BestFolio — Privacy Policy
Effective Date: March 2026
Last Updated: July 17, 2026
Update notice: Section 3.4 (Campaign and Referral Attribution) and the related rows in Sections 4, 6, 7.4 and 10 were added in July 2026 and took effect on July 17, 2026, alongside the consent-gated feature rollout.
Privacy-preserving retention clarification: In July 2026 we shortened and made explicit the retention periods for message content, delivery records, feedback, and security audits; documented the limited tax-record exception; and clarified provider roles. These changes add no new processing purpose or data sharing.
1. Introduction
This Privacy Policy explains how BestFolio (“BestFolio”, “we”, “us”, or “our”) collects, uses, stores, and protects your personal data when you use the BestFolio web application (the “Service”).
We are committed to protecting your privacy and processing your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Hungarian data protection legislation.
2. Data Controller
The data controller responsible for your personal data is:
BestFolio
sole proprietorship
Budapest, Hungary
Email: [email protected]
As a small business, we do not have a designated Data Protection Officer (DPO). For all data protection inquiries, please contact us at the email address above.
3. Data We Collect
3.1 Data You Provide Directly
| Data Category | Examples | Purpose |
|---|---|---|
| Account information | Email address, name | Account creation, authentication, communication |
| Portfolio preferences | Strategy selections, allocation settings, watchlists | Service functionality, personalization |
| Communications | Support emails, feedback | Customer support, service improvement |
| Optional cancellation feedback | A standard cancellation category and an optional private note | Understanding subscription cancellations and improving the Service |
A cancellation reason is always optional and does not affect your ability to cancel. Private cancellation notes are encrypted at rest and are not sent to product analytics, email providers, Telegram, TaskTracker, or general application logs.
3.2 Data Collected Automatically
| Data Category | Examples | Purpose |
|---|---|---|
| Usage data | Pages visited, features used, session duration | Service improvement, analytics |
| Technical data | Browser type, operating system, device type | Service optimization, debugging |
| Log data | IP address, access timestamps | Security, abuse prevention |
| Cookies | Session cookies, preference cookies | See Section 10 |
3.3 Data We Do NOT Collect
We want to be clear about what we do not collect:
- Payment and financial information: All payment processing is handled by Stripe. We never receive, process, or store your credit card numbers, bank account details, or other payment information.
- Brokerage login and trading credentials: We never ask for your brokerage username or password and do not receive authority to place orders, move funds, or change account settings.
- Social Security numbers, government IDs, or similar sensitive identifiers.
- Precise geolocation data beyond what can be inferred from your IP address.
3.3.1 Exception: Optional read-only IBKR Flex connection
If you choose to connect Interactive Brokers in Settings, you provide an Activity Flex Query token and Query ID. We store the token encrypted at rest and store the Query ID with your BestFolio account. The token is a report-only credential. It cannot be used to place orders, move funds, or change your brokerage account.
When you test the connection or open Holdings vs target, BestFolio sends the token and Query ID to IBKR over HTTPS and reads the Flex report you configured. We use the report date, account base currency, NAV, and open-position data, including symbol, description, quantity, market price, currency, and value, to calculate current weights and compare them with the selected model portfolio.
BestFolio processes the Flex report on the server for that request and does not write the report, positions, or NAV to our database. The resulting holdings-versus-target comparison, including NAV and percentage weights, is cached by date in your browser's localStorage so it can be shown again without a fresh request.
You can disconnect at any time in Settings, under IBKR. Disconnecting deletes the stored Flex token and Query ID from our database. We keep the timestamp of your information-only acknowledgement as an audit record. Deleting your BestFolio account deletes the user record containing the token, Query ID, and acknowledgement. Browser cache entries remain on your device until you clear BestFolio site data in your browser. You can also revoke or replace the token in IBKR.
3.4 Campaign and Referral Attribution (effective July 17, 2026)
When you arrive at BestFolio through a link we published ourselves (for example in a Reddit post or a blog article), the link may carry campaign tags (utm_source, utm_medium, utm_campaign, utm_content) identifying the post or article it came from.
