Privacy Policy
1. Introduction
This Privacy Policy ("Policy") sets forth how No More Monday Inc. ("We," "Us," or "Our") handles user information in operating the "Investical" service ("Service").
The Service is built on a Privacy by Design principle, prioritizing privacy protection above all. We do not collect unnecessary personal information from users as a foundational design choice.
2. Information We Collect
We collect only the minimum information necessary to provide the Service.
2.1 Information Collected via Google Account
When users log in via Google account, we collect only:
- OAuth Subject Identifier (OAuth
sub): An irreversible identifier issued by Google - Calendar Write Permission: Permission to manage only events created by our app (
calendar.app.createdscope)
2.2 Information Voluntarily Provided
- Display name: For dashboard display (optional, may be left blank)
- Watchlist symbols: For investment calendar features
- Settings: Notification times, primary brokerage, etc.
2.3 Automatically Collected Information
- IP address hash: For unauthorized access detection (auto-deleted within 30 days; see §7)
- User agent hash: Same as above
- Usage logs: Service access history (retention follows infrastructure-provider defaults; see §7)
The hashed IP addresses and user agents above are processed through an irreversible hash function, but the possibility of identifying an individual through correlation with our other data cannot be entirely excluded. Accordingly, we treat them as pseudonymous data (within the meaning of GDPR Art. 4(5)) and apply protections equivalent to those for personal data.
2.4 Information at Payment (via Stripe)
When users purchase a paid plan:
- We use Stripe (Stripe, Inc.) as the payment processor
- Payment information (credit card details, email addresses) is collected and stored directly by Stripe
- We retain only the Stripe Customer ID and do not hold users' card information or email addresses
3. Information We Don't Store on Our Systems
We do not store the following on our own systems (our DB) — payment-related items are collected and held by Stripe per §2.4, and we retain only the Stripe Customer ID:
- Email addresses (except those entered to Stripe at payment)
- Passwords (unnecessary due to OAuth)
- Names (except optional display names)
- Addresses
- Phone numbers
- Date of birth
- Other Google Calendar events (we access only events we create)
- Gmail, Google Drive, or other Google services data
4. Purpose of Use
Collected information is used solely for:
- Providing the Service (investment calendar delivery, briefings, etc.)
- Improving the Service
- Detecting unauthorized access via usage logs
- Compliance with applicable laws
- Payment processing via Stripe Customer ID
- Understanding service usage and improvement (using privacy-preserving analytics tools, see §6 of this Policy)
- Service communications, including announcements about the Service, new features, and information about our paid plans (delivered within the Service interface and by writing to the Investical sub-calendar). These are first-party communications from us (Investical) and are distinct from third-party advertising. See §6.3.
We do not use collected information for purposes other than the above. Because we do not retain users' email addresses, we do not send marketing emails; any announcements or notices from us are delivered solely within the Service interface and through the Investical sub-calendar (see §6.3).
5. Third-Party Sharing
We do not share collected information with third parties except:
- With user consent
- As required by law
- With Stripe (Stripe, Inc.) for payment processing
- To protect life, body, or property of any person
- In the event of merger, corporate division, business transfer, or other business succession (the successor will handle the collected information within the purposes and retention periods set forth in this Privacy Policy. Material changes after succession will be announced in advance via the status page set forth in §8)
We outsource certain operations of the Service to the following entities. Such outsourcing is not deemed third-party sharing pursuant to Article 27, Paragraph 5, Item 1 of the Japanese Personal Information Protection Act. We require these contractors to implement appropriate security measures and bind them with contractual confidentiality obligations:
- Cloudflare, Inc. (USA): Service infrastructure (Workers / D1 / KV), CDN, DDoS protection, server-side analytics (Cloudflare Web Analytics / Workers Analytics)
- Stripe, Inc. (USA): Payment processing, billing record management
- Functional Software, Inc. (Sentry) (USA): Error tracking (PII filtering enabled, only hashed user_id transmitted)
- Google LLC (USA): OAuth authentication, Google Calendar API (within the consented
calendar.app.createdscope)
These contractors are foreign third parties. We have taken the required measures regarding cross-border data transfer pursuant to Article 28 of the Japanese Personal Information Protection Act, and details are available upon request via the contact channels in §12.
