we honor it for anyone who asks, wherever you live, not only in the states that require it.

You do not have to ask at all if your browser asks for you. We honor the Global Privacy Control signal. If your browser sends it, opening Bufetico while signed in is enough for us to record it, you never have to write to us or fill in anything. It is read when the app starts and again when a payment begins, so if you are signed in there is no way to send that signal and have it ignored. “Tracking signals”, further down this section, explains where we read it and what it reaches.

Where to find this without reading a policy. The link titled “Do Not Sell or Share My Personal Information” is in the footer of bufetico.com, the home page, this policy, the terms and the support page, and the switch is in Settings inside the app, under Privacy.

Under 16. We have no actual knowledge that we sell or share the personal information of anyone under 16. Bufetico is for adults. If we learn that an account belongs to someone under 16 we delete it, and nothing further is sent about it.

What we still do not do. We do not profile you ourselves, and we make no automated decisions about you that produce legal or similarly significant effects. Meta does use the event inside its own advertising system, and that is profiling, by Meta, not by us. Opting out is what stops us feeding it.

If you are in Canada or Australia

Neither country is measured. In Canada your personal data is covered by PIPEDA, and in Quebec also by Law 25; in Australia, by the Privacy Act 1988 and its Australian Privacy Principles. Both would require your express permission before a purchase of yours could be sent to an advertising platform, we have not built a way to ask for it, and so we send nothing. The list of countries in our code has one entry, and it is not yours.

Everything else in this policy applies to you. You can ask for a copy of your data, ask us to correct it, and ask us to delete your account, by writing to support@bufetico.com. The opt-out above is open to you as well, if you would rather have it recorded on your account as a precaution. And if you ask us where a piece of information about you came from (the campaign tag, or the ad click identifier), we will tell you.

If you are in the European Union or the United Kingdom

Not measured either. Your personal data is covered by the General Data Protection Regulation, and in the United Kingdom by the UK GDPR and the Data Protection Act 2018. Nothing about your payments is sent to Meta or to any other advertising platform: the list of countries in our code has one entry, and it is the United States.

Section 4 already answers the question these laws ask first, what we use each piece of data for, and why we are allowed to. Section 7 lists what you can ask us for. On top of that you may ask us to restrict how we use your data while a question is open, object to a particular use, and withdraw permission you gave us earlier, such as for marketing email or push notifications. Withdrawing it does not undo what we did before, and it never affects the service you are paying for.

And you can complain about us without asking us first. If you are in the European Union, to the data protection authority of the country you live in; in the United Kingdom, to the Information Commissioner’s Office. We would rather you wrote to support@bufetico.com and gave us the chance to fix it, but that is a preference, not a condition.

Where your data is, if you are in Europe

It leaves Europe. Bufetico has no servers of its own: the service runs on providers based in the United States, and section 5 names every one of them: Supabase for the database and sign-in, Render for the scheduled jobs, Cloudflare for the site and the app, Stripe for payment, Brevo for email, and the market-data provider. Your account, your portfolios and your settings are stored and processed there.

We are telling you this rather than burying it because it is the part people are entitled to know and almost never get told. Transfers out of the European Economic Area and the United Kingdom rely on the standard contractual clauses that these providers include in their data processing terms, which is the mechanism the law provides for exactly this situation. If you want to know what a specific provider does with the data it holds for us, section 5 links to each one’s own policy.

Categories we collect

The third column answers one question: does any of it go to an advertising platform? Meta is the only one we send anything to, and only for payments whose country is the United States. For every other country the whole column reads no.

CategoryExamples in BufeticoSold or shared for advertising?
IdentifiersEmail address, account identifier, the one-way encrypted copy of your email address, the ad click identifier, your Stripe invoice numberYes, to Meta: the encrypted copy of your email address, the ad click identifier, and the invoice number that lets Meta discard duplicates. Never your address in the clear, and never your account identifier.
Commercial informationSubscription status, the holdings you record, the amount and currency of each paymentYes, to Meta: the amount and the currency of a payment. Never your holdings, and never what you looked at in the app.
Internet activityRequest counts, saved filters, tutorials watched, the campaign tag you arrived with, your IP addressYes, to Meta: the campaign tag you arrived with. Nothing else in this row, not your request counts, not your saved filters, not the tutorials you watched, and not your IP address.
Geolocation, country level onlyThe country of the billing address on your payment, as Stripe reports itNo. We use it to decide whether an event is sent at all, and the country itself is not part of what we send.
Visual informationYour profile photo, if you upload oneNo
Financial informationCard details are held by Stripe and never by us. The amount and the currency of each payment we do hold, and they also appear under Commercial information above.Yes, to Meta: the amount and the currency, and nothing else. Never card details, never a card number, never a bank account.
Sensitive personal informationThe login to your account: your email address together with your password. And, if you connect a broker, the pair of identifiers SnapTrade gives us, which is read-only access to your positions.No. Never, to anyone.

