Privacy Policy
1) Who We Are & What This Covers
CSIMarket, Inc. operates csimarket.com and its commercial data services. For the personal information described here, CSIMarket is the controller, meaning we decide why and how it is processed, except where we act as a processor for enterprise customers (see §14).
This policy applies to:
- The website: public research pages, industry and company analytics, news and glossary.
- Accounts & subscriptions: registration, login, plan management and billing.
- Data downloads: CSV/Excel exports and bulk dataset delivery.
- The REST API: api.csimarket.com, authenticated with per-organization API keys.
- The MCP server: mcp.csimarket.com, which lets AI clients query our data on your behalf.
Questions or requests: privacy@csimarket.com.
TODO(goran): "CSIMarket, Inc." is taken from the site footer copyright line and is consistent with the Delaware governing law in the Terms. Confirm the exact registered entity name, state of incorporation and registered postal address, and publish the address here, because a controller identity and contact details are mandatory under GDPR Art. 13(1)(a).
2) Information We Collect
We collect only what the Services need to run, to bill correctly, and to keep access secure.
- Account and registration data. Username, email address, an optional website URL, and a password. Accounts are stored with a creation timestamp and a role.
- Email verification data. A hashed verification token and its expiry, plus the time verification completed.
- Subscription and plan metadata. Your plan, product, licence status, entitlements and scopes, order records, and billing country.
- Billing data. Payments are handled by Stripe on Stripe-hosted checkout and billing-portal pages. We do not operate card-entry fields anywhere on this site and card numbers never reach CSIMarket servers; we retain the customer and subscription identifiers Stripe returns, along with invoice and payment status.
- API and MCP credential identifiers. For API keys we store a SHA-256 hash of the key plus a short truncated prefix for display; we do not store the key itself in our logs. For MCP we store hashed OAuth access and refresh tokens together with the licence and user they belong to.
- API and MCP request logs. For each authenticated request: licence identifier, hashed key reference, request identifier, the endpoint path, HTTP method, response status, response time in milliseconds, IP address, and a coarse city/region/country derived from that IP. See §3 for what these logs deliberately exclude.
- Authentication logs. Sign-in attempts are recorded with the email used, whether the attempt succeeded, IP address, user agent and approximate location. This is how we detect credential stuffing and account sharing.
- Support and sales correspondence. Messages you send us and our replies, retained as a contact history.
- Cookies and device data. See §6 for the full table.
Geolocation is resolved on our own server from a locally stored MaxMind GeoLite2 database. Your IP address is not sent to a geolocation service to do this.
3) What We Do Not Collect
This matters most for the MCP server, so we state it precisely.
- We do not receive your prompts or conversation history. When your AI client calls one of our MCP tools, we receive that tool call and the parameters it carries: a ticker, an industry, a period, a screening filter. The surrounding conversation, your other messages, and anything the model said stay inside your AI client. Our MCP server contains no prompt, conversation, message or transcript capture of any kind.
- Our MCP request log does not record tool parameters. The logger records a timestamp, level, event name, HTTP method, the request path with the query string stripped, a random request identifier, the product identifier and the licence identifier. It explicitly discards any API key, authorization header, access or refresh token, client secret, password or PKCE verifier that might otherwise reach it. In production the server runs at
infolevel, so the per-request debug entries are not emitted at all. - Our API access log stores the endpoint path only: not the query string, so the specific companies or filters in a request are not retained in that table.
- We do not store API keys or MCP tokens in recoverable form. Only hashes are kept.
- We do not ask for special-category data. We have no need for health, biometric, political, religious or similar information, and ask you not to send it.
- We do not collect financial account credentials or portfolio holdings. CSIMarket is not a broker and has no brokerage connectivity.
Aggregate operational metrics count tool calls by tool name and outcome, and measure call duration. They carry no user or licence identifier.
4) How We Use Information
- Delivering the Services: serving pages, exports, API responses and MCP tool results.
- Licence and scope enforcement: checking that a request is inside the purchased plan, including per-request scope checks such as
quant.read. - Rate limiting and capacity: applying plan limits and protecting service stability.
- Abuse, fraud and security monitoring: detecting credential sharing, scraping, key compromise and automated bulk harvesting.
- Billing and account administration: subscriptions, invoices, renewals, suspensions and refunds.
- Support: answering questions and investigating faults, which is why request identifiers exist.
- Product and usage analytics: understanding which pages and datasets are used, in aggregate, to decide what to build.
- Advertising measurement: on the free, advertising-supported parts of the website (see §6).
- Legal and compliance obligations: tax and accounting records, sanctions and export compliance, and responding to lawful requests.
We do not use your account data, request logs, or MCP activity to train machine-learning models.