5.1 No Sale or Sharing of Personal Information
We do not engage in any of the following:
- Sale of personal information to third parties (whether for monetary or other valuable consideration)
- Sharing personal information with third parties for cross-context behavioral advertising
- Provision of personal information to third-party advertising networks
This commitment applies to "sale" and "sharing" as defined under the California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA), and to equivalent concepts under other US state privacy laws (including the Colorado Privacy Act, Connecticut Data Privacy Act, and Texas TDPSA).
6. Analytics and Tracking Technologies
We use privacy-preserving analytics tools to improve service quality and user experience. We do not engage in cookie-based behavioral tracking, third-party advertising network tracking, or session recording.
The analytics tools we use are limited to the following categories:
| Category | Data Collected | Personal Identifiability |
|---|---|---|
| Server-side web analytics (cookieless) | Page views / referrers / device types (aggregated) | None (aggregate counts only, not tied to individual users) |
| Server-side API metrics | API request counts / processing time / error rates (aggregated) | None (aggregate counts only, not tied to individual users) |
| Event tracking (planned) | Frequency of key actions (via hashed user_id) | Low (treated as pseudonymous data per GDPR Art. 4(5)) |
| Error tracking | Exception stack traces, PII filtering enabled | Limited (hashed user_id only, treated as pseudonymous data) |
Specific vendors are disclosed in §9.3 (Subcontractors). When we change vendors, we will amend this Policy in advance and announce per §13.
Tools we explicitly do not use (anti-claim transparency):
- Google Analytics (including GA4) or similar cookie-based analytics
- Hotjar or similar session recording tools
- Facebook Pixel or similar third-party advertising trackers
- Cookie-based fingerprinting
6.0 Global Privacy Control (GPC) Signal
We honor the Global Privacy Control (GPC) signal. When an HTTP request includes the Sec-GPC: 1 header, We treat that user as having opted out of any optional analytics processing. In practice, this means We do not attach user identifiers to error-tracking events and similar telemetry.
That said, the Service does not use cookie-based tracking and only collects server-side aggregate data. As a result, We do not perform individually identifying analytics regardless of whether the GPC signal is present.
GPC is recognized as a legally valid opt-out signal under multiple US state privacy laws, including the California Consumer Privacy Act (CCPA), Colorado Privacy Act (CPA), and Connecticut Data Privacy Act (CTDPA).
6.1 Advertising Principles
We adhere to the following principles across the entire Service:
(1) No use of user personal information for ad targeting
User content obtained through OAuth integration (watchlist, settings, Calendar write history, support inquiry content, etc.) will not be provided to third-party advertising networks or used for ad targeting.
(2) No tracking technologies
- Cross-site retargeting and behavioral targeting (e.g., Facebook Pixel, Google Ads conversion tracking) will not be used
- Cookie-based fingerprinting for user identification will not be used
(3) Constraints when advertising is displayed
If advertising is displayed on any part of the Service, we will use page content–based Non-Personalized Ads (NPA) mode and will not use a user's individual browsing history or data obtained through OAuth integration for ad selection. When adding or modifying ad-displaying areas, we will amend this Policy in advance and announce per §13.
6.2 Functional Cookie Usage
When a user explicitly switches the site language via the language toggle, we set a same-domain functional cookie to persist their preference. This cookie qualifies as a strictly necessary / functional cookie under the ePrivacy Directive and equivalent regulations, and may be set without prior consent.
| Item | Detail |
|---|---|
| Cookie name | lang |
| Value | ja or en only (two possible values) |
| Lifetime | 1 year (Max-Age=31536000) |
| Attributes | Path=/, SameSite=Lax, Secure, HttpOnly |
| Set when | Only when the user explicitly clicks the language toggle |
| Purpose | Show the same language version on the next visit (initial visits use the Accept-Language header) |
Properties of this cookie:
- Two values only (
ja/en): the cookie alone cannot be used to identify users (technically impossible) - Same-domain only: read and written only within
investic.al, never transmitted to third parties - No behavioral tracking: page views, interaction history, dwell time, etc. are not recorded
- Freely removable: users may delete it anytime via browser settings without affecting service availability (the next visit falls back to Accept-Language detection)
If we add or change analytics tools in the future, we will announce in advance via the status page pursuant to §13. Any new tool will be required to operate without cookies, with IP anonymization, and in compliance with EU privacy regulations.
