Your privacy matters. This policy explains what data we collect, why we collect it, and how we protect it. We comply with the Indian Information Technology Act, 2000 and applicable data protection rules.
1. Data We Collect
| Data Type | What We Collect | Why |
|---|---|---|
| Account Data | Name, email address, phone number | Account creation & authentication |
| Financial Data | Broker account identifier (via Smallcase) | Portfolio tracking & trade execution |
| Usage Data | Pages visited, features used, session duration | Platform improvement |
| Device Data | Browser type, IP address, device identifiers | Security & fraud prevention |
| Payment Data | Payment confirmation (no card details stored) | Subscription management |
We do not collect or store your Demat password, broker credentials, or UPI PIN. These remain entirely within your broker's systems.
2. How We Use Your Data
- Providing and improving our investment recommendation service
- Processing subscription payments and sending invoices
- Sending research updates, rebalancing alerts, and service communications
- Complying with SEBI record-keeping requirements for registered investment advisers
- Detecting and preventing fraud or unauthorized access
3. Third-Party Sharing
We share your data only as necessary to provide our service:
- Smallcase Technologies: To enable basket transactions and portfolio tracking via the Smallcase Gateway
- Your Broker: Trade instructions are routed through your chosen broker via Smallcase
- Supabase (Database): Secure cloud database and authentication infrastructure
- Payment Processors: For subscription billing (no card data is stored on our servers)
We do not sell your personal data to third parties. We do not share your data for advertising purposes.
4. Cookies and Tracking
We use essential cookies to maintain your login session and platform preferences. We do not use third-party advertising cookies. We may use analytics cookies (such as privacy-respecting analytics) to understand how users interact with the platform. You can disable non-essential cookies in your browser settings.
5. Data Retention
We retain your account data for as long as your account is active. After account deletion, we retain certain records for up to 5 years to comply with SEBI record-keeping requirements for registered investment advisers under the SEBI (Investment Advisers) Regulations, 2013.
6. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Update inaccurate or incomplete data via your profile
- Deletion: Request deletion of your account and data (subject to legal retention obligations)
- Portability: Receive your data in a machine-readable format
- Objection: Object to processing for marketing communications
To exercise these rights, email privacy@equitywallet.in.
7. Data Security
We implement industry-standard security measures including TLS encryption for data in transit, encrypted database storage, and regular security audits. Authentication is handled via Supabase with enterprise-grade security. However, no system is 100% secure — please use a strong, unique password and enable any available 2FA options.
8. Children's Privacy
Our service is not directed at individuals under 18 years of age. We do not knowingly collect data from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately.
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or a prominent notice on the platform. Continued use of EquityWallet after changes constitutes acceptance of the updated policy.
10. Contact Us
For privacy-related queries, contact our Data Protection Officer at privacy@equitywallet.in.