Skip to main content
Privacy

Privacy Policy

What this site collects, why, and how you stay in control. The MarketClue product itself will have its own privacy notice; this page covers only the website.

1. Scope of this Policy

This Policy explains how MarketClue handles personal data collected through the public website at marketclue.com (the "Site") — including when you join the waitlist, contact us, or simply browse.

It does not cover the MarketClue application. Personal data processed inside the product is governed by the separate MarketClue Privacy Notice presented to you when you are granted access.

2. Who is responsible for your data

The controller of personal data collected through the Site is:

Controller

MarketClue LLC

Registered office

1441 Brickell Ave., Suite 1018, Miami, FL 33131, United States

Florida Document Number

L26000463790

Registered agent

Standard Rules LLC, 1441 Brickell Ave., Suite 1018, Miami, FL 33131

Privacy contact

privacy@marketclue.com

Data Protection Officer

Not appointed. MarketClue is not a public authority and does not process special category data at scale. Because the Site uses session recording, the Article 37(1)(b) "regular and systematic monitoring on a large scale" test has been considered rather than assumed: pre-launch waitlist volumes are not large scale. We will revisit this at product launch and whenever traffic materially increases.

EU representative (Article 27 GDPR)

MarketClue DevOps s. r. o., Mýtna 7643/42, 811 07 Bratislava – mestská časť Staré Mesto, Slovak Republic — a company in our group. Because we are established in the United States and offer the Site to people in the EEA, the GDPR requires us to have a representative there. You and any supervisory authority may address it on any matter concerning this Policy, in addition to or instead of us.

2.1 Group structure and change of controller

MarketClue LLC, a Florida limited liability company, operates the Site and is the controller of the personal data collected through it. MarketClue DevOps s. r. o., Bratislava, Slovak Republic, is a company in our group: it develops the Site and the MarketClue product, and it is our representative in the European Union (section 2).

MarketClue DevOps s. r. o. has access to personal data collected through the Site only for that development and support work, on our instructions and under the same obligations this Policy places on us. It does not use the data for any purpose of its own.

We may transfer the Site, and the personal data collected through it, to another company in our group. If we do, the controller of your data changes. We will post the change in this section before that transfer takes effect, and the receiving company will be bound to honour this Policy until it gives you notice of a replacement. If a change of controller would mean your data is used for a materially different purpose, we will ask for your consent again rather than rely on the consent you gave us.

3. The short version

What do we collect?

Your e-mail address if you give it to us, anything you write to us, a recording of how you use the Site if you consent to it, and standard technical information about your visit.

Why?

To tell you when MarketClue opens, to answer you, to keep the Site working and secure, and — only with your consent — to understand how the Site is used and to measure and target our advertising.

Do we sell your data?

We do not sell personal data for money, and we never upload your e-mail address to an advertising platform — not in hashed form either. We do share something: with your Marketing consent, the advertising tags on this Site pass identifiers to those platforms so they can measure our advertising and show it to you. Under California law that counts as "sharing" for cross-context behavioural advertising. See section 13.2, and use the "Do Not Sell or Share My Personal Information" link in our footer to opt out.

Do we record what I do on the Site?

Only if you consent to analytics. We use session recording, which captures the pages you view, your mouse movement, clicks and scrolling. Text you type is masked before it leaves your browser.

Do we use it to profile you or make decisions about you?

We do not make automated decisions producing legal or similarly significant effects. Advertising platforms do build audience profiles from the data we share with them, with your consent.

How long do we keep it?

See the retention column in section 6. Unsubscribing stops the e-mails at once; we keep the address on a suppression list so we do not write to you again, and delete it 24 months after your last engagement — sooner if you ask us to (section 12).

How do I get out?

Unsubscribe link in every e-mail, the "Cookie settings" link in our footer, or write to privacy@marketclue.com.

4. What personal data we collect

4.1 Data you give us

  • Waitlist registration: your e-mail address, and the date and time of registration. The form asks for nothing else. Alongside it we record which campaign or referrer brought you to the Site, if you accepted marketing cookies (see the Cookie Policy, "mc_attr").
  • Correspondence: your e-mail address, the content of your message, and any information you choose to include in it.