6.3 First-Party Service Communications
In connection with providing the Service, we may send the following first-party communications from us through the Service interface (e.g., the dashboard) and by writing to the Investical sub-calendar that we create (under the calendar.app.created scope; see §2.1):
- Announcements and important notices about the Service
- Information about new features and changes to the Service
- Information about our paid plans, including trials, discounts, and similar promotional offers
These are first-party communications from us (Investical) and are different in nature from the third-party advertising (e.g., Google AdSense) described in §6.1 and §16. With respect to these communications, we adhere to the following:
- No provision or sharing with third parties: User content obtained through OAuth integration (watchlist, settings, etc.) is used only to deliver these first-party communications within the Service, and is never provided to third-party advertising networks or used for third-party ad targeting (we maintain the principles of §6.1).
- Restrained frequency: We operate these communications in a restrained manner to avoid excessive frequency.
- User control: Users may stop receiving these communications by (i) deleting the relevant calendar events ("Wipe Investical Sub-Calendar" in
/dashboard/settings; see §9.3), (ii) unsubscribing from or deleting the Investical sub-calendar, or (iii) revoking the OAuth integration (see §9.4).
Note that the emergency notifications for significant incidents set forth in §8.1 are a separate category of notice; routine operational information and promotional information (such as maintenance, feature changes, policy amendments, and the communications described above) are not included in those emergency notifications (we maintain the limitation in §8.1).
7. Retention Period
Retention is set per medium and purpose, as follows.
| Information | Retention | Medium / Auto-deletion mechanism |
|---|---|---|
OAuth sub and usage data (watchlist / settings, etc.) |
Duration of account | Our live DB |
| Session IP/UA hashes (for unauthorized access detection) | Up to 30 days (after session expiry, deleted by daily cron) | Our live DB (HMAC-SHA256 hashed) |
| Access / error logs (including hashed user_id) | Infrastructure-provider defaults (~7 days; error tracking service: ~30 days) | Auto-deletion managed by each infrastructure provider |
| Billing history | Statutory period (7 years) | Stripe (We retain only the Customer ID) |
| OAuth Refresh Token | Duration of account | Our live DB (AES-256-GCM encrypted) |
| After account deletion (live DB) | Promptly physically deleted (see §9.5) | Our live DB |
| After account deletion (infrastructure provider's point-in-time history) | Up to 30 days (automatic GC; see §9.5) | Infrastructure provider |
Note that infrastructure-provider auto-deletion periods may vary depending on plan / configuration. If extended retention is required (e.g., for compliance), we will switch to external storage via mechanisms such as Logpush (in which case we will amend this Policy with advance notice).
8. Breach Notification
8.1 Notification Method
The Service prioritizes privacy protection by not storing users' email addresses on our systems (except those collected by Stripe at payment, which we do not hold or use for notifications). Consequently, in the event of a data breach or other significant incident, individual email notification to users may not be possible.
In such cases, pursuant to the alternative measures permitted under Article 26(2) proviso of the Japanese Personal Information Protection Act and Article 7 of its Enforcement Regulations, we will provide notice through public announcement using the following methods:
- Service status page (
status.investic.al) - Service website (
investic.al) - Official SNS account (X / Twitter)
- Press release for serious incidents
- Emergency event posting to active users' Investical calendars (limited to significant incidents involving personal information leakage etc.; routine operational notices such as maintenance, feature changes, and policy amendments are NOT covered). Users may disable calendar writes from the "Incident Notifications" section in
/dashboard/settings(enabled by default).
8.2 User Recommendations
Due to communication channel limitations, we recommend:
- Periodic checking of the status page
- Following our official SNS (recommended)
- Regular login to the Service
These limitations stem from the Service's privacy-first design. Please understand the trade-off of limited communication channels in exchange for minimal personal information retention.
9. User Rights
Users may exercise the following rights against us. Identity verification is, in principle, performed via Google OAuth authentication. Due to our email-free design, users who lose access to their Google account face a structural inability to exercise these rights, as detailed in §11.