If, and only if, you accept Analytics cookies in the consent banner, we store those campaign tags together with the landing page path, the referring site's domain, and a timestamp:
- first in your browser's localStorage, where the record expires after 90 days if you do not create an account; and
- if you create an account within those 90 days, in our database linked to your account, as a first-touch and a last-touch record.
Purpose: understanding which of our own posts and articles lead to signups and subscriptions, so we know which content is worth producing. Legal basis: consent (Art. 6(1)(a)).
- The attribution record contains no IP address, no full browser user agent, and no browsing history: only the bounded campaign identifiers, landing path, referrer domain, and timestamps.
- Campaign identifiers never leave BestFolio. In particular, they are not shared with Stripe or any other payment processor.
- Withdrawing Analytics consent deletes the stored attribution record, and campaign identifiers are also removed from retained billing audit records. Deleting your account removes the record as well.
- Any remaining attribution data is deleted at the latest 780 days after capture.
4. Legal Basis for Processing
Under the GDPR, we process your personal data based on the following legal grounds:
| Legal Basis | Processing Activities |
|---|---|
| Contract performance (Art. 6(1)(b)) | Account creation, service delivery, subscription management |
| Legitimate interest (Art. 6(1)(f)) | Strictly necessary service reliability and security telemetry, fraud prevention, and debugging required to operate the Service |
| Consent (Art. 6(1)(a)) | Product analytics, marketing communications, non-essential cookies, campaign/referral attribution (Section 3.4) |
| Legal obligation (Art. 6(1)(c)) | Tax record-keeping, legal requests |
5. How We Use Your Data
- Providing the Service: Authenticating your account, displaying your strategy preferences and portfolio configurations, delivering strategy signals and analysis.
- Communication: Sending transactional emails (account confirmation, password resets, subscription changes), responding to support requests. Marketing emails are only sent with your explicit consent.
- Service improvement: With analytics consent, understanding how users interact with the Service to improve features and develop new functionality; essential reliability and debugging data remains limited to operating and securing the Service.
- Security: Detecting and preventing unauthorized access, abuse, and fraud.
- Legal compliance: Meeting tax, accounting, and regulatory obligations.
6. Data Retention
| Data Category | Retention Period |
|---|---|
| Account information | Duration of the account; locally held account data is erased when account deletion completes, subject only to the specific exceptions below |
| Portfolio preferences | Duration of account; deleted upon account deletion |
| IBKR Flex token and Query ID | Until you disconnect IBKR or delete your account; the token is encrypted at rest |
| IBKR report positions and NAV on BestFolio servers | Processed for the request only; not written to our database |
| IBKR holdings-versus-target browser cache | Dated localStorage entries remain until you or your browser clears BestFolio site data |
| IBKR information-only acknowledgement timestamp | Retained after disconnect; deleted with your BestFolio account |
| Usage and analytics data | 26 months (rolling) |
| Campaign attribution data (Section 3.4) | 780 days, or earlier upon consent withdrawal or account deletion |
| Log data (IP addresses) | 90 days |
| Outbound message identifiers, content, and diagnostic free text | 90 days, or earlier when an account-linked record is erased |
| Minimal outbound delivery record | 365 days, or earlier when an account-linked record is erased |
| In-app feedback submissions | Up to 3 years after the later of submission or resolution; account deletion erases linked free text and identifiers sooner |
| Structured cancellation category and lifecycle record | For the duration of your account; deleted with the account |
| Optional private cancellation note | 365 days or until account deletion, whichever occurs first; encrypted at rest |
| Minimal BestFolio partner payout and tax records | Through an explicit conservative deadline covering 10 full years after the normal following-year tax-return deadline; user links, names, vanity codes, and raw Stripe invoice locators are removed on account deletion |
| Payment records held independently by Stripe | Under Stripe's own legal obligations and retention notice |
| Operator access audit for protected provider references | 24 months; the revealed reference is never stored in the audit |
| Deletion-prevention token | The recoverable provider identifier is scrubbed after confirmed deletion; a one-way provider-scoped token remains while the integration is active. If an integration retires, a code-level retirement registry makes the daily retention job delete its tokens on day 90. Service shutdown includes deletion of remaining hosted data |
| Marketing consent records | Duration of consent + 3 years after withdrawal |
After 90 days, the local outbound-message record no longer contains the subject, rendered body, raw error, or free-form metadata. The limited delivery record kept until day 365 contains only the channel, message category and template, source, delivery status, and delivery/open/click timestamps; the account link, recipient, and provider message ID are removed at day 90. After linked feedback is erased, only non-identifying workflow facts such as its category, status, timestamps, and related deployment may remain.
