Privacy Policy

Updated: August 24, 2026
This Privacy Policy explains what personal information CSIMarket collects, why we collect it, who we share it with, and the choices and rights you have. It covers our website, accounts and subscriptions, data downloads, the licensed REST API, and the MCP server. It sits alongside our Terms of Use, which govern how the Services themselves may be used.

1) Who We Are & What This Covers

CSIMarket, Inc. operates csimarket.com and its commercial data services. For the personal information described here, CSIMarket is the controller, meaning we decide why and how it is processed, except where we act as a processor for enterprise customers (see §14).

This policy applies to:

  • The website: public research pages, industry and company analytics, news and glossary.
  • Accounts & subscriptions: registration, login, plan management and billing.
  • Data downloads: CSV/Excel exports and bulk dataset delivery.
  • The REST API: api.csimarket.com, authenticated with per-organization API keys.
  • The MCP server: mcp.csimarket.com, which lets AI clients query our data on your behalf.

Questions or requests: privacy@csimarket.com.

TODO(goran): "CSIMarket, Inc." is taken from the site footer copyright line and is consistent with the Delaware governing law in the Terms. Confirm the exact registered entity name, state of incorporation and registered postal address, and publish the address here, because a controller identity and contact details are mandatory under GDPR Art. 13(1)(a).

2) Information We Collect

We collect only what the Services need to run, to bill correctly, and to keep access secure.

  • Account and registration data. Username, email address, an optional website URL, and a password. Accounts are stored with a creation timestamp and a role.
  • Email verification data. A hashed verification token and its expiry, plus the time verification completed.
  • Subscription and plan metadata. Your plan, product, licence status, entitlements and scopes, order records, and billing country.
  • Billing data. Payments are handled by Stripe on Stripe-hosted checkout and billing-portal pages. We do not operate card-entry fields anywhere on this site and card numbers never reach CSIMarket servers; we retain the customer and subscription identifiers Stripe returns, along with invoice and payment status.
  • API and MCP credential identifiers. For API keys we store a SHA-256 hash of the key plus a short truncated prefix for display; we do not store the key itself in our logs. For MCP we store hashed OAuth access and refresh tokens together with the licence and user they belong to.
  • API and MCP request logs. For each authenticated request: licence identifier, hashed key reference, request identifier, the endpoint path, HTTP method, response status, response time in milliseconds, IP address, and a coarse city/region/country derived from that IP. See §3 for what these logs deliberately exclude.
  • Authentication logs. Sign-in attempts are recorded with the email used, whether the attempt succeeded, IP address, user agent and approximate location. This is how we detect credential stuffing and account sharing.
  • Support and sales correspondence. Messages you send us and our replies, retained as a contact history.
  • Cookies and device data. See §6 for the full table.

Geolocation is resolved on our own server from a locally stored MaxMind GeoLite2 database. Your IP address is not sent to a geolocation service to do this.

3) What We Do Not Collect

This matters most for the MCP server, so we state it precisely.

  • We do not receive your prompts or conversation history. When your AI client calls one of our MCP tools, we receive that tool call and the parameters it carries: a ticker, an industry, a period, a screening filter. The surrounding conversation, your other messages, and anything the model said stay inside your AI client. Our MCP server contains no prompt, conversation, message or transcript capture of any kind.
  • Our MCP request log does not record tool parameters. The logger records a timestamp, level, event name, HTTP method, the request path with the query string stripped, a random request identifier, the product identifier and the licence identifier. It explicitly discards any API key, authorization header, access or refresh token, client secret, password or PKCE verifier that might otherwise reach it. In production the server runs at info level, so the per-request debug entries are not emitted at all.
  • Our API access log stores the endpoint path only: not the query string, so the specific companies or filters in a request are not retained in that table.
  • We do not store API keys or MCP tokens in recoverable form. Only hashes are kept.
  • We do not ask for special-category data. We have no need for health, biometric, political, religious or similar information, and ask you not to send it.
  • We do not collect financial account credentials or portfolio holdings. CSIMarket is not a broker and has no brokerage connectivity.

