Privacy Policy
Last updated: September 2026
What we collect
Account data: your email address, password (stored only as a hash by our authentication provider), plan status, and the CRR account codes you claim with their verification status.
Usage data: standard server logs (IP address, browser type, pages requested, timestamps) kept for security and operations. On credit-lane features, views of counterparty data are recorded in an append-only access log — that is a product feature, disclosed to those customers.
Market data is not personal data: positions, awards, and prices we analyze are public records published by ERCOT. Where a CRR account’s registered contact is a person’s name and email, that information comes from ERCOT’s public registry and we use it solely to verify account claims and, where lawful, to send relevant correspondence.
What we do with it
Operate the Service: authentication, showing you your claimed book, sending transactional email (verification, alerts you opt into, billing). Improve the Service using aggregate usage. Send product updates you can opt out of. We do not sell personal data, run third-party advertising, or share your identity or activity with other subscribers. Which holder codes you claim, and what you view, is never disclosed to anyone else except as required by law.
Who processes it for us
We use a small set of processors: Supabase (database and authentication, hosted in the US), Vercel (web hosting), Render (data pipeline), Resend (transactional email), and a payment processor once billing launches (card details will go directly to them and never touch our servers). Each receives only what its function requires.
Retention and deletion
Account data is kept while your account exists. Close your account (or email us) and we delete your account data within 30 days, except records we must keep for legal, billing-dispute, or security purposes and append-only audit records, which are retained but disassociated from you where feasible. Server logs rotate on a short schedule.
Your choices and rights
You can access, correct, export, or delete your account data by emailing team@shadowprice.io. Marketing email has an unsubscribe link; transactional email (verification, billing) is sent as needed to run the Service. Where your jurisdiction grants additional rights, we honor them on request.
Security
Data is encrypted in transit; access is credentialed and role-limited; per-holder data is gated by database-level rules, not just interface code. No system is perfectly secure — report concerns to team@shadowprice.io and we will respond promptly.
Changes and contact
Material changes to this policy will be announced by email or in-product before taking effect. Questions: team@shadowprice.io.