Privacy Policy
We try to collect as little as possible and to be specific about what we do collect, who processes it, and what we never do with it. This policy covers 13f.mapperlab.co (the “Service”).
1. Effective date
This policy is effective June 3, 2026. If we make material changes we'll update this date and, where reasonable, notify signed-in users.
2. What we collect
The Service collects only what it needs to function:
- Email address — required for sign-in (via Clerk) and used as the destination for any fund alerts you subscribe to. We also store it in Vercel KV to drive the alerts pipeline.
- Display name (optional) — only if you set one in your Clerk profile.
- IP address and basic request metadata— captured by Vercel's server logs (origin IP, user agent, requested path, timestamp) for security, abuse prevention, and debugging. Vercel rotates these logs on its own retention schedule.
- Authentication cookies — set by Clerk to keep you signed in. We do not set additional analytics or advertising cookies.
- Your watchlist — the fund CIKs and stock tickers you star, stored in Vercel KV under your user ID so we can sync them across your devices.
- Your alert subscriptions— the fund CIKs you've asked to receive emails about, stored in Vercel KV together with your email so the alerts cron can deliver them.
We do not currently collect any payment information — the Service is free today. If we add paid features later we will update this policy and route payment data through a regulated processor.
3. How we use it
The data above is used only for:
- Authentication — verifying your identity and keeping you signed in across devices (Clerk).
- Service features — persisting your watchlist and alert preferences, and rendering personalized views like /watchlist.
- Email alerts — delivering the fund updates you subscribed to, via Resend, with a one-click unsubscribe link in every message.
- Security, abuse prevention, and debugging — for example, investigating an error in server logs or rate-limiting abusive traffic.
We don't profile you for advertising, sell your data, or use it to train third-party machine-learning models.
4. Who we share it with
The Service is built on a small set of named processors. We share only what each one needs to do its job:
- Clerk Inc. — authentication. Receives your email, optional display name, and session activity. See clerk.com privacy policy.
- Vercel Inc. — hosting (Next.js runtime), edge network, and Vercel KV for your watchlist and alert subscriptions. Receives your IP address, request logs, and the stored watchlist/alert records. See vercel.com privacy policy.
- Resend — transactional email delivery for fund alerts. Receives your email address, the subject and body of each alert, and standard delivery metadata. See resend.com privacy policy.
We may also disclose information when required by law (subpoena, court order, regulatory request) or when necessary to investigate or prevent abuse, fraud, or imminent harm. If we ever sell the business or merge with another company, your data may transfer to the acquirer subject to a privacy policy at least as protective as this one.
We fetch from SEC EDGAR and other public data sources; those sources receive normal server-to-server request metadata (originating from our infrastructure, not from your browser) and no information about you.
5. What we don't do
We don't sell your data. We don't share it with data brokers. We don't run advertising on the Service and we don't embed third-party advertising or analytics tags. There are no Facebook pixels, no Google Analytics, no LinkedIn Insight tags, no session-replay scripts.
We don't use your data to train third-party AI models, and we don't share your watchlist with other users.
6. Cookies
The only cookies the Service sets are the session cookies Clerk uses to keep you signed in. They are first-party, secure, and expire when your Clerk session ends. We don't use advertising, analytics, or cross-site tracking cookies. Because there are no such cookies, the Service does not display a cookie consent banner; the Clerk session cookies are strictly necessary for authentication and do not require consent under typical EU/UK rules.
7. Your rights
You can exercise the following at any time:
- Delete your account. Use the Clerk user portal to delete your account; doing so removes your authentication record at Clerk and triggers deletion of your watchlist and alert records in Vercel KV.
- Export your watchlist. The /watchlist page shows your full watchlist; you can copy it or take a screenshot at any time.
- Unsubscribe from email. Every alert email includes a one-click unsubscribe link. You can also remove individual fund alerts from your watchlist UI.
- Access, correct, or restrict processing.Email us and we'll respond. If you're in the EU, UK, California, or another jurisdiction with statutory data-subject rights (GDPR / UK GDPR / CCPA / CPRA), the same address handles those requests. We don't discriminate against users who exercise privacy rights.
8. Data retention
We keep account data for as long as your account exists. When you delete your account, the corresponding records in Vercel KV (watchlist, alert subscriptions, alert dispatch history) are removed; certain alerts records carry a Vercel KV time-to-live and expire automatically on that schedule even before deletion. Server logs (IP address, request paths) are retained on Vercel's standard rotation and are not associated with your user ID after deletion. Resend retains delivery records on its own rotation, which we do not control.
We may retain anonymized or aggregated data (counts, error rates) indefinitely; that data cannot be tied back to you.
9. Children
The Service is not intended for children under 13, and we don't knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, please contact us and we'll delete it.
10. International users
The Service is operated from the United States. Our primary Vercel region is iad1 (US East). If you access the Service from outside the US, your information will be transferred to, stored, and processed in the US (and may transit other regions through Vercel's edge network). By using the Service you consent to that transfer.
Our subprocessors (Clerk, Vercel, Resend) are US-based companies that operate global infrastructure; consult their privacy policies for the data-transfer mechanisms they rely on.
11. Changes to this policy
We'll update this policy when our practices change. For material changes we'll update the effective date at the top and, where reasonable, notify signed-in users by email or via an in-product notice before the change takes effect.
12. Contact
Questions? Email hello@mapperlab.co. We try to answer within a few business days.
For the legal framework around use of the Service, see our Terms of Service.