7. Service Providers and Other Recipients
BestFolio is the controller for the processing described in this notice. A provider that handles personal data only on our documented instructions acts as our processor, under GDPR Article 28 terms. A provider that determines its own purposes and essential means acts as an independent controller for that activity. A processor's own downstream provider is its subprocessor; we do not use “subprocessor” as a blanket label for every company below.
7.1 Stripe (Payments and Billing)
- Role: service provider for configured billing functions and independent controller where Stripe processes data for its own legal, fraud-prevention, security, or tax purposes
- Purpose: Payment processing, subscription management, invoicing, tax compliance
- Data shared: Account and subscription identifiers and the checkout details Stripe requests
- Stripe independently collects payment information directly from you. BestFolio does not have access to this data.
- Privacy policy: stripe.com/privacy
7.2 Authentication (Clerk)
- Role: processor for authentication and account management
- Purpose: User authentication and account management
- Data shared: Email address, name, authentication tokens
- Privacy policy: clerk.com/legal/privacy
7.3 Transactional Email (Brevo)
- Role: processor for message delivery and related events
- Purpose: Sending transactional emails (account confirmation, password resets, monthly strategy signal updates, subscription notices)
- Data shared: Email address, name, message contents
- Privacy policy: brevo.com/legal/privacypolicy
7.4 Product Analytics (PostHog)
- Role: processor for consented product analytics
- Purpose: Aggregated and pseudonymous product usage analysis to improve the Service
- Data shared: An anonymous device identifier before sign-in; for consented signed-in events, a random BestFolio-owned pseudonymous analytics identifier; sanitized page paths, explicitly named interaction events, and country derived from IP address. New analytics event capture does not include Clerk or Stripe identifiers, email addresses, names, arbitrary page text, DOM attributes, query strings, or session replay. During the July 2026 identity transition, a restricted administrative query may use the former Clerk analytics locator solely to find, reconcile, or erase historical PostHog records created before the transition; it is never added to new event payloads.
- Legal basis: Consent. Analytics are loaded only after you accept analytics cookies in the consent banner.
- Privacy policy: posthog.com/privacy
7.5 Error Monitoring (Sentry)
- Role: processor for error monitoring
- Purpose: Application error monitoring and debugging
- Data shared: Error messages, stack traces, request and technical context, release and environment information, and for selected errors an internal BestFolio user ID
- Automatic capture of user IP addresses, request headers, and cookies is disabled. Error context may still include request data; webhook routes are excluded from tracing.
