Privacy Policy

Last updated: March 2026

1. Data Controller

The data controller responsible for data processing on this website is:

Sheran Investments UG (haftungsbeschränkt)
Erzgießereistr. 5a
80335 München, Germany
Phone: +49 176 4734 3575
Email: support@seasonaledge.app

The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of the processing of personal data (e.g., names, email addresses, etc.).

2. General Information on Data Processing

We take the protection of your personal data seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations, in particular the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

When you use this website, various personal data is collected. This privacy policy explains what data we collect, what we use it for, and how we process it.

3. Legal Basis for Processing

We process personal data based on the following legal grounds under Art. 6(1) GDPR:

  • Consent (Art. 6(1)(a) GDPR): Where you have given us consent for a specific processing purpose (e.g., cookies, newsletter).
  • Contract performance (Art. 6(1)(b) GDPR): Where processing is necessary for the performance of a contract with you, including provision of our services and subscription management.
  • Legal obligation (Art. 6(1)(c) GDPR): Where processing is necessary to comply with a legal obligation (e.g., tax retention requirements).
  • Legitimate interest (Art. 6(1)(f) GDPR): Where processing is necessary for our legitimate interests, such as ensuring website security and improving our services, provided your rights do not override those interests.

4. Data We Collect

4.1 Account Registration

When you create an account, we collect your email address, display name, and authentication credentials. Account authentication is managed through Firebase Authentication (Google Ireland Limited). The legal basis is Art. 6(1)(b) GDPR (contract performance).

4.2 Subscription and Payment Data

When you subscribe to our service, payment processing is handled by Stripe, Inc. (Stripe Payments Europe, Ltd. for EU customers). We do not store your full payment card details on our servers. Stripe processes your payment information in accordance with PCI-DSS standards. We receive only a truncated card number, expiration date, and billing address for record-keeping. The legal basis is Art. 6(1)(b) GDPR (contract performance).

For more information, see Stripe's privacy policy at stripe.com/privacy.

4.3 Usage Data

When you visit our website, our servers automatically collect technical data including your IP address, browser type and version, operating system, referrer URL, pages visited, and the date and time of your visit. This data is collected based on our legitimate interest in ensuring website security and functionality (Art. 6(1)(f) GDPR).

4.4 Contact Requests

If you contact us via email, your message and all provided personal data (name, email address) will be stored for the purpose of processing your inquiry. We will not share this data without your consent. The legal basis is Art. 6(1)(b) GDPR if your inquiry relates to the performance of a contract, or Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).

5. Cookies

Our website uses cookies. Cookies are small text files that are stored on your device by your web browser. You can configure your browser to reject cookies or to alert you when cookies are being sent; however, some parts of the Service may not function properly without them.

5.1 Strictly Necessary Cookies

These cookies are essential for the operation of the website and cannot be disabled. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in providing a functional website).

CookiePurposeDuration
firebase-auth-sessionAuthentication session token24 hours
cookie-consentStores your cookie consent preferencePersistent
astro-selectionRemembers your selected symbol/tickerPersistent
themeStores your light/dark mode preferencePersistent

5.2 Analytics Cookies

If you consent via our cookie banner, we use PostHog analytics cookies to understand how visitors interact with our website. These cookies are only set after you have given your explicit consent (Art. 6(1)(a) GDPR). You can withdraw your consent at any time by clearing your cookies or changing your preference in the cookie banner.

CookiePurposeDuration
ph_*PostHog analytics — page views, interactions1 year

6. Third-Party Services

We use the following third-party service providers to operate the Service. Each provider processes personal data on our behalf as a data processor or as an independent controller, as indicated below.

6.1 Firebase Authentication (Google)

We use Firebase Authentication by Google Ireland Limited for user account management and sign-in. When you sign in (via email/password or Google Sign-In), Firebase processes your authentication data (email address, display name, authentication tokens). The legal basis is Art. 6(1)(b) GDPR (contract performance). Google may transfer data to the US under Standard Contractual Clauses (SCCs) in accordance with Art. 46(2)(c) GDPR. For more information, see Firebase Privacy Information.

6.2 Stripe (Payment Processing)

Payment processing is handled by Stripe Payments Europe, Ltd. (for EU-based customers). Stripe processes your payment details (card number, expiration date, billing address) in a PCI-DSS-compliant environment. We receive only a truncated card number and billing details for record-keeping. The legal basis is Art. 6(1)(b) GDPR (contract performance). For international data transfers, Stripe relies on Standard Contractual Clauses. For more information, see Stripe's Privacy Policy.

