Privacy Policy
Last updated: 17 June 2026
Data controller
dbLabs (org. no. 900323-5612), a sole proprietorship registered in Sweden, with address Västra Husby Solliden 1, 60596 Norrköping, Sweden, is the data controller. Contact: support@ontickr.com.
Data we process
- Account data: email, sign-in method.
- User data: watchlist, portfolio transactions, price alerts.
- Technical data: IP, device/browser information, logs.
Purposes and legal basis
- Provide the Service — contract.
- Security and fraud prevention — legitimate interest.
- Bookkeeping — legal obligation.
Recipients
- Stripe Payments Europe, Ltd. — Merchant of Record for payments, invoicing, VAT, fraud prevention and refunds.
- Hosting and database providers that run the Service.
- AI providers (Google) for analyses — only aggregated market data, no personal data.
- Authorities when required by law.
Data processors
We use the following data processors, who process data on our behalf under written Data Processing Agreements (DPAs). Transfers outside the EU/EEA rely on the European Commission's Standard Contractual Clauses (SCCs).
- Supabase — authentication, database and file storage (EU region).
- Cloudflare — hosting, CDN and DDoS protection.
- Lovable AB — runtime platform and edge functions.
- Stripe Payments Europe, Ltd. (Ireland) — payments as Merchant of Record.
- Google (Gemini AI) — AI analysis on aggregated market data.
- Resend — transactional email (receipts, password reset).
- Yahoo Finance & CoinGecko — market data providers (no personal data shared).
Storage and transfers
Data is primarily stored within the EU/EEA. Where we use providers outside the EU/EEA, transfers are based on SCCs together with supplementary technical safeguards (encryption in transit and at rest).
Retention
As long as your account is active. On deletion, data is removed except where law requires longer retention.
Your rights (GDPR)
Under GDPR you have the right to access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability and objection, and to withdraw consent.
How to request access or erasure
- Access / data export: email us from your registered address at support@ontickr.com with the subject "GDPR – access". We respond within 30 days with a machine-readable copy of your data.
- Account deletion: sign in and go to Settings → "Delete account", or email support@ontickr.com with the subject "GDPR – erasure". Your account and related personal data are deleted within 30 days, except data we must retain by law (e.g. accounting records for 7 years).
- Rectification or restriction: email the same address describing what needs to change.
- Complaints: you may lodge a complaint with the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, Sweden, imy.se, or your local EU data protection authority.
Security
Encryption in transit, access control and logging.
Cookies
We only use necessary cookies for sign-in and settings. See our cookie policy for the full description.