Privacy Policy
Last Updated: April 21, 2026 | Compliance Standard: Singapore PDPA 2012 (as amended)
1. DATA WE COLLECT
When you use the SGX Omni-Matrix Platform, we may collect the following categories of personal data:
- Authentication Data: Email address and Firebase Authentication UID provided through Google Sign-In. We do not collect or store your Google account password.
- Subscription Data: Payment transaction records processed securely by Stripe. We do NOT host, process, or store your credit card numbers, CVV, or banking details. We only retain an encrypted reference linking your email to your subscription tier.
- Usage Analytics: Anonymous, aggregated platform usage metrics including page views, feature interactions, stock tickers searched, and session durations. This data contains no personal identifiers.
- Local Storage: Your watchlist preferences, language settings, EULA acknowledgment status, and usage counters are stored locally on your device via browser localStorage. This data never leaves your device.
2. HOW WE USE YOUR DATA
Your personal data is used strictly for the following purposes:
- Service Delivery: To authenticate your identity, manage your subscription tier, and deliver tier-appropriate analysis features.
- Platform Improvement: Anonymous analytics help us improve the user experience, optimize AI model performance, and identify technical issues.
- Billing Administration: To process subscription payments, manage billing cycles, and prevent fraudulent transactions (via Stripe).
- Legal Compliance: To comply with applicable laws, regulations, or valid legal processes.
3. DATA WE DO NOT COLLECT
We want to be explicit about what we do NOT collect:
- We do NOT collect, access, or store your brokerage account credentials or trading passwords.
- We do NOT execute, place, or modify any trades on your behalf through any brokerage platform.
- We do NOT collect your physical location, GPS coordinates, or device hardware identifiers.
- We do NOT sell, rent, or trade your personal data to any third parties for marketing purposes.
4. THIRD-PARTY SERVICES
The Platform integrates with the following third-party service providers, each governed by their own privacy policies:
- Google Firebase: Authentication and user identity management. Firebase Privacy Policy
- Stripe: Secure payment processing for subscriptions. Stripe Privacy Policy
- Vercel: Web hosting and edge delivery network. Vercel Privacy Policy
- Google Cloud Platform: Backend API hosting and computation. GCP Privacy Policy
5. DATA SECURITY
We implement industry-standard security measures to protect your personal data, including:
- All communications are encrypted using TLS 1.3 (HTTPS)
- Authentication tokens are managed via Firebase with automatic expiration and renewal
- Payment processing is handled by PCI DSS Level 1 certified Stripe infrastructure
- Backend APIs enforce JWT-based authorization with server-side validation
However, no method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.
6. DATA RETENTION & DELETION
We retain your personal data only for as long as necessary to provide the Service and fulfill the purposes outlined in this policy. Upon account deletion or subscription cancellation:
- Your authentication record will be deactivated within 30 days
- Your watchlist data (stored locally) is deleted when you clear your browser data
- Anonymous analytics data may be retained indefinitely in aggregated form
- Stripe transaction records are retained per Stripe's data retention policies and applicable tax/accounting regulations
To request deletion of your personal data, contact us at derrick3096@gmail.com.
7. YOUR RIGHTS UNDER PDPA
Under the Singapore Personal Data Protection Act 2012 (PDPA), you have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of any inaccurate personal data
- Withdrawal of Consent: Withdraw your consent for data collection at any time (this may affect service availability)
To exercise any of these rights, please contact our Data Protection Officer at derrick3096@gmail.com. We will respond to your request within 30 business days.
8. COOKIES & LOCAL STORAGE
The Platform uses browser localStorage (not traditional cookies) to store your preferences, authentication state, and session data. This data is processed entirely on your device and is not transmitted to our servers. You can clear this data at any time through your browser settings.
9. CHANGES TO THIS POLICY
We reserve the right to update this Privacy Policy at any time. Changes will be effective immediately upon posting. Your continued use of the Platform constitutes acceptance of the revised policy. We encourage you to review this page periodically.
© 2026 SGX Omni-Matrix Systems by Derrick. All rights reserved.
Data Protection Officer: derrick3096@gmail.com