6.3 PostHog (Analytics)

With your consent, we use PostHog to analyse how visitors interact with our website. PostHog collects data such as pages visited, clicks, session duration, browser type, screen resolution, and approximate location derived from your IP address. Your IP address is anonymized before storage. The legal basis is Art. 6(1)(a) GDPR (consent). PostHog data is processed within the EU. You can withdraw your consent at any time via the cookie banner or by clearing your browser cookies. For more information, see PostHog's Privacy Policy.

6.4 Cloudflare (CDN and Security)

We use Cloudflare, Inc. as a content delivery network (CDN) and for DDoS protection. Cloudflare may process your IP address, request headers, and other connection metadata to route traffic and protect against malicious requests. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in website security and performance). Cloudflare is certified under the EU-US Data Privacy Framework. For more information, see Cloudflare's Privacy Policy.

6.5 Vercel (Hosting)

Our website frontend is hosted by Vercel Inc. Vercel may process server logs containing IP addresses and request metadata. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in providing the Service). Vercel uses Standard Contractual Clauses for data transfers outside the EU/EEA. For more information, see Vercel's Privacy Policy.

7. International Data Transfers

Some of our third-party service providers are based outside the European Economic Area (EEA). Where personal data is transferred to countries outside the EEA that do not have an adequate level of data protection as determined by the European Commission, we ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR, adopted by the European Commission
  • EU-US Data Privacy Framework certifications where applicable (Art. 45 GDPR adequacy decision)

You may request a copy of the applicable safeguards by contacting us at support@seasonaledge.app.

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:

  • Account data: Retained for the duration of your account. Deleted within 30 days of account deletion request.
  • Payment/transaction data: Retained for 10 years in accordance with German commercial and tax law (§257 HGB, §147 AO).
  • Analytics data: Anonymized and retained for up to 12 months, then automatically deleted.
  • Server logs: Retained for up to 90 days for security purposes, then automatically deleted.
  • Contact inquiries: Retained for 6 months after final correspondence, unless longer retention is required for ongoing business relationships.

After expiry of the applicable retention period, personal data is securely deleted or anonymized. Where deletion is not possible due to legal archival obligations, the data is restricted from further processing and stored securely until deletion is possible.

9. Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR): You have the right to request information about the personal data we hold about you, including the purposes of processing, categories of data, and recipients.
  • Right to rectification (Art. 16 GDPR): You have the right to request correction of inaccurate or incomplete personal data.
  • Right to erasure (Art. 17 GDPR): You have the right to request deletion of your personal data, subject to legal retention obligations.
  • Right to restriction (Art. 18 GDPR): You have the right to request restriction of processing of your personal data.
  • Right to data portability (Art. 20 GDPR): You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
  • Right to object (Art. 21 GDPR): You have the right to object to processing of your personal data based on legitimate interest or direct marketing. Where you object to processing for direct marketing purposes, the data will no longer be processed for such purposes.
  • Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
  • Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority. The competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.

To exercise any of these rights, please contact us at support@seasonaledge.app. We will respond to your request within one month as required by Art. 12(3) GDPR.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, in accordance with Art. 32 GDPR. These measures include:

  • SSL/TLS encryption for all data transmission between your browser and our servers
  • Encrypted storage of sensitive data at rest
  • Firewall protection and DDoS mitigation via Cloudflare
  • Access controls and role-based permissions for backend systems
  • Regular security updates and vulnerability monitoring

Despite these measures, no method of transmission over the internet or method of electronic storage is 100% secure. We regularly evaluate and update our security measures but cannot guarantee absolute security.

11. Children's Data

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us at support@seasonaledge.app and we will promptly delete such data from our systems.

12. Automated Decision-Making

We do not use automated decision-making or profiling as defined in Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you. The trade signals and analytical outputs displayed on the platform are generated by algorithms applied to market and astronomical data, not to your personal data, and do not constitute automated individual decision-making.

13. Newsletter and Marketing Communications

If you subscribe to our newsletter or marketing emails, we process your email address on the basis of your consent (Art. 6(1)(a) GDPR). You may unsubscribe at any time by clicking the “unsubscribe” link included in every marketing email or by contacting us at support@seasonaledge.app. Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.

We may send you transactional emails related to your account and subscription (e.g., payment confirmations, service notifications) without separate consent, as these are necessary for contract performance (Art. 6(1)(b) GDPR).

14. Changes to This Privacy Policy

We reserve the right to update this privacy policy to reflect changes in our practices, third-party services, or for other operational, legal, or regulatory reasons. We will notify registered users of material changes via email. The updated version will be indicated by the “Last updated” date at the top of this page. We encourage you to review this policy periodically.