Aggregate operational metrics count tool calls by tool name and outcome, and measure call duration. They carry no user or licence identifier.

4) How We Use Information

  • Delivering the Services: serving pages, exports, API responses and MCP tool results.
  • Licence and scope enforcement: checking that a request is inside the purchased plan, including per-request scope checks such as quant.read.
  • Rate limiting and capacity: applying plan limits and protecting service stability.
  • Abuse, fraud and security monitoring: detecting credential sharing, scraping, key compromise and automated bulk harvesting.
  • Billing and account administration: subscriptions, invoices, renewals, suspensions and refunds.
  • Support: answering questions and investigating faults, which is why request identifiers exist.
  • Product and usage analytics: understanding which pages and datasets are used, in aggregate, to decide what to build.
  • Advertising measurement: on the free, advertising-supported parts of the website (see §6).
  • Legal and compliance obligations: tax and accounting records, sanctions and export compliance, and responding to lawful requests.

We do not use your account data, request logs, or MCP activity to train machine-learning models.

6) Cookies & Tracking

The public website is advertising-supported and carries third-party analytics, advertising and sharing scripts. The API and the MCP server are machine-to-machine interfaces and set no cookies at all.

Current status: please read. CSIMarket does not presently operate a cookie-consent banner or consent-management platform. The analytics, advertising and sharing technologies listed below therefore load when you visit the public website, rather than after you have given consent. We are addressing this; in the meantime you can control them with the browser and provider opt-outs described at the end of this section, and the choices in §11 remain available to you.

What loads on the public site:

TechnologyProviderPurpose CategoryParty
PHPSESSIDCSIMarketKeeps you signed in and preserves page state for the browser sessionStrictly necessaryFirst
Google Analytics 4 (G-XH70B07PYX)GoogleMeasures visits, pages and traffic sourcesAnalyticsThird
Google Tag Manager (GTM-PB8NTMC)GoogleDelivers tags on the homepage and glossary indexAnalyticsThird
Google AdSense (ca-pub-8061702267227905)GoogleServes and measures advertising; loaded only for signed-out visitorsAdvertisingThird
ShareaholicShareaholicShare and follow buttons, and their usage measurementAnalytics / MarketingThird
Google reCAPTCHAGoogleBlocks automated sign-in and registration abuseStrictly necessary (security)Third
StripeStripeFraud prevention on checkout and billing-portal pagesStrictly necessary (payments)Third
Universal Analytics (UA-35686840-1)GoogleLegacy measurement tags still present on older pages; the service is retired and no longer processes dataAnalytics (inactive)Third

Cookie lifetimes are set by each provider and change without notice, so we describe purpose and category rather than quoting durations we cannot guarantee. TODO(goran): commission a runtime cookie audit (real browser, signed-out and signed-in) to record the exact cookie names and durations actually observed, and publish them in this table.

Your choices. You can block or delete cookies in your browser; strictly necessary cookies are required for sign-in to work. You can opt out of Google Analytics with Google's browser add-on, and manage Google advertising personalisation at My Ad Center. Signing in to a paid account removes advertising from the pages you view.

If your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out request where legally required.

7) Sharing & Processors

We do not sell personal information for money. The parties below are the ones that actually receive data through the Services. There are no others.

RecipientRoleWhat they receive & why
StripeProcessorName, email, billing country and payment details you enter on Stripe-hosted pages, to take payment and manage subscriptions
Google (Analytics, Tag Manager)Processor / independent controllerOnline identifiers, IP address, pages viewed, used to measure website usage
Google (AdSense)Independent controllerOnline identifiers, IP address and page context, used to serve and measure advertising. Under CCPA/CPRA this counts as sharing for cross-context behavioural advertising; see §11
Google (reCAPTCHA)ProcessorDevice and interaction signals on the sign-in and registration forms, to distinguish humans from bots
ShareaholicIndependent controllerOnline identifiers and page context, to power share/follow widgets
OVHProcessor (hosting)Hosts our servers and databases; has infrastructure-level access only
Content delivery networks (jsDelivr, cdnjs, Google Fonts)Independent controllersReceive your IP address and user agent when your browser fetches shared assets. jsDelivr (Bootstrap) and cdnjs (Font Awesome) are requested on most pages, including this one; Google Fonts on sign-in and dashboard pages
Professional advisers, auditors, and authoritiesControllersOnly where required by law, or to establish or defend legal claims

