This policy explains what personal data Bufetico collects, why we have it, and what you can do about it. It is written to be read, not skimmed past.
Bufetico is operated by JH GRANDGERARD, an individual established in the United States (“we”, “us”). We are responsible for the personal data described below.
One thing here is not only ours, so we put it at the top instead of burying it. To measure our advertising we send purchase events to Meta Platforms, Inc., and Meta then uses them inside its own advertising system, for its own purposes. We decide what is sent and when, and we answer to you for it; what Meta does afterwards is governed by Meta’s privacy policy. Sections 3, 5 and 8 explain all of it, including the limit that matters most: we only do this when the country on your payment is the United States. From every other country (Canada, Australia, the United Kingdom, the European Union, everywhere) nothing is sent at all. Section 8 tells you how to stop it, and that works wherever you live.
For any privacy matter, write to support@bufetico.com.
| Data | Why we have it |
|---|---|
| Email address | To create your account, sign you in, and contact you about the service. If the country on your payment is the United States it has one more use: at the moment you pay, we make a one-way encrypted (SHA-256) copy of it and send that to Meta, so Meta can match your purchase to the ad you came from. Meta never receives your address in the clear. If you pay from any other country, or from a payment that carries no country, nothing is sent. Sections 3, 5 and 8 explain it, and the box in section 8 says how to stop it. |
| Password | Stored only as a cryptographic hash by our authentication provider. We never see it. |
| Google or Facebook sign-in | If you use social sign-in, we receive your email address and a basic profile identifier from that provider. We never receive your password. That is data coming to us. Data also goes the other way, and it has nothing to do with this button: if the country on your payment is the United States, we send Meta a purchase event whether or not you ever touched the Facebook button. See sections 3 and 5. |
| Portfolio holdings you enter | To show your positions and their metrics |
| Profile photo (optional) | Shown only to you, inside your own account |
| Support messages | To answer you, and to keep a record of what users ask |
| A hash of your email address | To ensure the $1 first month is used once per person. See section 6. There is a second, separate hash of the same address, made for a completely different reason: the purchase event we send to Meta. Sections 3, 5, 6 and 8 cover that one. Two hashes, two purposes, and we keep them apart. |
| The country of your payment | Stripe tells us the country of the billing address on your payment. Besides tax, it does one thing: it decides whether an advertising event is sent at all. The United States, and nothing from anywhere else. If your payment carries no country, we treat it as unknown and send nothing. If it is wrong, you can ask us to correct it, see section 8. |
Broker connections are handled by SnapTrade. You authenticate in a window operated by SnapTrade, and we receive only a pair of identifiers plus your read-only positions.
| Purpose | Why we are allowed to |
|---|---|
| Providing the service you signed up for | Because it is what you are paying us for |
| Billing and subscription management | Because we have to charge you and keep the record of it |
| Security, abuse prevention, usage limits | Because the service would not survive without it |
| Service email (alerts you configured, account notices) | Because it is part of the service you signed up for |
| Marketing email | Because you said yes, and you can say no at any time |
| Push notifications | Because you turned them on, and you can turn them off at any time |
| Advertising measurement: telling Meta that a purchase or a renewal happened, so we can see which ads bring customers | Because we need to know whether our advertising works, and what leaves us is narrow, section 3 lists every field of it. It runs unless you tell us to stop, and you can tell us at any time; the box in section 8 says how, and it takes one line. We only do this for payments whose country is the United States, where these state laws allow exactly that. We do not do it anywhere else, so we are not relying on this anywhere else. |
| Loading the app’s typefaces | Because the app is drawn in them. They are served from bufetico.com itself, so opening Bufetico contacts nobody but us. Sections 5 and 10 describe it. |
We use a small number of providers to run Bufetico. Most of them receive only what they need to make the service work. Meta is the only one we send data to for advertising, and that is why it has two rows below: one for signing in, one for measurement. That second one is not needed to run Bufetico at all. It is there so we can see which ads bring customers, and it only happens when the country on your payment is the United States.
