Privacy Policy

Effective 2026-08-09

What SQMATE collects, how it is used, and what you can ask us to do about it. The Service is usable without an account today; this policy will be updated before Google or email sign-up is introduced.

1. Overview

SQMATE (the "Service") handles personal data with care and complies with applicable law, including the Korean Personal Information Protection Act. This policy explains what data the Service processes and how.

The Service is an information platform that shows cycle position and chart-pattern similarity for equities, commodities and crypto. It is not a registered investment adviser or financial investment business, and nothing on the site is investment advice or a solicitation.

2. Data we process

Most screens work without an account. For signed-out visitors we do not collect directly identifying information such as your name or phone number; the following is processed automatically to operate the Service.

Access logs: IP address, requested URL, timestamp, user agent, referrer (server and CDN logs)

Usage records: symbols viewed, search terms, navigation paths (for trending-search counts and error tracing)

Cookies and local storage: language choice (NEXT_LOCALE), theme, analytics identifiers

If you create an account with Google sign-in or email sign-up, we additionally collect the following.

Required: email address and the identifier needed for authentication (e.g. Google account ID)

Optional: profile name and image, watchlist and alert settings

For email sign-up: password, stored only as a one-way hash — never in plain text

If you subscribe, payment-related data is also processed. Card number, expiry and CVC are collected directly by our payment provider (Stripe) — the Service neither receives nor stores them.

Stored by the Service: the customer and subscription identifiers issued by the provider, subscription status and dates (trial end, next charge date), whether the last charge succeeded, and the card brand and last four digits for display

Usage counts for enforcing plan limits: per-user, per-day report views and screen searches (kept up to 120 days, then deleted)

If you send us a message from the contact page, we process what we need to reply. Messages are not stored in a separate database; they are delivered to our operations mailbox.

When you contact us: the email address for our reply, the topic and body of your message, and the time, IP address and browser information of the submission (to block spam)

3. Purposes

Providing the Service: generating analysis screens, remembering language and theme

Improvement: usage statistics, reproducing and fixing errors, trending-search counts

Security: detecting and blocking abnormal access or excessive automated requests

Support: replying to your inquiries

Account authentication and (planned) watchlist alerts

4. Retention

Access and usage records: kept up to 12 months, then deleted

Cookies: language and theme up to 1 year; analytics cookies per each provider's policy

Contact messages: cleared from the operations mailbox once the thread is closed, and in any case within 3 years (the statutory retention period for consumer complaint and dispute records)

Account data: when you close your account we lock it immediately and erase it after 30 days. The window exists so an accidental deletion can be undone — sign in or sign up again with the same email within it and your account, watchlist and alert settings are restored as they were. After the window the data is erased automatically. Records the law requires us to retain are stored separately for the required period

Where statute (e-commerce, telecommunications privacy, etc.) requires longer retention, that period applies.

5. Sharing and processors

We do not sell personal data and do not share it with third parties except as required by law. The following processors support the Service.

Google (Google Analytics): usage analytics — United States

Microsoft (Clarity): usability analytics — United States

Cloudflare: CDN and security — United States and global edge

Microsoft (Azure): server hosting and email delivery — Republic of Korea

Google: account sign-in (OAuth) — United States

Stripe: paid subscription payments — United States and Ireland (Stripe collects and stores card details directly; the Service receives only the payment identifier and status. Payment and tax records are retained by Stripe for the period required by law.)

These arrangements involve transferring data outside Korea. The transferred items are the automatically collected data in section 2, for the purposes and periods stated there. If you prefer not to have data transferred, you may block cookies and scripts in your browser; some features may then be limited.

6. Your rights

You may request access, correction, deletion or suspension of processing of your personal data at any time. Send requests to the contact address below; we will act without delay and inform you of the outcome.

You can refuse or delete cookies in your browser settings, and opt out of analytics collection using browser tracking protection or each provider's opt-out tool.

7. Children

The Service is not directed to children under 14 and we do not knowingly collect their personal data. If we learn that a user is under 14, we delete the data.

8. Security measures

Encryption in transit (HTTPS)

Least-privilege access with administrator access logging

Passwords stored as one-way hashes (never in plain text)

Notification to users as required by law in the event of a breach

9. Changes to this policy

If this policy changes, we will post the changes and the effective date on the Service. Material changes that disadvantage users will be announced at least 7 days before they take effect.

10. Contact

Privacy inquiries and access requests: admin@sqmate.com

Privacy Policy — SQMATE