Your AI client and its provider. When you use the MCP server, the tool results we return are delivered into the AI client you chose, for example Claude or ChatGPT. Once our response reaches that client it is handled under that provider's privacy policy, not ours. Choosing which AI provider to connect is your decision, and we have no visibility or control over what happens to the data after delivery.

Business transfers. If CSIMarket is involved in a merger, acquisition or sale of assets, personal information may transfer as part of that transaction; we will give notice before your information becomes subject to a different privacy policy.

TODO(goran): confirm whether Google Analytics is configured under Google's controller or processor terms for our property, and whether an EU/UK data-processing addendum has been accepted for each of Stripe, Google and Shareaholic. The answers change the §8 transfer wording.

8) International Transfers

Our servers are located in the European Union. Several of the processors and providers above are established in the United States, so personal information may be transferred outside the EEA and the UK.

Where that happens, we rely on the transfer mechanisms those providers make available: the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and, where the recipient is certified, the EU-US and UK-US Data Privacy Framework. You may request further information about the safeguards applied to a specific transfer at privacy@csimarket.com.

TODO(goran): record, per processor, which mechanism is actually in force (SCCs on file vs DPF certification) and the date of the transfer impact assessment, so this section can name them specifically instead of describing the set.

9) Retention

We keep personal information only as long as it serves the purpose it was collected for, or as long as the law requires.

CategoryRetention
Account and profile dataFor the life of the account, then deleted or anonymised on request or after a defined dormancy period. TODO(goran): set the dormancy period
Subscription, licence and entitlement recordsFor the life of the licence plus the statutory limitation period
Billing, invoice and tax recordsAs required by applicable tax and accounting law. TODO(goran): confirm the jurisdiction and the number of years
API and MCP request logsTODO(goran): no retention limit is currently enforced. No pruning job exists, so these logs accumulate indefinitely. Set a period (12 months is typical for access logs) and schedule the purge before publishing a figure here.
Authentication logsTODO(goran): set a period. These contain IP and user-agent data and should not be kept indefinitely
MCP OAuth tokensAccess tokens expire 30 minutes after issue; refresh tokens expire after 90 days; expired records are removed from the token store
Email verification tokensUntil used or expired
Support and sales correspondenceTODO(goran): set a period
Cookies and third-party identifiersControlled by each provider. See §6

We would rather flag these as open than publish a retention figure we do not actually enforce. Each TODO above is a commitment we intend to make concrete and then honour.

10) Security

  • Encryption in transit. The website, API and MCP server are served over TLS.
  • Credentials at rest. API keys are stored as SHA-256 hashes; MCP OAuth access and refresh tokens are stored hashed. Logging deliberately strips keys, tokens, authorization headers, client secrets and passwords before anything is written.
  • Scope enforcement. Every API and MCP request is checked against the licence's scopes, so a credential cannot reach data outside its plan.
  • Enterprise controls. IP whitelisting, HMAC request signing and scope-based access are available on enterprise plans.
  • Abuse controls. Automatic rate limits, reCAPTCHA on authentication forms, a limit on login attempts per authorization request, and single-use short-lived OAuth authorization codes.
  • Access control. Administrative access to production systems and databases is restricted to named personnel.

Breach notification. Where a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by GDPR Art. 33. We will also notify affected individuals without undue delay where the risk is high.