4.2 Data collected automatically

  • Technical and connection data: IP address, browser type and version, operating system, device type, screen size, language setting, and the pages you visited with timestamps.
  • Referral and campaign data: the page that referred you and any UTM or campaign parameters in the link you followed.
  • Session recordings (consent only): where you consent to analytics, we record your session on the Site. A recording captures the pages you view, how you move your pointer, what you click, how far you scroll, and the technical data above. Text you type into forms is masked in your browser before the recording is transmitted, so we do not receive the content of what you type — including the e-mail address you enter on the waitlist form. Recordings are not made if you refuse analytics consent.
  • Cookie and similar identifiers: see the Cookie Policy. Non-essential identifiers are set only after you consent.

4.3 Data we generate or receive

  • Hashed e-mail identifiers — none. We do not convert your e-mail address into a hash and we do not send it to advertising platforms. There is no box on the waitlist form asking you to allow that, and no part of this Site does it. See section 9.
  • Campaign and audience measurement data from advertising and analytics providers, in aggregate or pseudonymous form.
  • E-mail engagement data. Whether a message we sent was opened and whether a link in it was clicked. See section 7.

4.4 What we do not collect on the Site

  • We do not collect payment card details on the Site. No payment is taken on the Site.
  • We do not collect brokerage credentials, account numbers, holdings or transaction data on the Site.
  • We do not knowingly collect special category data (Article 9 GDPR) or sensitive personal information under US state law, and we ask you not to send any to us.
  • We do not collect precise geolocation. IP-derived location is approximate — typically country or city level — and is not used to identify your address.
  • We do not capture the content of what you type into forms in our session recordings.

5. Whether you have to give us data

You are not required to give us any personal data to read the Site. Joining the waitlist requires an e-mail address; without it we cannot notify you, which is the purpose it serves. There is no contractual or statutory obligation on you to provide anything, and the only consequence of not providing it is that you do not receive our e-mails.

You can read the whole Site and join the waitlist while refusing every optional cookie and every optional consent. We do not condition the waitlist on your consent to analytics or to advertising.

6. Why we process your data, on what legal basis, and for how long

The following table is the operative record of our processing on the Site. Article references are to the EU GDPR, which applies to us although we are established in the United States, because we offer the Site to people in the EEA (Article 3(2)). Our representative in the EU is named in section 2.

Purpose, data used, legal basis and retention
PurposeData usedLegal basisRetention
Registering you on the waitlist and sending you launch and product-availability updatesE-mail address; registration timestamp; campaign sourceConsent — Art. 6(1)(a) GDPR. Consent for the e-mails themselves under the national rule implementing Article 13 of the ePrivacy Directive where you live; for US residents the CAN-SPAM Act governs the messages24 consecutive months after the later of your signup and your last e-mail engagement, then deleted from our database and from Loops. Unsubscribing stops the e-mails immediately and does not extend that period: the address stays on a suppression list so we do not contact you again, and is deleted on the clock it already had. You can ask us to erase it sooner (section 12).
Measuring whether our e-mails are opened and whether links in them are clickedE-mail address; open and click events; timestamps; approximate location derived from IPConsent — Art. 6(1)(a) GDPR, and the national rule implementing Article 5(3) of the ePrivacy Directive for the tracking pixel24 months from the event
Responding to your enquiryE-mail address; message contentArt. 6(1)(b) — steps at your request prior to a contract; otherwise Art. 6(1)(f) legitimate interest in answering correspondence24 months from the last message in the thread
Operating, securing and troubleshooting the Site; preventing abuse, fraud and automated attackIP address; user agent; request logs; error reportsArt. 6(1)(f) — our legitimate interest in the availability, integrity and security of our own serviceServer and security logs: 30 days, extended only where an incident is under investigation
Understanding how the Site is used, so we can improve itPseudonymous analytics identifier; IP address; pages viewed; referrer; approximate country; device classConsent — Art. 6(1)(a) GDPR, together with the national rule implementing Article 5(3) of the ePrivacy Directive for the storage of, or access to, information on your deviceAnalytics identifiers: maximum 14 months
Recording your session on the Site so we can see where the Site confuses people and fix itSession recording as described in section 4.2, with typed input masked; pseudonymous analytics identifierConsent — Art. 6(1)(a) GDPR, together with the national rule implementing Article 5(3) of the ePrivacy DirectiveRecordings: 30 days, then automatic deletion
Measuring our advertising campaigns — whether an advertisement led you to the Site and to a waitlist registrationAdvertising platform identifiers; conversion events; campaign parametersConsent — Art. 6(1)(a) GDPR and the national rule implementing Article 5(3) of the ePrivacy DirectiveThe identifiers live in cookies that last between 30 days and 24 months depending on the platform; each is listed with its duration in the Cookie Policy, section 7.4. What a platform keeps on its own side is governed by its own privacy notice, linked from the same table
Recording your cookie and marketing preferences, and proving that we obtained consentConsent record: choice per category, timestamp, consent string version, truncated IPArt. 6(1)(c) — legal obligation to demonstrate consent under Art. 7(1) GDPR3 years from the date of the consent record
Complying with legal obligations, and establishing, exercising or defending legal claimsWhichever of the above is relevantArt. 6(1)(c) and Art. 6(1)(f)For the applicable statutory or limitation period