9.1 Identity Verification
The Service adopts an email-free design and does not retain users' email addresses, names, or addresses on our own systems for identity verification purposes (payment data is held by Stripe per §2.4). Therefore, identity verification for user rights requests is limited to:
| Scenario | Identity Verification Method | Limitation |
|---|---|---|
During an OAuth session (logged into /dashboard) |
Available: Submit via the support form at /dashboard/support (identity is verified at the moment of submission) |
None (standard case, recommended channel) |
| OAuth re-authentication possible (Google account retained, logged out, etc.) | Available: Email to support@investic.al → user identified by Google OAuth re-authentication |
Depends on re-authentication ability |
| After Google account loss | Unavailable: Identity verification impossible (structural limitation of email-free design) | Pursuant to Article 32, Paragraph 2 of the Japanese APPI, we are not obligated to respond to requests where identity cannot be verified |
| During account suspension (Investical-side lockout) | Conditional: Individual handling via support, with Google-side account retention confirmation | Emergency response only, SLA undefined |
Compliance basis (Article 32, Paragraph 2 of the Japanese Personal Information Protection Act): Where identity cannot be verified for a rights request, we are not legally obligated to respond. This structurally prevents information disclosure via impersonation requests, and the importance of users continuing to retain access to their Google account is emphasized in §11.
9.2 Right to Disclosure (Article 33 of the Japanese APPI)
Users may request disclosure of their personal information.
| Item | Content |
|---|---|
| Method | (1) After signing in, submit via /dashboard/support with subject "Disclosure request" (recommended channel), or (2) email to support@investic.al (identity verified by OAuth re-authentication upon receipt) |
| Identity Verification | OAuth authentication at form submission / Google OAuth re-authentication for email |
| Response Time | Within 30 days |
| Disclosure Scope | All data we hold pertaining to the requesting user (including hashed IP/UA logs, but excluding information of other users or third parties, and information required for our security (e.g., encrypted OAuth tokens; per Article 33, Paragraph 2, Item 3 of the Japanese APPI)) |
9.3 Right to Correction / Deletion (Article 34 / 35 of the Japanese APPI)
Users may request correction or deletion of their personal information.
About correction requests: Due to our email-free design, the Service does not retain "typically correctable" personal information such as users' names, addresses, or phone numbers. The items users can correct are limited to the following, all of which are self-service via the dashboard or Stripe:
- Display name: self-edit via
/dashboard/settings(optional field) - Watchlist symbols: self-edit via
/dashboard/watchlist - Macro indicator subscriptions: self-edit via
/dashboard/macro - Payment-related information (card number, payment email, etc.): self-edit via Stripe Customer Portal (we retain only the Stripe Customer ID)
System-generated data (OAuth Subject Identifier (sub) / Stripe Customer ID / timestamps / hashed IP/UA logs, etc.) is automatically assigned by our system and not subject to correction. If you find an error, please contact us via §12 (individually handled).
About deletion requests:
| Item | Content |
|---|---|
| Method | (1) Dashboard /dashboard/settings "Wipe Investical Sub-Calendar" feature (immediate; targets only Calendar events created by the Service), (2) /dashboard/settings Danger Zone "Permanently delete account" (immediate physical deletion, see §9.5), (3) Submit via /dashboard/support with subject "Deletion request" (recommended channel), or (4) email to support@investic.al (identity verified by OAuth re-authentication upon receipt) |
| Identity Verification | Form / Danger Zone: OAuth authentication / Email: Google OAuth re-authentication |
| Response Time | Immediate (Danger Zone), or within 30 days (form / email) |
9.4 Right to Suspend Use
Users may request suspension of Service use.
| Item | Content |
|---|---|
| Cancellation of paid plan | Access Stripe Customer Portal from the dashboard (when logged in) or from the /billing page on our website (no login required) — self-service at any time |
| Full account deletion | Submit via /dashboard/support with subject "Deletion request" (recommended channel), or email to support@investic.al (identity verified by OAuth re-authentication upon receipt) |
| Revocation of OAuth integration | We will soft-delete the OAuth refresh_token upon account deletion request, or users may revoke access themselves via Google account settings (myaccount.google.com/permissions) |
9.5 Treatment Upon Account Deletion
For direct deletion requests submitted from the dashboard, We may require re-authentication with Google immediately before execution as an additional security measure (to prevent unintended deletion from unauthorized access or operational errors).
