PRIVACY POLICY
How the board handles information.
This policy describes the information Halted Stock Board collects, what appears publicly, how information is used, and the choices available to users.
Effective date: August 1, 2026
Information we collect
Account and profile information
This includes an email address, display name, system-generated username, email-notification preference, and account timestamps. Authentication is provided by Supabase. Halted Stock Board does not receive or store a readable copy of your password.
If you choose Google sign-in, Google shares your account identifier, verified email, and basic profile information with Supabase for authentication. Your Google name and photo are not automatically published on the board. New Google accounts receive a randomly generated display name that you can change in My profile, with optional email notifications initially off.
Listings and board activity
This includes ticker, Long or Short side, share count, broker, country or region, listing timestamps, status, and structured close information. We also store Contact Requests, their status and notes, private messages, notification state, blocks, safety reports, and moderation records.
Support and security information
Contact us submissions include a reply email, subject, message, and submission time. Authentication and security records may include IP addresses, approximate country or region codes, request timestamps, and ordinary browser, device, and network metadata processed by our infrastructure providers.
How information is used
We use information to:
- create and maintain accounts and provide the position directory;
- support Listings, Contact Requests, private conversations, blocks, and reports;
- send account confirmation, password reset, Contact Request, acceptance, and unread-message notifications;
- respond to support, correction, privacy, and safety inquiries;
- prevent abuse, investigate reports, enforce service rules, and maintain audit records; and
- understand service availability, traffic, and page performance and comply with applicable legal obligations.
What information is public
Security status records, halt timelines, and links to official sources are public. An active position Listing publicly displays the user’s display name, system-generated username, ticker, Long or Short side, share count, broker, country or region, and listing update time.
Public ticker pages do not include account email addresses, authentication data, private messages, Contact Request notes, safety reports, or support submissions.
What is not shown publicly
Email addresses, authentication and security logs, Contact Request notes, safety reports, private messages, support submissions, and non-public moderation records are not displayed publicly.
Accepting a Contact Request does not disclose either participant’s email address. Through the normal service interface, private messages are available only to the participants in the accepted Contact Request.
Authorized administrators and service providers may access or process non-public information when reasonably necessary to operate, secure, support, and moderate the service, investigate reports, or comply with legal obligations. This access is not a promise that non-public information can never be accessed.
Service providers and disclosures
We use service providers including Supabase for authentication and database infrastructure; Cloudflare for DNS, hosting, content delivery, security, request handling, and web analytics; email providers such as Resend for account and service messages; and content-delivery providers for browser libraries.
These providers process information as necessary to provide their services. The information involved depends on the service and may include account email addresses, email-delivery metadata, database records, IP addresses, request metadata, and performance measurements. We may also disclose information when reasonably necessary to comply with law, protect users or the service, or respond to a valid legal request.
We do not sell personal information or use it for behavioral advertising.
The Google sign-in button uses a Google-hosted font. Loading that font sends ordinary network metadata, such as your IP address, to Google even before you choose to sign in.
Browser storage, cookies, and analytics
The board uses browser local storage to maintain an authenticated session. If the standalone local version is opened directly, sample board data may also be stored only in that browser on that device.
Cloudflare Web Analytics collects limited page-view and performance measurements. Cloudflare states that this analytics product does not collect or use visitors’ personal data and does not track individual users across Cloudflare customer sites. Cloudflare security features may set strictly necessary cookies when a security or bot challenge is used.
Do Not Track
We do not use personal information to track users over time across unaffiliated websites for targeted advertising, and we do not currently respond differently to browser Do Not Track signals. We do not authorize third parties to conduct cross-site behavioral advertising through the board. Service providers may receive ordinary request metadata when their resources or services are used.
Retention
Retention periods vary according to the type of information and why it is needed. Account, profile, Listing, Contact Request, and private-message information may be retained while an account is active and afterward when reasonably necessary to operate the service, maintain continuity, resolve support or safety issues, prevent fraud and abuse, preserve audit history, or meet legal obligations.
Closed or hidden Listings, reports, blocks, moderation actions, and security records may be retained after they stop appearing publicly. Infrastructure, authentication, analytics, and email providers maintain their own operational logs under their respective retention practices.
Your choices
Signed-in users can edit their display name, manage email notifications, edit or close Listings, dismiss notifications, block or unblock interactions, and submit safety reports. Account password and recovery controls are provided through Supabase Auth.
You may contact us to ask what information is associated with your account or to request a correction or deletion. A request may be limited where information must reasonably be retained for security, fraud prevention, dispute resolution, legal compliance, or protection of other users.
Age requirement
The service is intended for users who are at least 18 years old. Do not create an account or submit personal information if you are under 18.
Changes to this policy
When this policy changes, we will post the revised version at this URL and update its effective date. If a change is material, we may also provide a notice through the service or by email when appropriate.
Privacy contact
Privacy questions and requests can be sent to contact@haltedstock.com or through the board’s Contact us form.