Privacy Policy
This policy explains what information TBBTrade (“TBBTrade,” “we,” “us”) collects when you use this website, why we collect it, who we share it with, and the rights you have over it. We collect as little as we can to run the product, and we never sell your personal information.
01Who we are
TBBTrade publishes supply-chain research and operates this website, including reader accounts, watchlists, and a job-application form. TBBTrade is operated by [legal entity name], which acts as the data controller for the personal information described here. For any privacy question, contact us at poorfoliopickers@gmail.com.
02Information we collect
We only collect information in the situations below.
Account information. When you create an account, we collect your email address and a password. The password is hashed and stored by our authentication provider (Supabase); we never see or store it in plain text.
Watchlist data. If you add tickers to your watchlist, we store the ticker symbols, the date you added them, and the price at that time, linked to your account so we can show you your list.
Job applications. If you apply through our Apply form, we collect the information you submit — your name, age, school, the position you’re applying for, how you heard about us, any additional notes, and the files you upload (a résumé, and a writing sample for editorial roles). These files are stored in a private bucket accessible only to us.
Technical information. Like most websites, our hosting and infrastructure providers automatically process limited technical data needed to serve and secure the site — IP address, browser type, request timestamps, and error logs. We use this for security, debugging, and abuse prevention, not to build advertising profiles.
Cookies. See Section 06.
03How we use your information
- To create and operate your account and keep you signed in.
- To store and display your watchlist.
- To review and respond to job applications.
- To send transactional email (for example, a welcome message when you sign up).
- To secure the service, prevent abuse, debug problems, and meet legal obligations.
We do not sell your personal information, and we do not use it for third-party advertising.
04Legal bases (EU/UK users)
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases under the GDPR:
- Contract — to provide the account, watchlist, and application features you request.
- Legitimate interests — to secure the service, prevent fraud and abuse, and improve reliability.
- Consent — where you opt in, such as joining our newsletter (you can withdraw consent at any time).
- Legal obligation — where the law requires us to retain or disclose information.
07Data retention
- Account & watchlist — kept while your account is active. Deleted on request (see Section 09).
- Job applications — retained while we evaluate candidates and for a reasonable period afterward, then deleted, unless you ask us to delete them sooner.
- Technical logs — retained for a limited period by our infrastructure providers for security and debugging.
08Security
Access to personal data is restricted. Reader data is protected by database row-level security so one account cannot access another’s. Application files are stored in a private bucket reachable only with short-lived signed URLs. Passwords are hashed by our authentication provider. No system is perfectly secure, but we work to protect your information and to limit what we collect in the first place.
09Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and associated data.
- Export a copy of your data (portability).
- Object to or restrict certain processing.
- Withdraw consent for anything you opted into, such as the newsletter.
California residents have additional rights under the CCPA/CPRA, including the right to know, delete, and correct, and the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined under California law.
To exercise any right, email poorfoliopickers@gmail.com. We will respond within the timeframe required by applicable law. EEA/UK users also have the right to lodge a complaint with their local data-protection authority.
10International transfers
Our providers may process and store data in the United States and other countries. Where required, transfers of personal data out of the EEA or UK are protected by appropriate safeguards such as Standard Contractual Clauses.
11Children
This site is intended for adults. We do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact us and we will delete it.
12Changes to this policy
We may update this policy as the product evolves. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Continued use of the site after an update means you accept the revised policy.
13Contact
Questions, requests, or complaints about privacy: poorfoliopickers@gmail.com.
This policy describes our current practices in plain language. It is provided for transparency and is not legal advice.