6.1 Legitimate interests

Where we rely on Article 6(1)(f) — Site security and answering your correspondence — we have weighed that interest against your rights and freedoms, and consider that it is not overridden by them. The data involved is technical, the use is limited to keeping the Site running and replying to you, and you would expect both. If you want to know more about how we struck that balance, write to privacy@marketclue.com.

6.2 Withdrawing consent

Every purpose above that relies on consent can be switched off at any time, and doing so is as easy as switching it on. The "Cookie settings" link in the footer covers everything set on your device: analytics, session recording and advertising cookies. The e-mails stop on the page the unsubscribe link in any message opens, immediately and without a reason. Withdrawal does not affect the lawfulness of anything we did before it.

7. E-mail we send you

If you join the waitlist we will send you a small number of messages: a confirmation, occasional progress updates, and a message when MarketClue opens.

We do not send third-party advertising, and we do not rent, sell or otherwise make your address available to any third party for that third party's own marketing purposes. We also do not give your address to an advertising platform for our own marketing — not in hashed form, not as seed data for a lookalike audience, not at all. The only address we hold is the one we e-mail, and the only people who see it are the providers in section 9 who send that e-mail for us.

Every message contains a one-click unsubscribe link and our postal address. Unsubscribing takes effect immediately and does not require you to give a reason or to log in anywhere.

For the updates, we record whether a message was opened and whether a link in it was clicked, in order to gauge interest and to stop sending to addresses that never engage. This uses a tracking pixel, and you can defeat it by disabling remote image loading in your e-mail client. The confirmation message carries no such pixel.

The confirmation is sent through SendGrid (Twilio Inc., United States), with open and click tracking switched off. Every later message is sent through Loops, Astrodon Corporation (United States), which stores your address on our behalf. The sub-processors Loops itself uses are listed at loops.so/subprocessors, and our processing agreement with Loops requires it to return or securely delete the data it holds for us within 30 days of our request. See sections 9 and 10.

8. Cookies and similar technologies

The Site uses cookies and similar technologies. Strictly necessary items are set without consent because the Site cannot function without them. Everything else — preferences, analytics, session recording, and advertising — is set only after you have given consent through the cookie banner, and you can change or withdraw that consent at any time. Full detail, including the inventory of each item and its duration, is in the Cookie Policy.

Any advertising tag we run reaches the Site through Google Tag Manager; Google Analytics and PostHog are loaded by the Site's own code. Google Tag Manager does not itself set cookies for advertising or analytics, and its container is requested only once you have accepted analytics or advertising cookies: no tag in a consent-requiring category fires before you consent. Which advertising platforms are on the Site at any time is listed in the Cookie Policy at section 7.4, which says so plainly when none is.

9. Who we share personal data with

We do not sell personal data for money. We share it with the recipients set out below. Where a recipient acts on our instructions it does so under a written contract meeting Article 28 GDPR; where a recipient determines its own purposes, that is identified in the table. An advertising platform receives nothing until its tag is on the Site, so for those five rows the safeguard column names the arrangement that will govern the platform once it runs, not one already in force. Which of them are on the Site at any time is in the Cookie Policy, section 7.4.