Upon receiving an account deletion request, we promptly perform the following (the user loses access to the Service at the moment of execution):
- Delete the Investical sub-calendar from Google Calendar
- Revoke OAuth integration (physically delete
refresh_token/access_token/id_token) - Physically delete all records pertaining to the requesting user from the live database (
user/account/watchlist/event_writes/user_macro_subscriptions/subscriptions/support_requests/sessiontables)
Simultaneously with the physical deletion from the live database, the user loses access to the Service. Note that our cloud database infrastructure retains up to 30 days of point-in-time history for disaster recovery (a standard feature of the infrastructure provider; see §9.3). This is a backup mechanism managed by the infrastructure provider, and we cannot selectively exclude individual user data from it. We do not operationally reference this history; after 30 days, the infrastructure provider's automatic garbage collection completes the removal.
Complete removal timeline:
- 0 seconds: Access to the Service is suspended, and live database records are physically deleted
- 0-30 days: Point-in-time history remains in the infrastructure provider's backup mechanism (not referenced in our operations)
- After 30 days: Automatic garbage collection by the infrastructure provider completes the removal
Statutory retention exceptions:
- Billing history is retained for 7 years under the Companies Act / Specified Commercial Transactions Act (retained by Stripe; Investical itself retains only the Stripe Customer ID)
- Our access / error logs (including hashed IP/UA) are retained per the per-medium retention periods in §7 (up to 30 days) and then automatically deleted
9.6 Third-Party Requests
To prevent intentional impersonation, we will not respond to any request that does not satisfy at least one of the following:
- Request authenticated via OAuth / re-authenticated by the Google account linked to the relevant Investical account
- Formal lawful demands from public authorities (police, prosecutors, courts, tax authorities, etc.): We cooperate to the fullest extent of the data we hold in response to formal lawful demands. However, due to our email-free design (§3) and OAuth-only identification (§9.1), we cannot provide data we do not hold (such as the user's email address, name, address, or phone number). The scope of data we can produce in response to a request is described in §7 (Retention Period). To expedite identification, where possible, please also provide the user's Google OAuth Subject Identifier (
sub, obtainable directly from Google) or access information with a timestamp range, which will accelerate user identification. - Requests from heirs / agents accompanied by official documents proving the user's death or guardianship status (handled individually after legal review, subject to the same technical limits as the preceding item)
Other third-party requests (claims by family members or acquaintances) will not be honored due to insufficient identity verification means.
10. Security
We protect collected information through:
- Transport Encryption: TLS 1.3 for all communications
- At-Rest Encryption: Sensitive data including authentication tokens are stored encrypted using industry-standard encryption (e.g., AES-256-GCM), with keys managed via cloud infrastructure secret management services
- Access Control: All requests to the Service are routed through an edge network (man-in-the-middle protection / DDoS mitigation / bot detection)
- Monitoring and Logging: Error tracking and performance monitoring are performed. PII is filtered before transmission, and user_id is hashed (specific vendors disclosed in §9.3)
- Two-Factor Authentication for Administrator Accounts: TOTP (time-based one-time password) two-factor authentication is enabled on administrator accounts of external services we use for operations
11. Account Recovery (Important — Structural Limitation of Email-Free Design)
The Service uses Google OAuth for authentication. If users lose access to their Google account, the Service account cannot be recovered. This is a design trade-off resulting from our practice of not retaining email addresses.
11.1 Scope of Impact
Upon Google account loss, users permanently lose:
- Access to the Service account (cannot re-login)
- User data including watchlist / economic indicator subscriptions / report calendar (daily Calendar delivery) history
- The ability to exercise personal information rights set forth in §9 (we cannot respond to disclosure / correction / deletion requests due to inability to verify identity)
- For active paid plan subscribers, separate contact to
support@investic.almay allow case-by-case subscription cancellation or refund handling on the Stripe side (cases where OAuth re-authentication is unnecessary, identity verified by checking receipt information or card details)
11.2 Risk Mitigation
Users are strongly encouraged to:
- Complete Google account recovery setup (recovery phone number / backup address / recovery codes)
- Enable two-factor authentication on the Google account
- For important data, consider local backups / alternative calendar synchronization via Google Calendar app, etc.