TODO(goran): confirm the contractual breach-notification window offered to enterprise customers (often 24–72 hours) so it can be stated here and kept consistent with the DPA. TODO(goran): the account-creation routine writes a column named customer_password_decoded. If any recoverable form of a customer password is being stored, that must be removed before this section's claims are accurate.

11) Your Rights

Do we sell or share personal information? We do not sell personal information for money. We do share online identifiers with Google for advertising on the free, advertising-supported parts of the website, which qualifies as a sale or sharing for cross-context behavioural advertising under the CCPA as amended by the CPRA. You can opt out. See below.

If you are in the EEA or the UK, you have the right to:

  • access the personal information we hold about you;
  • have inaccurate information corrected;
  • have information erased, subject to legal exceptions;
  • restrict processing in certain circumstances;
  • receive your data in a portable, machine-readable format;
  • object to processing based on legitimate interests, including profiling;
  • withdraw consent at any time, without affecting processing already carried out; and
  • lodge a complaint with your local supervisory authority, which in the UK is the Information Commissioner's Office.

If you are a California resident, you have the right to know what we collect and why, to access specific pieces of personal information, to delete it, to correct it, to opt out of sale or sharing for cross-context behavioural advertising, to limit the use of sensitive personal information where applicable, and not to be discriminated against for exercising any of these rights. An authorized agent may submit a request on your behalf with proof of authorization.

How to make a request. Email privacy@csimarket.com and tell us which right you are exercising. We will acknowledge promptly and respond within one month for GDPR/UK requests and within 45 days for CCPA/CPRA requests, extending only where the law allows and telling you if we do. We may need to verify your identity before acting, and we will not charge a fee except where a request is manifestly unfounded or excessive.

Until a consent-management platform is in place (§6), the most reliable way to exercise an advertising opt-out is to email us, use Google's My Ad Center controls, or send a GPC signal from your browser.

12) Automated Decision-Making

We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not carry out profiling for that purpose.

Automated logic is used only for operational controls: licence and scope validation, rate limiting, and abuse detection, for example an automatic suspension when a key shows credential-sharing patterns. These decisions concern service access under your contract, not your legal status, and you can always ask a person to review one by contacting privacy@csimarket.com.

Note that the AI client you connect to the MCP server may itself generate summaries or inferences from our data. Those outputs are produced by your AI provider, not by CSIMarket, and are informational only. See Terms of Use §9.

13) Children

The Services are intended for professional and adult users and are not directed to children. We do not knowingly collect personal information from anyone under 16 in the EEA or the UK, or under 13 in the United States. If you believe a child has provided us with personal information, contact privacy@csimarket.com and we will delete it.

14) Business & Enterprise Customers

For most of what this policy describes, CSIMarket is the controller. But where an enterprise or OEM licensee uses the API or MCP server to process personal information of its own users or clients, that licensee is the controller and CSIMarket acts as a processor on its documented instructions.

In that role we process only as instructed, keep the confidentiality obligations described in §10, assist with data-subject requests and breach notification, and return or delete the data at the end of the engagement.

A Data Processing Agreement incorporating the Standard Contractual Clauses is available for enterprise licensees. Request one at data.info@csimarket.com.

Enterprise customers remain responsible for the lawfulness of the data they send us and for how their own AI clients and end users handle our responses.

TODO(goran): confirm that a signed DPA template actually exists and publish a direct link here; if not, this paragraph promises something we cannot yet deliver.

15) Changes to This Policy

We may update this policy by posting a revised version at this URL with a new effective date. If a change materially affects how we use your personal information, we will give notice, by email to account holders or by a prominent notice on the site, before it takes effect.

Effective date: August 24, 2026

16) Contact

TODO(goran): if CSIMarket has no establishment in the EEA or the UK but offers services to individuals there, an Article 27 representative must be appointed and named here (EU and UK are separate appointments). Do not publish a name until one is actually engaged. TODO(goran): confirm whether a Data Protection Officer is required. Likely not, given we do not carry out large-scale monitoring of individuals or process special-category data, and record that assessment.