| Provider | Role | What it sees |
|---|---|---|
| Supabase | Database, authentication, file storage | Account data, portfolios, profile photo, and your IP address: your browser talks to it directly, at auth.bufetico.com, on every request the app makes |
| Signing in, only if you choose that button | That you signed in to Bufetico; it passes us your name and email address | |
| Meta (Facebook) | Signing in, only if you choose that button | That you signed in to Bufetico; it passes us your name and email address |
| Meta (Facebook) | Advertising measurement, and only when the country on your payment is the United States. It applies to everyone who pays from there, whether or not you ever used the Facebook button. From every other country, Canada and Australia included, nothing is sent. | When Stripe confirms a payment, our server sends Meta the amount, the currency, a one-way encrypted (SHA-256) copy of your email address, the identifier of the ad click that brought you if there is one, the campaign tag you arrived through if there is one, and your Stripe invoice number so that duplicates can be discarded. Meta never sees your address in the clear. Be clear-eyed about what that means, though: Meta holds its own users’ addresses and can encrypt them the same way to see which one matches. The encryption stops anyone else from reading it; it does not hide you from Meta. Meta also uses the event inside its own advertising system. |
| Render | Background jobs | Account data while processing |
| Cloudflare | Domain, hosting, email routing, visit counts | Network traffic, inbound email, pages viewed |
| Brevo | Sending email | Your email address and the message content |
| Stripe | Payments | Payment and billing details, including the country of the billing address on your payment. Stripe’s confirmation that a payment went through is what sets off the event we send to Meta, and the country Stripe reports is what decides whether that event is sent at all. |
| SnapTrade | Broker connection (optional) | Broker authorization and positions |
| Your browser’s push service (Google, Apple or Mozilla, depending on the browser) | Delivering push notifications (optional) | An anonymous delivery address for your device, and the encrypted notification |
| Financial Modeling Prep | Market data supplier | No personal data |
Most of these providers operate in the United States; some operate elsewhere, including in the European Union and Canada. That means your data crosses borders, and if you are in Australia this is the overseas disclosure that Australian Privacy Principle 8 is about. We rely on the contractual protections each provider offers, and we will send you a copy of the relevant terms if you ask. Using Bufetico is not your agreement to any of this: choosing these suppliers was our decision, and it is on us. If you would rather we did not process your data at all, write to us and delete your account, and we will remove everything except the few things listed in section 7, which we cannot take back.
| Data | Retention |
|---|---|
| Sign-ups that were never confirmed | One reminder after 24 hours, then deleted after 30 days |
| Active accounts | Kept while the account exists |
| Deleted accounts | Removed at the moment you confirm the deletion, including portfolios, positions, preferences, devices, the broker connection and the profile photo. Some things do not go with them, and each one has its own row below. |
| Support messages | Kept as a record of what users ask. Deleting your account unlinks the message from you, but your name, your email address and what you wrote stay in that record. |
| Billing records | Kept as long as accounting and tax rules require. They contain personal data, your email address, the amounts, the dates and the country of your payment, and they outlive your account, because the tax rules do not care that you left. |
| Server logs | Kept only while they are useful for security and for finding out why something broke, and never used for advertising. We are not going to name a number of days we have not measured. Our providers keep logs of their own, under their own terms and their own retention, and those are not ours to delete. |
| Request counts | Deleted automatically: a daily job removes every counter older than a week. They are only ever used to enforce usage limits and detect abuse. |
| A one-way hash of your email address, for the $1 offer | Kept permanently, including after you delete your account, so the $1 first month can only be used once per person. We cannot turn it back into your address, it never leaves us, and it is never used to contact you or for anything else. It is not the hash we send to Meta. |
| The hash of your email address that goes to Meta | We do not store it. It is built at the moment of the payment, sent, and dropped. What Meta keeps afterwards is on Meta’s side. |
| The campaign tag and the ad click identifier you arrived with | On your device until you clear this site’s storage; on your account for as long as the account exists, and deleted with it |
| Purchase and renewal events already sent to Meta | When you opt out or delete your account we stop sending, and the check runs before every event, so the next one is already covered. What has gone is on Meta’s side: we cannot reach in and delete it, and we are not going to pretend otherwise. If your payment country is not the United States, nothing was ever sent and there is nothing to undo. |
A confirmed account is never deleted for inactivity alone.
You can ask us to:
Write to support@bufetico.com. A person reads it, and we answer in writing within 30 days. If our answer does not satisfy you, you can take it further: in the United States, to your state Attorney General; in Canada, to the Office of the Privacy Commissioner; in Australia, to the Office of the Australian Information Commissioner. If you are in the European Union or the United Kingdom, you may complain to your national data protection authority.