12. Contact
For inquiries regarding this Policy:
- Service contact form:
https://investic.al/support - Email:
support@investic.al(any email address may be used to send) - Personal Information Protection Manager:
privacy@investic.al(rights requests under §33–35 of the Japanese APPI may also be sent here)
13. Policy Amendments
We may amend this Policy as necessary. For significant amendments:
- Notification to active users via Investical calendar
- Public announcement on status page and official SNS
- 30-day parallel display of old policy after amendment
14. Governing Law and Jurisdiction
This Policy is governed by Japanese law. Disputes regarding the Service are subject to the exclusive jurisdiction of the Tokyo District Court.
15. EU / UK Markets (Out of Scope)
This Service is designed and operated for users residing in Japan and does not target EU / UK data subjects within the meaning of GDPR Article 3(2)(a).
Specifically, we do not engage in activities that constitute "offering of goods or services to data subjects in the Union":
- We do not advertise or market the Service in EU / UK markets
- We do not provide customer support in EU-specific languages
- We do not accept payments in EUR or other EU Member State currencies
- We do not have operations, deliveries, or local presence in the EU / UK
While our design principles align with GDPR's foundational concepts (data minimization, privacy by design, purpose limitation, etc.) as documented below, this Policy does not constitute an admission that GDPR applies to our processing activities. Should we expand to EU / UK markets in the future, we will (a) implement full GDPR / UK-GDPR compliance, (b) amend this Policy in advance, and (c) announce per §13.
The following subsections describe our design-level alignment with GDPR principles for transparency, not as a representation of legal compliance under GDPR.
15.1 Lawful Basis for Processing (Article 6)
- Contract (Art. 6(1)(b)): OAuth
sub, watchlist, settings, and subscription data are processed based on the user's contract for service provision. - Consent (Art. 6(1)(a)): Calendar write permission via the OAuth scope
calendar.app.createdis processed based on explicit user consent obtained at the OAuth consent screen. - Legitimate Interest (Art. 6(1)(f)): Hashed IP/UA logs are processed for fraud detection and abuse prevention based on legitimate interest, balanced against user privacy by hashing and 90-day retention.
15.2 Data Subject Rights Mapping
We provide the following means to exercise GDPR data subject rights, primarily through the OAuth-authenticated support form at /dashboard/support or via email to support@investic.al. Identity verification follows §9.1 of this Policy:
| GDPR Article | Right | How to Exercise |
|---|---|---|
| 15 | Right of Access | Submit "disclosure_request" via /dashboard/support or email |
| 16 | Right to Rectification | Submit "correction_request" via /dashboard/support or email |
| 17 | Right to Erasure (Right to Be Forgotten) | Submit "deletion_request" via /dashboard/support or email |
| 18 | Right to Restriction of Processing | Submit "use_suspension" via /dashboard/support or email |
| 20 | Right to Data Portability | Currently fulfilled via email request (we provide data in machine-readable JSON format). A self-service export feature is planned. |
| 21 | Right to Object | Submit "other" via /dashboard/support or email with details |
| 22 | Right not to be Subject to Automated Decision-Making | Not Applicable. We do not perform automated decision-making or profiling within the meaning of Article 22. |
15.3 International Data Transfers
We outsource certain operations to vendors located in the United States (Cloudflare, Stripe, Sentry, Google; see §5). Transfers to these vendors are governed by their respective data processing terms, which include Standard Contractual Clauses (SCC) where applicable. For details on each vendor's compliance posture, please refer to their respective Trust Centers and Data Processing Agreements.
15.4 EU/UK Representative
As the Service does not currently target EU/UK data subjects within the meaning of Article 3(2) of the GDPR, we have not designated an EU/UK representative under Article 27. Should we expand to EU/UK markets, an EU/UK representative will be designated and disclosed in this Policy.
15.5 Cookies and Similar Technologies
We do not use cookies for tracking, advertising, or analytics. Strictly necessary authentication cookies are used for session management and are exempt from consent requirements under the ePrivacy Directive (and equivalent UK regulations). We also do not use device fingerprinting, browser fingerprinting, or other tracking techniques.