Recipient, what they do, role, location and safeguard
RecipientWhat they doRoleLocationSafeguard
DigitalOcean, LLCWebsite hosting and infrastructure; runs the database that holds waitlist addresses, and stores server and security logsProcessorUnited StatesArt. 28 DPA. EU-U.S. Data Privacy Framework, certified and active (verified 26 August 2026)
Cloudflare, Inc.Network in front of the Site: DNS, TLS termination, caching, and protection against denial-of-service attacks and abusive traffic. Every request to the Site passes through it, so it sees your IP address, request metadata and — for the moment of transmission — anything you submit, including the waitlist formProcessorGlobal network; the request is handled at the Cloudflare location nearest to you, which for a visitor in the EEA is normally inside it. Company established in the United StatesArt. 28 DPA (Cloudflare Data Processing Addendum v6.4, 3 April 2026, incorporated into the service agreement). EU-U.S. Data Privacy Framework, certified and active (verified 2 September 2026)
Loops, Astrodon Corporation ("Loops")Stores waitlist addresses; sends and measures our e-mailProcessorUnited StatesArt. 28 DPA. EU-U.S. Data Privacy Framework, certified and active (verified 26 August 2026)
Twilio Inc. — SendGridDelivers the single confirmation e-mail we send when you join the waitlist, and records whether it was delivered. Open and click tracking are switched off on that messageProcessorUnited StatesArt. 28 DPA (Twilio Data Protection Addendum of 9 April 2026, incorporated into Twilio's Terms of Service). The European Commission's Standard Contractual Clauses (Decision 2021/914), as set out in Schedule 3 of that Addendum
Google LLC — Google Analytics 4 and Google Tag ManagerAggregate usage measurement; tag delivery (both consent-gated)ProcessorEU and United StatesArt. 28 DPA (Google Ads Data Processing Terms); SCCs
PostHog, Inc.Product analytics and session recording (consent-gated)ProcessorUnited StatesArt. 28 DPA. EU-U.S. Data Privacy Framework, certified and active (verified 26 August 2026). See section 10
Usercentrics A/S ("Cookiebot")Runs the consent platform behind the banner and stores the consent recordProcessorEuropean UnionArt. 28 DPA
Meta Platforms Ireland LimitedAdvertising delivery and conversion measurement. We do not use custom or lookalike audiencesJoint controller with us for measurement dataEU and United StatesArt. 26 arrangement (Meta Controller Addendum); SCCs
Google LLC — Google AdsAdvertising delivery and conversion measurement. We do not use customer match or similar audiencesJoint controller or independent controller depending on the product usedEU and United StatesArt. 26 or Art. 28 as applicable; SCCs
TikTok Technology LimitedAdvertising delivery and conversion measurement. We do not use custom or lookalike audiencesJoint controller with us for measurement dataEU (Ireland). TikTok's own onward transfers, including remote access from other countries, are made under its Standard Contractual ClausesArt. 26 arrangement (TikTok Business Products (Data) Terms); SCCs
X Corp. / Twitter International Unlimited CompanyAdvertising delivery and conversion measurement. We do not use tailored audiencesJoint controller or independent controllerEU and United StatesArt. 26 or Art. 28 as applicable; SCCs
Reddit, Inc.Advertising delivery and conversion measurement. We do not use custom audiencesJoint controller or independent controllerUnited StatesArt. 26 or Art. 28 as applicable; SCCs
MarketClue DevOps s. r. o.Develops and supports the Site and the product on our behalf; our representative in the European Union (section 2)Processor within our groupEuropean Union (Slovak Republic)Group company acting on our instructions under the obligations of Article 28 GDPR. It is established in the EEA, so its access is not a transfer out of it
Professional advisersLegal, accounting and tax advice, under professional duties of confidenceIndependent controllersUnited States and European UnionConfidentiality obligation
Public authoritiesOnly where we are legally required to disclose, and only to the extent requiredIndependent controllersAs applicableLegal obligation
A successor entityOn a reorganisation, merger, or transfer of the businessControllerEU / USNotice to you; contractual protection

9.1 What advertising platforms receive, and what they do with it

We send them nothing about you from our servers. We do not upload e-mail addresses to any advertising platform, in hashed form or otherwise, and we do not build custom or lookalike audiences from our waitlist. There is no box on the waitlist form offering that, because we do not do it.

