Stoggio

Privacy Policy

Last updated 11 August 2026

Stoggio is the data controller for the personal data described here. We collect as little as the service can run on, and we do not sell it to anyone.

1.Who to contact

2.What we collect, and why

Account data — your name, email address and a cryptographic hash of your password (never the password itself). We need this to give you an account and to sign you in. Legal basis: performance of our contract with you.

Session data — a session token, plus the IP address and browser user-agent of the device you signed in from. This keeps you signed in and lets us spot account abuse. Legal basis: contract, and our legitimate interest in keeping accounts secure.

Subscription data — your Stripe customer and subscription identifiers, plan status and billing period. We need this to know whether your access is active. Legal basis: contract, and our legal obligation to keep accounting records. We never receive or store your card number — Stripe handles the card and we only see the result.

Email delivery data — your address is passed to our email provider so that account emails and trade digests can be delivered. Legal basis: contract.

3.What we do not do

  • We do not sell, rent or trade your personal data.
  • We do not run advertising or third-party tracking, and there are no analytics or advertising cookies on this site.
  • We do not profile you or make automated decisions that produce legal effects for you. The AI on this site analyses securities, not subscribers — no personal data of yours is sent to the AI model provider.
  • We do not send marketing email unless you have asked for it. Trade digests are part of the subscription you paid for, and stop when it does.

4.Cookies

Stoggio sets one cookie: the session cookie that keeps you signed in. It is strictly necessary for a service you asked for, so it does not require consent and there is no cookie banner. Signing out removes it. If you go through Stripe Checkout, Stripe sets its own cookies on its own domain under its policy.

5.Who processes data on our behalf

These providers act as our processors under contract, and only on our instructions:

  • Stripe — payments and subscription billing.
  • Mailgun — sending account email and trade digests.
  • Our hosting and database providers — running the application and storing its data.

Where a provider transfers data outside the EU/EEA, that transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision.

6.How long we keep it

Account and subscription data is kept while your account exists. If you delete your account, we erase your account data within 30 days, except records we must keep for accounting purposes — Danish bookkeeping rules require transaction records to be retained for five years. Session records expire and are cleared automatically; password reset and email confirmation tokens expire within an hour.

7.Your rights

Under the GDPR you can ask us to:

  • Give you a copy of the personal data we hold about you, in a portable format.
  • Correct anything inaccurate.
  • Delete your data (subject to the retention rules above).
  • Restrict or object to a particular use, including any use based on our legitimate interests.
  • Withdraw consent, where a use is based on consent, without affecting what came before.

Email mail@stoggio.com and we will respond within one month.

8.Security

Passwords are stored only as salted hashes. Traffic is served over HTTPS and the database connection is encrypted. No system is perfectly secure, but if a breach ever affects your data and poses a risk to you, we will tell you and the supervisory authority as the GDPR requires.

9.Complaints

If you think we have mishandled your data, please tell us first. You also have the right to complain to the Danish Data Protection Agency (Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk), or to the supervisory authority where you live.