- Privacy policy: sentry.io/privacy
7.6 Proxy, CDN, and Traffic Security (Cloudflare)
- Role: processor for delivery and traffic security
- Purpose: Reverse proxy, content delivery, TLS, traffic security, and caching
- Data processed: IP address, requested URL, request headers, timestamps, network and device information, and country inferred from IP address
- Privacy policy: cloudflare.com/privacypolicy
7.7 Hosting (Hetzner)
- Role: processor for application and database hosting
- Purpose: Hosting the application, database, and service logs
- Data processed: Account, portfolio, preference, and service data, including encrypted IBKR credentials when you enable the optional connection
- Privacy policy: hetzner.com/legal/privacy-policy
7.8 Optional IBKR Flex Connection (Interactive Brokers)
- Role: connected service and independent controller for your brokerage account and its own platform processing
- Purpose: Retrieving the Flex report you authorize for a holdings-versus-target comparison
- Data sent: Your Activity Flex Query token and Query ID
- Data received: The configured report's date, account base currency, NAV, and open positions
- Access boundary: Optional and report-only; BestFolio receives no trading session and cannot place orders, move funds, or change brokerage settings
- Privacy policy: interactivebrokers.ie privacy policy
7.9 Support Mailbox (Google Workspace)
- Role: processor for BestFolio's support mailbox
- Purpose: Receiving and replying to support requests and reconciling sent replies with feedback
- Data processed: Email address, message headers, message content, and attachments you choose to send
- Privacy policy: policies.google.com/privacy
7.10 Optional Telegram Delivery
- Role: connected communications service; Telegram may act as an independent controller for its own platform, security, and account processing
- Purpose: Delivering Telegram alerts when you enable that channel
- Data sent: Telegram chat identifier and the alert content
- Privacy policy: telegram.org/privacy
Self-service account deletion removes BestFolio's local account data, cancels any active BestFolio subscription, and submits deletion of the Clerk authentication identity. It does not claim to erase records that another controller must retain for its own purposes. For a verified broader request, contact us and we will relay the request to processors where required; requests concerning an independent controller are handled under that provider's notice.
We do not sell, rent, or trade your personal data to any third party for their own purposes.
8. Your Rights Under GDPR
As a data subject, you have the following rights:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate personal data.
- Right to Erasure (Art. 17): Request deletion of your personal data, subject to certain exceptions.
- Right to Restriction of Processing (Art. 18): Request that we restrict processing in certain circumstances.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interest.
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time for consent-based processing.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority:
Nemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)
(Hungarian National Authority for Data Protection and Freedom of Information)
Address: 1055 Budapest, Falk Miksa utca 9-11.
Phone: +36 1 391 1400
Email: [email protected]
Website: naih.hu
How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days and may ask you to verify your identity.
9. International Data Transfers
BestFolio is operated from Hungary (EU). Your data is primarily stored and processed within the European Economic Area (EEA). Where a service transfers data outside the EEA, we use the safeguard that applies to that service and transfer, such as an adequacy decision or EU Standard Contractual Clauses, and assess supplementary protections where required. You may ask us for the relevant details.
10. Cookie Policy
10.1 What Are Cookies
Cookies are small text files placed on your device when you visit a website. They serve various purposes including remembering your preferences and understanding how you use the Service.
10.2 Cookies We Use
| Cookie Type | Purpose | Legal Basis | Duration |
|---|---|---|---|
| Strictly necessary | Authentication, session management, security | Legitimate interest | Session or up to 30 days |
| Functional | User preferences (theme, display settings) | Legitimate interest | Up to 1 year |
| Analytics | Understanding usage patterns | Consent | Up to 26 months |
We also use browser localStorage (a technology similar to cookies) for the campaign attribution described in Section 3.4. It is written only after you accept Analytics cookies, expires after 90 days if you do not create an account, and is removed when you withdraw consent.
10.3 Managing Cookies
You can control and manage cookies through your browser settings. On your first visit, we will present a cookie consent banner allowing you to accept or decline non-essential cookies.
11. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including encryption of data in transit (TLS/HTTPS), access controls, and regular security reviews. While we take reasonable precautions, no method of electronic transmission or storage is 100% secure.
12. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children under 18. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected].
13. Automated Decision-Making
BestFolio does not engage in automated decision-making or profiling that produces legal effects concerning you. Strategy signals and portfolio analysis are informational outputs, not decisions made about you.
14. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you may have additional rights including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale or sharing of your personal information. We do not sell or share your personal information as defined by the CCPA/CPRA.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date and state when the change takes effect. We will provide advance notice when applicable law requires it or when the notice for a particular change says we will; otherwise, the change takes effect on the date shown in this policy.
16. Contact Us
If you have questions about this Privacy Policy, please contact us:
BestFolio
Email: [email protected]
Budapest, Hungary
For payment-related privacy inquiries, please refer to Stripe's privacy policy.