What these platforms do receive comes from your own browser, and only if you have accepted Marketing in the cookie banner: their advertising and conversion tags then set or read an identifier and report that a visit or a waitlist registration happened. Each platform determines some purposes of its own with that — which is why several of them are identified above as joint or independent controllers rather than as our processors. Their own privacy notices govern what they do in that capacity, and we link to them from our Cookie Policy. Refusing or withdrawing Marketing consent stops all of it.

10. International transfers

We are established in the United States, and so are several of our service providers. What you send us through the Site is collected by us directly. Under the European Data Protection Board's guidance that is not a "transfer" in the GDPR sense, but it does mean your data is held by a United States company — one that is subject to the GDPR under Article 3(2) and to this Policy, and that has a representative in the EU named in section 2. Where personal data is then passed on from the EEA to a provider outside it, we rely on one or both of the following:

  • an adequacy decision of the European Commission, including — for a provider that is certified — the EU-US Data Privacy Framework;
  • the European Commission's Standard Contractual Clauses, together with technical measures such as encryption in transit and at rest.

10.1 Where the Site is hosted

The Site itself is hosted in the United States, by DigitalOcean, LLC, and so is the database that holds waitlist addresses. DigitalOcean is covered by the EU-U.S. Data Privacy Framework. Requests to the Site reach that server through Cloudflare's network, which handles each request at the location nearest to you; Cloudflare is also a United States company, and the same Framework covers it.

10.2 The specific transfers we make

Your waitlist e-mail address is stored in the United States twice over: in our own database, which runs on DigitalOcean's infrastructure there, and by Loops. Session recordings and product analytics are processed in the United States by PostHog. Advertising identifiers set in your browser reach advertising platforms that process in the United States. Your e-mail address itself never reaches any of those platforms, in any form.

For Loops, PostHog, DigitalOcean and Cloudflare we rely on the EU-U.S. Data Privacy Framework. Each is on the U.S. Department of Commerce's Data Privacy Framework List with an active certification covering non-HR data under the EU-U.S. Framework, verified on 26 August 2026 (Cloudflare: 2 September 2026). A transfer to a certified organisation is treated as a transfer to a country with an adequate level of protection, so no additional Standard Contractual Clauses are required for it.

For an advertising platform, the transfer basis will be Standard Contractual Clauses or the joint-controller arrangement described in section 9, according to the terms that platform offers. None is in force yet, because no platform's tag runs on the Site.

We re-check each provider's certification status at least annually, and whenever we are notified that it has changed. If a certification lapses we fall back to Standard Contractual Clauses, and we will update this Policy.

10.3 Session recordings

Because session recordings are richer than ordinary analytics data, we apply additional mitigations to them beyond the transfer mechanism itself: input masking at source so that typed text never leaves your browser, a 30-day retention ceiling, and access restricted to those who need it.

You may request a copy of the safeguards applying to a particular transfer by writing to privacy@marketclue.com.

Verification note

Verified 26 August 2026 against the Data Privacy Framework List at dataprivacyframework.gov: Loops, Astrodon Corporation (Beaverton, OR); PostHog Inc (San Francisco, CA); DigitalOcean (Broomfield, CO) — all three active under the EU-U.S. Framework. Cloudflare, Inc. (San Francisco, CA) was verified the same way on 2 September 2026: active.

11. Security

We apply technical and organisational measures appropriate to the risk, including: encryption of traffic in transit (TLS); access control on the systems holding waitlist data, restricted to those who need it; masking of typed input before session recordings leave your browser; and contractual security obligations on our processors.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority or authorities within 72 hours as required by Article 33 GDPR, and we will notify you directly where Article 34 requires it.

12. Your rights under the GDPR

If you are in the EEA, you have the following rights in relation to your personal data. They are not absolute and some depend on the legal basis for the processing.

