Privacy Policy
This policy explains what personal data Bloombroke collects, why, who receives it, how long we keep it and what you can ask us to do. We follow Singapore's Personal Data Protection Act 2012 (the "PDPA").
1. Who we are
Bloombroke ("we", "us") runs bloombroke.com. We decide how your personal data is used.
Our Data Protection Officer can be reached at [email protected]. Write to this address for any question, request or complaint about your personal data.
2. The short version
- You can use the free terminal without an account, a name or an email address.
- Your watchlist, portfolio, saved wage, command history and screen layouts are stored in your own browser, not on our servers, unless you turn on Pro sync.
- We use one analytics service, DataFast, to count visits.
- Pro payments go through Stripe. We never see your full card number.
- We do not sell your personal data, and we do not send marketing messages.
3. What we collect and why
Using the free terminal
- Requests to our server. When you open a screen, your browser asks our server for data, such as the symbols on your watchlist. Our server passes the symbols to the data source and sends back the result. We use these requests only to answer them. When you open a ticker screen, your browser sends its symbol and a random number made for that browser tab. To count each tab once and to stop abuse, our server keeps a coded copy of that number and of your IP address, with the tickers opened, in memory for one hour, then only the count per ticker for 24 hours. Nothing is written to disk. Apart from this count, we do not keep a record of which symbols a person asked for.
- Your IP address. Every connection reveals your IP address. Our network provider, Cloudflare, uses it to deliver the site and block attacks. Our application does not write IP addresses to its logs. It holds an IP address in memory for up to 15 minutes to limit how often the Pro routes and the ticker counter can be called, to stop abuse and guessing of licence keys.
- Error logs. When something breaks, our server writes an error message to its logs. These messages do not contain your IP address, and we aim to delete them within 14 days.
- Your browser storage. The terminal saves some things in your browser's local storage so they are there next time: your watchlist, portfolio, saved wage, recent commands, screen layouts, your acceptance of these terms (with its version and time) and, for Pro, your licence key. This data stays on your device. We cannot see it unless you use Pro sync. You can delete it at any time by clearing this site's data in your browser.
Analytics
We use DataFast (datafa.st) to understand how many people visit and which screens they use. The DataFast script sets two first-party cookies: datafast_visitor_id, which lasts about one year, and datafast_session_id, which lasts about 30 minutes. It sends DataFast the page address, the referring page, your browser, operating system, device type, screen size, language and time zone. DataFast uses your IP address to work out your approximate location, such as your country and city. We use this only as totals and trends, and we do not use it to identify you.
Pro subscribers
If you subscribe to Pro, we also process:
- Your licence record. A one-way hash of your licence key and its last four characters (never the key in plain text), your Stripe customer ID, subscription ID and checkout session ID, your subscription status and its dates, and the time you accepted the Terms at checkout. For 24 hours after checkout we also keep an encrypted copy of your key so the success page can show it to you; after that it is deleted.
- Synced data. If you use sync, the watchlist, portfolio, ticker tape and screen layouts you choose to sync are stored on our server, linked to your licence, so they can appear on your other devices.
- Payment data. Stripe collects your name, email address, billing address and card details. Stripe tells us your email address, name, billing country, the brand and last four digits of your card and your payment history, which we use to run your subscription, send receipts and deal with problems. We do not receive your full card number.
When you contact us
If you email us, we receive your email address and whatever you write, and we use them to reply and keep a record of the conversation.
4. Purposes
We use personal data only to:
- provide the service and show you the data you ask for;
- run Pro: take payments, give access, sync your data and handle cancellations and refunds;
- keep the service secure, prevent abuse and fraud, and enforce our Terms of Use;
- understand how the service is used, in totals, so we can improve it;
- answer your messages and requests;
- meet our legal, tax and accounting duties.
5. Consent
By using Bloombroke, and by clicking ACCEPT on the first-visit notice, you consent to us collecting, using and disclosing your personal data as this policy describes. Where the PDPA lets us process data without consent, for example to meet a legal duty, we may rely on that instead.
You can withdraw your consent at any time by writing to [email protected]. We will tell you what withdrawing means for you. For example, we cannot provide Pro without your licence record and payment data, so withdrawing consent for those means ending your subscription. You can also stop analytics by blocking cookies or scripts from datafa.st in your browser; the terminal keeps working.
6. Who receives your data
We share personal data only with service providers that help us run Bloombroke, and only what each one needs:
- Stripe (payments; United States and Ireland, among other places) for Pro payments and billing.
- Cloudflare (network, security and delivery; a global network, based in the United States) for every visit.
- DataFast (analytics) for visit statistics, as described in section 3.
- Hetzner (hosting; our server is in Ashburn, Virginia, United States) for the server that runs Bloombroke and stores Pro data.
- Our email providers, if you email us.
We may also disclose personal data when the law requires it, to a regulator or court, to protect our rights or someone's safety, or to a buyer if the service is sold, in which case this policy continues to apply.
We do not sell personal data. We do not share it with advertisers or data brokers.
7. Transfers outside Singapore
Our server and several providers are outside Singapore, so your personal data is transferred to and stored in other countries, including the United States. When we transfer personal data out of Singapore, we take steps required by the PDPA so that it keeps a standard of protection comparable to the PDPA, for example through the providers' data processing terms and the safeguards they commit to.
8. How long we keep it
- IP addresses in our rate limiter: up to 15 minutes.
- Ticker counter: a coded copy of your browser tab's random number and of your IP address, with the tickers opened, for one hour; after that only the count per ticker, for 24 hours. All in memory, never on disk.
- Error logs on our server: we aim to delete them within 14 days.
- Cloudflare and DataFast keep their own records for the periods in their own policies.
- Pro licence record and synced data: deleted within 30 days after your subscription ends, or sooner if you ask. Records of payments that tax and company law require us to keep, such as invoices, are kept for as long as that law requires, normally five years, and are held mainly in Stripe.
- Emails: for as long as we need them to deal with your message, and then deleted, unless we need to keep them for a legal reason.
- Your browser storage: until you clear it. We have no control over it.
9. Your rights
You may ask us:
- for a copy of the personal data we hold about you, and how it has been used or disclosed in the past year;
- to correct personal data that is wrong or incomplete;
- to delete your Pro data before the end of the 30-day period.
Write to [email protected]. We may need to check that you are who you say you are, for example by asking you to prove you hold the licence key. We will reply within 30 days, or tell you within that time when we will reply. We may charge a reasonable fee for a copy of your data, and we will tell you the fee first. There are some cases where the PDPA lets us refuse a request, and we will explain if that happens.
10. How we protect it
We keep only what we need. Licence keys are stored as one-way hashes, connections are encrypted with HTTPS, and access to our server is restricted. No system is perfectly secure, so we cannot promise that data will never be lost or accessed without permission.
If a data breach happens, we will assess it quickly. If it is a notifiable data breach under the PDPA, we will notify the Personal Data Protection Commission within the time the law sets, and notify the people affected where the law requires it.
11. Children
Bloombroke is not for anyone under 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it.
12. Changes to this policy
We may change this policy. The version number and date at the top of this page show which version applies. If a change is significant, we will ask you to accept it on your next visit.
13. Contact
Bloombroke. Data Protection Officer: [email protected].
If you are not satisfied with our reply, you may contact Singapore's Personal Data Protection Commission.