Most of this section is about US state law. If you live somewhere else, your part is further down: there is a heading for Canada and Australia, and another for the European Union and the United Kingdom.
Bufetico is operated from Florida. Several US states give their residents specific privacy rights, including California, Colorado, Connecticut, Florida, Montana, Oregon, Texas, Utah and Virginia. If you live in one of them, you may ask us to:
Neither country is measured. In Canada your personal data is covered by PIPEDA, and in Quebec also by Law 25; in Australia, by the Privacy Act 1988 and its Australian Privacy Principles. Both would require your express permission before a purchase of yours could be sent to an advertising platform, we have not built a way to ask for it, and so we send nothing. The list of countries in our code has one entry, and it is not yours.
Everything else in this policy applies to you. You can ask for a copy of your data, ask us to correct it, and ask us to delete your account, by writing to support@bufetico.com. The opt-out above is open to you as well, if you would rather have it recorded on your account as a precaution. And if you ask us where a piece of information about you came from (the campaign tag, or the ad click identifier), we will tell you.
Not measured either. Your personal data is covered by the General Data Protection Regulation, and in the United Kingdom by the UK GDPR and the Data Protection Act 2018. Nothing about your payments is sent to Meta or to any other advertising platform: the list of countries in our code has one entry, and it is the United States.
Section 4 already answers the question these laws ask first, what we use each piece of data for, and why we are allowed to. Section 7 lists what you can ask us for. On top of that you may ask us to restrict how we use your data while a question is open, object to a particular use, and withdraw permission you gave us earlier, such as for marketing email or push notifications. Withdrawing it does not undo what we did before, and it never affects the service you are paying for.
And you can complain about us without asking us first. If you are in the European Union, to the data protection authority of the country you live in; in the United Kingdom, to the Information Commissioner’s Office. We would rather you wrote to support@bufetico.com and gave us the chance to fix it, but that is a preference, not a condition.
It leaves Europe. Bufetico has no servers of its own: the service runs on providers based in the United States, and section 5 names every one of them: Supabase for the database and sign-in, Render for the scheduled jobs, Cloudflare for the site and the app, Stripe for payment, Brevo for email, and the market-data provider. Your account, your portfolios and your settings are stored and processed there.
We are telling you this rather than burying it because it is the part people are entitled to know and almost never get told. Transfers out of the European Economic Area and the United Kingdom rely on the standard contractual clauses that these providers include in their data processing terms, which is the mechanism the law provides for exactly this situation. If you want to know what a specific provider does with the data it holds for us, section 5 links to each one’s own policy.
The third column answers one question: does any of it go to an advertising platform? Meta is the only one we send anything to, and only for payments whose country is the United States. For every other country the whole column reads no.
| Category | Examples in Bufetico | Sold or shared for advertising? |
|---|---|---|
| Identifiers | Email address, account identifier, the one-way encrypted copy of your email address, the ad click identifier, your Stripe invoice number | Yes, to Meta: the encrypted copy of your email address, the ad click identifier, and the invoice number that lets Meta discard duplicates. Never your address in the clear, and never your account identifier. |
| Commercial information | Subscription status, the holdings you record, the amount and currency of each payment | Yes, to Meta: the amount and the currency of a payment. Never your holdings, and never what you looked at in the app. |
| Internet activity | Request counts, saved filters, tutorials watched, the campaign tag you arrived with, your IP address | Yes, to Meta: the campaign tag you arrived with. Nothing else in this row, not your request counts, not your saved filters, not the tutorials you watched, and not your IP address. |
| Geolocation, country level only | The country of the billing address on your payment, as Stripe reports it | No. We use it to decide whether an event is sent at all, and the country itself is not part of what we send. |
| Visual information | Your profile photo, if you upload one | No |
| Financial information | Card details are held by Stripe and never by us. The amount and the currency of each payment we do hold, and they also appear under Commercial information above. | Yes, to Meta: the amount and the currency, and nothing else. Never card details, never a card number, never a bank account. |
| Sensitive personal information | The login to your account: your email address together with your password. And, if you connect a broker, the pair of identifiers SnapTrade gives us, which is read-only access to your positions. | No. Never, to anyone. |
We collect this for the purposes set out in section 4, which now has a row for the advertising measurement, and we keep it for the periods in section 6, which now has rows for the campaign tag, the ad click identifier, the request counts and the events already sent to Meta. California counts account credentials as sensitive personal information, so we say it rather than deny it: the sensitive information we hold is the login to your account, your email address and your password, which our authentication provider stores only as a hash, and the SnapTrade identifiers if you connect a broker. We use them to sign you in and to read your positions, never to infer anything about you, and we never sell or share them. We do not knowingly collect anything from anyone under 18, and we do not knowingly sell or share the personal information of anyone under 16.