Access (Art. 15)

To be told whether we hold personal data about you and to receive a copy of it, together with information about how it is used.

Rectification (Art. 16)

To have inaccurate data corrected and incomplete data completed.

Erasure (Art. 17)

To have your data deleted where it is no longer needed, where you withdraw consent and there is no other basis, or where it has been processed unlawfully.

Restriction (Art. 18)

To have processing paused while an accuracy dispute or an objection is resolved.

Portability (Art. 20)

To receive the data you gave us, in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible. This applies to data processed on consent or contract.

Objection (Art. 21)

To object at any time to processing based on our legitimate interests, on grounds relating to your particular situation. Where we process for direct marketing, you may object at any time and we will stop, with no balancing test.

Withdraw consent (Art. 7(3))

To withdraw consent at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing before it.

Automated decisions (Art. 22)

Not engaged. We do not make decisions about you by automated means that produce legal or similarly significant effects.

Complain (Art. 77)

To lodge a complaint with a supervisory authority.

12.1 Rights against advertising platforms

Where a platform named in section 9 acts as a joint controller, you may exercise your rights against us or against that platform directly. If you write to us, we will pass your request on and tell you that we have done so. Withdrawing your Marketing consent in the cookie banner stops that platform's tags on this Site immediately; it does not by itself erase data the platform holds about you in its own capacity, for which you should use that platform's own controls.

12.2 How to exercise a right

Write to privacy@marketclue.com. We will respond within one month, which we may extend by a further two months for complex requests, telling you why. We may ask you for information to confirm your identity — we will ask only for what is needed, and we will not use it for anything else. There is no charge unless a request is manifestly unfounded or excessive.

12.3 Supervisory authority

Because we are not established in the European Union, no single authority leads on complaints about us. You may lodge a complaint with the supervisory authority of the EU Member State where you live or work, or where the alleged infringement took place. The European Data Protection Board lists them at edpb.europa.eu/about-edpb/about-edpb/members_en. Our representative in the EU, MarketClue DevOps s. r. o., named in section 2, is established in the Slovak Republic, whose authority is the Úrad na ochranu osobných údajov Slovenskej republiky (dataprotection.gov.sk).

Complaints about cookies and other storage on your device go to the authority your Member State designates under the ePrivacy Directive, which in some Member States is a telecommunications regulator rather than the data protection authority.

13. Additional information for residents of US states

This section applies if you live in a US state with a comprehensive consumer privacy law. As at September 2026 nineteen such laws are in force: in California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, with further laws taking effect in 2027.

Applicability

Most of these laws apply only above a threshold — commonly the personal data of 100,000 state residents, or a revenue test. A pre-revenue landing page is very unlikely to meet any of them today. We publish this section anyway. Where a right below is not available to you under your state's law, we will still honour a deletion or opt-out request as a matter of practice.

13.1 Notice at collection — categories

CCPA notice-at-collection categories
Category (California Civil Code § 1798.140)Do we collect it?SourceBusiness purposeDisclosed or shared?
Identifiers — e-mail address, IP address, online identifiersYesFrom you; automaticallyWaitlist notification; security; analytics; advertisingYes — to service providers; the online identifiers set in your browser are also shared with advertising platforms for cross-context behavioural advertising. Your e-mail address is not.
Customer records — nameNo. The waitlist form asks only for an e-mail address
Commercial informationNo — no purchases are made on the Site
Internet or network activity — pages viewed, referrer, session recording, interaction with our e-mailYesAutomatically; from analytics and e-mail providersImproving the Site; measuring interestDisclosed to service providers; advertising identifiers shared with advertising platforms
Geolocation dataApproximate only, derived from IP. Not precise geolocationAutomaticallySecurity; aggregate audience understandingDisclosed to service providers
Audio, electronic, visual information — session recordings of your interaction with our pagesYes, with consentAutomaticallyDiagnosing usability problemsDisclosed to our analytics provider only
Inferences / profilesWe do not build them. Advertising platforms build audience profiles from data we shareAdvertisingShared with advertising platforms
Sensitive personal informationNo
Biometric, health, financial account, government ID dataNo

How long we keep each category is set out against its purpose in the retention column of section 6; the periods there apply to this notice too.