15.6 Data Protection Officer (DPO)
Designation of a Data Protection Officer is not currently required under GDPR Article 37 (we do not engage in large-scale processing of special categories of data, nor large-scale systematic monitoring of public areas). Our designated Personal Information Protection Manager (§12, reachable at privacy@investic.al) serves as the primary point of contact for privacy matters.
15.7 Supervisory Authority
EU/UK data subjects have the right to lodge a complaint with their respective national supervisory authority. As the Service does not currently target EU/UK markets, complaints regarding our processing are addressed by contacting us at privacy@investic.al. Should we expand to EU/UK markets, the relevant supervisory authority's contact information will be added to this Policy.
16. Advertising and External Transmission
On the public media area of the Service (/stocks/*, /sectors/*, /macro/*, and other login-free pages), we display advertisements through Google AdSense. In displaying advertisements, Google and partner advertising vendors may use cookies and similar technologies to deliver relevant ads based on the user's visits to this and other websites.
This section also serves as the public disclosure required by the "External Transmission Regulation" of the Telecommunications Business Act of Japan (revised in Reiwa 4 [2022], effective June 2023). See §16.6.
16.1 Default Setting (Non-Personalized Ads)
To respect user privacy, we have selected "Non-Personalized Ads (NPA)" as the initial default. NPA mode does not use the user's browsing history or attribute data for ad delivery.
16.2 Switch to Personalized Ads (Explicit Consent)
Personalized ads are delivered by Google only if the user explicitly consents through the CMP (Consent Management Platform) banner. Consent can be withdrawn at any time from the CMP banner or the settings page.
16.3 Respect for DNT (Do Not Track) / GPC (Global Privacy Control)
For users whose browsers send a DNT or GPC signal, we do not load the advertising widget at all (the ad scripts themselves are blocked). This is an extension of the practice established in §6.
16.4 Opt-Out Paths
- Google Personalized Ads (all sites): adssettings.google.com
- This Service only: Select "Do not consent" on the CMP banner
- All ads hidden: Enable DNT (Do Not Track) or GPC (Global Privacy Control) in your browser
16.5 Information Transmitted to Google and International Transfers
When ads are displayed, the following information is transmitted to Google:
- IP address
- User-Agent
- Referrer URL
- Cookie identifier (only when explicit consent is provided)
- Page content keywords
User identifiers we hold (OAuth sub, display name, watchlist, etc.) are not transmitted.
In connection with ad delivery, the above data may be transferred to servers operated by Google LLC or its affiliates located in the United States (California, etc.). For an overview of personal information protection systems in the destination country and the measures Google takes, please refer to Google's Privacy Policy and the CMP details page designated by us.
16.6 Public Disclosure under the External Transmission Regulation (Telecommunications Business Act)
In accordance with the External Transmission Regulation under the Telecommunications Business Act of Japan (revised Reiwa 4 [2022], effective June 2023), regarding the transmission of information to third parties via the user's terminal, we disclose the following:
| Item | Content |
|---|---|
| Information transmitted about the user | Cookie identifier (only with explicit consent), IP address, User-Agent, referrer URL, page content keywords |
| Entity handling the information | Google LLC (Mountain View, California, USA) |
| Purpose of use | Ad delivery and effectiveness measurement |
| Opt-out methods | See §16.4. Google Personalized Ads settings (adssettings.google.com), our CMP banner, and enabling DNT / GPC in the browser |
16.7 Provision of Personal Related Information (APPI Article 31)
Because we do not transmit user identifiers (OAuth sub, display name, etc.) to Google, this does not constitute "third-party provision of personal data" (APPI Article 27) on our side. On the other hand, when Google converts cookies into personal data on their side, the rules on third-party provision of personal-related information (APPI Article 31) apply. We address this through the explicit consent flow via CMP described in §16.2.
16.8 Detailed Operating Policy
Operating policies not covered in this section (category blocklist, placement principles, compliance with stealth-marketing regulations, consideration for third-party IR sites, etc.) are set forth in our separately defined Advertising Policy.
17. Effective Date
Effective from June 5, 2026.
Last updated: 2026-06-05