How we protect your account and your financial data.
TickerZone reads your investment holdings so it can help you track and analyze your portfolio. That access is intentionally narrow, read-only, and revocable. This page explains exactly what we can and can’t do, how we secure your data, and how to report a security issue.
What we can and can’t see
You connect a brokerage through Plaid, a regulated data network used by thousands of financial apps. Your brokerage login is entered with Plaid — never with us — so we never see or store your username or password.
What TickerZone can see
Your investment holdings and positions
Account and cash balances
The name of the institution you linked
What TickerZone cannot do
Move, transfer, or withdraw money
Place, cancel, or modify any trade
See your brokerage username or password
Pull your transaction history — we don’t request that access
How we protect your data
Encrypted in transit. All traffic to TickerZone is served over HTTPS/TLS, with HSTS enabled so browsers only ever connect securely.
Encrypted at rest. The access tokens used to read your linked accounts are encrypted in our database with rotating keys, so a database copy alone can’t read them.
Least privilege. We request read-only investment data and nothing more, and we drop products we don’t use.
No trackers, no selling. We don’t use advertising or analytics trackers, and we never sell your data.
You’re in control
Disconnect anytime. Unlinking a brokerage revokes our access token with Plaid immediately.
Delete anytime. Deleting your account from Settings → Privacy permanently erases your data, cancels your subscription, and revokes any linked-account access.
Reporting a security issue
We welcome reports from security researchers and treat them as a priority. If you believe you’ve found a vulnerability, email security@tickerzone.com with enough detail for us to reproduce it.
Safe harbor. We won’t pursue legal action against good-faith research that respects this policy and our users’ privacy.
In scope. The TickerZone web app and API.
Please don’t. Access or modify data that isn’t yours, run automated scans that degrade the Service, or publicly disclose an issue before we’ve had a chance to fix it.
What to expect. We aim to acknowledge reports within 3 business days and to keep you updated until the issue is resolved.