Write to support@bufetico.com. For a copy of your data, a correction or a deletion, we will need to confirm that the request comes from you, normally by replying from the email address on the account. You may use an authorized agent, in which case we may still ask you to confirm the request yourself.
Opting out of advertising measurement is deliberately easier, because the law says it has to be. We do not verify who you are for it. Neither the form at bufetico.com/do-not-sell nor an email to support asks you to sign in or to create an account, and the form needs nothing but the email address you paid with. The switch in Settings works just as well, and the Global Privacy Control signal works without you asking at all.
We answer within 45 days, and may extend that once if the request is complex. Exercising any of these rights costs nothing and we will not treat you differently for it. If we refuse a request, we will explain why, and you may appeal by replying to that answer; if we deny your appeal you may contact your state Attorney General.
There is one thing we now match across sites, and we would rather say it plainly than hide behind how it works: we match a click on a Facebook or Instagram ad to a payment on Bufetico. It happens on our server. There is no Meta pixel and no Meta advertising code on bufetico.com or in the app, which changes how it is done, not what it is. The box above, under “Do Not Sell or Share My Personal Information”, tells you how to switch it off, and it never happens at all unless the country on your payment is the United States.
Global Privacy Control. We honor it, and you never have to do anything else for it to count. We read the signal at the moment you start a payment, because that is the only moment it can reach us: a renewal months later is sent by our server from a Stripe confirmation, with no browser anywhere in sight. A payment always starts from your signed-in browser, so the signal always arrives with an account behind it and we record it there. That stops the payment you are making from being sent to Meta, and it stops every renewal after it. We never ask you to write to us for the signal to count: the switch, the form and the email are extra ways in, not the price of the signal. Switching it off does not undo events already sent, and section 6 says what we can and cannot do about those. Apart from this measurement, we do not disclose personal information to third parties for their own direct marketing.
No system is perfectly secure. If a breach affects your personal data, we will tell you.
Bufetico stores a session token on your device so you stay signed in, and caches part of the app so it loads quickly. It also stores two small marketing values, and we would rather name them than let you find them: bf_campana, the campaign tag telling us which ad or link you arrived through, and bf_fbc, the identifier of the ad click, which is what lets Meta match a purchase to an ad. Both are ordinary localStorage entries, not cookies. Clearing this site’s storage in your browser removes them.
We do not use advertising or third-party tracking cookies, and we added none for the measurement in section 3: it runs from our server to Meta’s, so no Meta advertising code runs in your browser. Do not read the absence of cookies as an absence of measurement, though. If the country on your payment is the United States, we do tell Meta about your payment. The two values above are the part of it that lives on your device.
We count page views through Cloudflare Web Analytics, both on this website and in the app. It sets no cookies, stores nothing on your device, and does not follow you to other sites, it tells us how many people visited a page, not who they were.
The typefaces the app is drawn in used to load from Google, which meant Google saw your IP address every time you opened Bufetico, whether or not you ever touched the Google sign-in button. They no longer do. The font files now sit on bufetico.com beside the rest of the app, so opening Bufetico contacts nobody but us. We are writing it down rather than quietly deleting the old paragraph, because if you read this policy before, it said the opposite.
Bufetico is not intended for anyone under 18, and we do not knowingly collect data from children. We have no actual knowledge that we sell or share the personal information of anyone under 16. If we learn that an account belongs to someone under 16 we delete it, and nothing further is sent about it.
If we change this policy in a way that materially affects you, we will tell you by email or in the app before it takes effect. The date at the top always reflects the current version. The advertising measurement in section 3 is exactly that kind of change, so we are telling you here and by email. If you already subscribe, this matters to you too: your renewal is one of the two kinds of event, so an event about you would be sent each time you are charged, for as long as you stay subscribed. If you would rather not be measured, opt out and nothing about you will be sent. The box in section 8 says how, and it takes one line.