13.2 Sale and sharing

We do not sell personal information for money.

We do share personal information for cross-context behavioural advertising when advertising tags run on the Site. Where we deploy advertising and conversion tags from platforms such as Meta, Google, TikTok, X or Reddit, those tags pass online identifiers and conversion events to the platforms. Which platforms' tags are on the Site at any time is listed in the Cookie Policy, section 7.4, which says so plainly when none is. Under the CCPA as amended by the CPRA, and under the equivalent provisions of other state laws, that is treated as "sharing" — and by some regulators as a "sale" — even though no money changes hands. We do not upload e-mail addresses, hashed or otherwise, and we do not build custom or lookalike audiences from our waitlist.

Accordingly:

  • a "Do Not Sell or Share My Personal Information" link appears in the footer of every page of the Site;
  • we honour Global Privacy Control signals automatically, as described in section 13.4;
  • we do not share the personal information of anyone we know to be under 16.

The categories shared are identifiers (advertising cookie identifiers, IP address) and internet activity (pages viewed, conversion events). The categories of third party they are shared with are advertising platforms, listed by name in section 9.

13.3 Your rights

  • To know what personal information we have collected, used, disclosed and shared about you, and to receive a copy of it.
  • To have it corrected if it is inaccurate.
  • To have it deleted, subject to legal exceptions.
  • To opt out of any sale or sharing for cross-context behavioural advertising, and of targeted advertising.
  • To opt out of profiling in furtherance of decisions producing legal or similarly significant effects — not applicable, as we do not do this.
  • To limit the use of sensitive personal information — not applicable, as we do not collect it.
  • Not to be discriminated against for exercising any of these rights. We do not offer financial incentives for personal information.

To exercise any of these rights, use the "Do Not Sell or Share My Personal Information" link in the footer, or write to privacy@marketclue.com. We will verify your request by reference to the e-mail address on file. An authorised agent may act for you if you give them written permission and we can verify it. If we decline a request we will tell you why, and you may appeal by replying to our decision. Where your state requires it, we will also tell you how to complain to your state attorney general.

13.4 Opt-out preference signals

We honour the Global Privacy Control (GPC) signal. If your browser or extension sends a GPC signal, we treat it as a request to opt out of any sale or sharing of personal information and of targeted advertising, and we apply it automatically for that browser without requiring you to interact with the banner. We do not respond to legacy "Do Not Track" headers, for which no common standard was ever settled.

13.5 Notice to Nevada residents

Nevada residents may direct a request not to sell covered information to privacy@marketclue.com. We do not sell covered information as defined by Nevada law.

14. Children

The Site is not directed at children and is intended only for people aged 18 or over. We do not knowingly collect personal data from anyone under 18, and we do not knowingly collect personal information from children under 13 within the meaning of the US Children's Online Privacy Protection Act. We do not knowingly share the personal information of anyone under 16 for cross-context behavioural advertising. If you believe a child has given us personal data, write to privacy@marketclue.com and we will delete it.

15. Automated decision-making and artificial intelligence

The Site does not carry out profiling or automated decision-making producing legal or similarly significant effects concerning you.

The MarketClue product uses artificial intelligence to explain market data. That processing is described in the product privacy notice and is outside the scope of this Policy. Personal data collected through the Site is not used to train any AI model, and session recordings are not used to train any AI model.

16. Changes to this Policy

We may update this Policy. The version in force is the one posted here, identified by the "last updated" date at the end of it. Where a change materially affects how we use data we already hold about you, we will tell you by e-mail before it takes effect and, where the law requires it, ask for your consent again.

17. Contact

Privacy enquiries and rights requests: privacy@marketclue.com

Post: MarketClue LLC, 1441 Brickell Ave., Suite 1018, Miami, FL 33131, United States

Representative in the European Union (Article 27 GDPR): MarketClue DevOps s. r. o., Mýtna 7643/42, 811 07 Bratislava – mestská časť Staré Mesto, Slovak Republic

Last updated: 8 September 2026. Version 1.0.