We collect this for the purposes set out in section 4, which now has a row for the advertising measurement, and we keep it for the periods in section 6, which now has rows for the campaign tag, the ad click identifier, the request counts and the events already sent to Meta. California counts account credentials as sensitive personal information, so we say it rather than deny it: the sensitive information we hold is the login to your account, your email address and your password, which our authentication provider stores only as a hash, and the SnapTrade identifiers if you connect a broker. We use them to sign you in and to read your positions, never to infer anything about you, and we never sell or share them. We do not knowingly collect anything from anyone under 18, and we do not knowingly sell or share the personal information of anyone under 16.

How to exercise these rights

Write to support@bufetico.com. For a copy of your data, a correction or a deletion, we will need to confirm that the request comes from you, normally by replying from the email address on the account. You may use an authorized agent, in which case we may still ask you to confirm the request yourself.

Opting out of advertising measurement is deliberately easier, because the law says it has to be. We do not verify who you are for it. Neither the form at bufetico.com/do-not-sell nor an email to support asks you to sign in or to create an account, and the form needs nothing but the email address you paid with. The switch in Settings works just as well, and the Global Privacy Control signal works without you asking at all.

We answer within 45 days, and may extend that once if the request is complex. Exercising any of these rights costs nothing and we will not treat you differently for it. If we refuse a request, we will explain why, and you may appeal by replying to that answer; if we deny your appeal you may contact your state Attorney General.

Tracking signals

There is one thing we now match across sites, and we would rather say it plainly than hide behind how it works: we match a click on a Facebook or Instagram ad to a payment on Bufetico. It happens on our server. There is no Meta pixel and no Meta advertising code on bufetico.com or in the app, which changes how it is done, not what it is. The box above, under “Do Not Sell or Share My Personal Information”, tells you how to switch it off, and it never happens at all unless the country on your payment is the United States.

Global Privacy Control. We honor it, and you never have to do anything else for it to count. We read the signal at the moment you start a payment, because that is the only moment it can reach us: a renewal months later is sent by our server from a Stripe confirmation, with no browser anywhere in sight. A payment always starts from your signed-in browser, so the signal always arrives with an account behind it and we record it there. That stops the payment you are making from being sent to Meta, and it stops every renewal after it. We never ask you to write to us for the signal to count: the switch, the form and the email are extra ways in, not the price of the signal. Switching it off does not undo events already sent, and section 6 says what we can and cannot do about those. Apart from this measurement, we do not disclose personal information to third parties for their own direct marketing.

9. Security

No system is perfectly secure. If a breach affects your personal data, we will tell you.

10. Cookies and local storage

Bufetico stores a session token on your device so you stay signed in, and caches part of the app so it loads quickly. It also stores two small marketing values, and we would rather name them than let you find them: bf_campana, the campaign tag telling us which ad or link you arrived through, and bf_fbc, the identifier of the ad click, which is what lets Meta match a purchase to an ad. Both are ordinary localStorage entries, not cookies. Clearing this site’s storage in your browser removes them.

We do not use advertising or third-party tracking cookies, and we added none for the measurement in section 3: it runs from our server to Meta’s, so no Meta advertising code runs in your browser. Do not read the absence of cookies as an absence of measurement, though. If the country on your payment is the United States, we do tell Meta about your payment. The two values above are the part of it that lives on your device.

We count page views through Cloudflare Web Analytics, both on this website and in the app. It sets no cookies, stores nothing on your device, and does not follow you to other sites, it tells us how many people visited a page, not who they were.

The typefaces the app is drawn in used to load from Google, which meant Google saw your IP address every time you opened Bufetico, whether or not you ever touched the Google sign-in button. They no longer do. The font files now sit on bufetico.com beside the rest of the app, so opening Bufetico contacts nobody but us. We are writing it down rather than quietly deleting the old paragraph, because if you read this policy before, it said the opposite.

11. Children

Bufetico is not intended for anyone under 18, and we do not knowingly collect data from children. We have no actual knowledge that we sell or share the personal information of anyone under 16. If we learn that an account belongs to someone under 16 we delete it, and nothing further is sent about it.

12. Changes to this policy

If we change this policy in a way that materially affects you, we will tell you by email or in the app before it takes effect. The date at the top always reflects the current version. The advertising measurement in section 3 is exactly that kind of change, so we are telling you here and by email. If you already subscribe, this matters to you too: your renewal is one of the two kinds of event, so an event about you would be sent each time you are charged, for as long as you stay subscribed. If you would rather not be measured, opt out and nothing about you will be sent. The box in section 8 says how, and it takes one line.

13. Contact

support@bufetico.com