5) Legal Bases (EU/UK GDPR)
If you are in the EEA or the UK, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the website, subscriptions, downloads, API and MCP access | Contract (Art. 6(1)(b)) |
| Account creation, email verification, billing and invoicing | Contract (Art. 6(1)(b)) |
| Licence and scope enforcement, rate limiting | Contract; legitimate interests (Art. 6(1)(b), 6(1)(f)) |
| Security monitoring, abuse and fraud prevention, authentication logs | Legitimate interests: protecting our service and licensees (Art. 6(1)(f)) |
| Support correspondence | Contract; legitimate interests (Art. 6(1)(b), 6(1)(f)) |
| Strictly necessary cookies | Legitimate interests; exempt from consent under ePrivacy |
| Analytics, advertising and social-sharing cookies | Consent (Art. 6(1)(a); ePrivacy Art. 5(3)). See the gap noted in §6 |
| Retaining tax, accounting and transaction records | Legal obligation (Art. 6(1)(c)) |
| Responding to lawful requests and establishing or defending legal claims | Legal obligation; legitimate interests (Art. 6(1)(c), 6(1)(f)) |
Where we rely on legitimate interests, we have considered the impact on you and you may object at any time (see §11).
8) International Transfers
Our servers are located in the European Union. Several of the processors and providers above are established in the United States, so personal information may be transferred outside the EEA and the UK.
Where that happens, we rely on the transfer mechanisms those providers make available: the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and, where the recipient is certified, the EU-US and UK-US Data Privacy Framework. You may request further information about the safeguards applied to a specific transfer at privacy@csimarket.com.
TODO(goran): record, per processor, which mechanism is actually in force (SCCs on file vs DPF certification) and the date of the transfer impact assessment, so this section can name them specifically instead of describing the set.
9) Retention
We keep personal information only as long as it serves the purpose it was collected for, or as long as the law requires.
| Category | Retention |
|---|---|
| Account and profile data | For the life of the account, then deleted or anonymised on request or after a defined dormancy period. TODO(goran): set the dormancy period |
| Subscription, licence and entitlement records | For the life of the licence plus the statutory limitation period |
| Billing, invoice and tax records | As required by applicable tax and accounting law. TODO(goran): confirm the jurisdiction and the number of years |
| API and MCP request logs | TODO(goran): no retention limit is currently enforced. No pruning job exists, so these logs accumulate indefinitely. Set a period (12 months is typical for access logs) and schedule the purge before publishing a figure here. |
| Authentication logs | TODO(goran): set a period. These contain IP and user-agent data and should not be kept indefinitely |
| MCP OAuth tokens | Access tokens expire 30 minutes after issue; refresh tokens expire after 90 days; expired records are removed from the token store |
| Email verification tokens | Until used or expired |
| Support and sales correspondence | TODO(goran): set a period |
| Cookies and third-party identifiers | Controlled by each provider. See §6 |
We would rather flag these as open than publish a retention figure we do not actually enforce. Each TODO above is a commitment we intend to make concrete and then honour.
10) Security
- Encryption in transit. The website, API and MCP server are served over TLS.
- Credentials at rest. API keys are stored as SHA-256 hashes; MCP OAuth access and refresh tokens are stored hashed. Logging deliberately strips keys, tokens, authorization headers, client secrets and passwords before anything is written.
- Scope enforcement. Every API and MCP request is checked against the licence's scopes, so a credential cannot reach data outside its plan.
- Enterprise controls. IP whitelisting, HMAC request signing and scope-based access are available on enterprise plans.
- Abuse controls. Automatic rate limits, reCAPTCHA on authentication forms, a limit on login attempts per authorization request, and single-use short-lived OAuth authorization codes.
- Access control. Administrative access to production systems and databases is restricted to named personnel.
Breach notification. Where a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by GDPR Art. 33. We will also notify affected individuals without undue delay where the risk is high.
TODO(goran): confirm the contractual breach-notification window offered to enterprise customers (often 24–72 hours) so it can be stated here and kept consistent with the DPA. TODO(goran): the account-creation routine writes a column named customer_password_decoded. If any recoverable form of a customer password is being stored, that must be removed before this section's claims are accurate.
11) Your Rights
Do we sell or share personal information? We do not sell personal information for money. We do share online identifiers with Google for advertising on the free, advertising-supported parts of the website, which qualifies as a sale or sharing for cross-context behavioural advertising under the CCPA as amended by the CPRA. You can opt out. See below.
If you are in the EEA or the UK, you have the right to:
- access the personal information we hold about you;
- have inaccurate information corrected;
- have information erased, subject to legal exceptions;
- restrict processing in certain circumstances;
- receive your data in a portable, machine-readable format;
- object to processing based on legitimate interests, including profiling;
- withdraw consent at any time, without affecting processing already carried out; and
- lodge a complaint with your local supervisory authority, which in the UK is the Information Commissioner's Office.
If you are a California resident, you have the right to know what we collect and why, to access specific pieces of personal information, to delete it, to correct it, to opt out of sale or sharing for cross-context behavioural advertising, to limit the use of sensitive personal information where applicable, and not to be discriminated against for exercising any of these rights. An authorized agent may submit a request on your behalf with proof of authorization.
How to make a request. Email privacy@csimarket.com and tell us which right you are exercising. We will acknowledge promptly and respond within one month for GDPR/UK requests and within 45 days for CCPA/CPRA requests, extending only where the law allows and telling you if we do. We may need to verify your identity before acting, and we will not charge a fee except where a request is manifestly unfounded or excessive.
Until a consent-management platform is in place (§6), the most reliable way to exercise an advertising opt-out is to email us, use Google's My Ad Center controls, or send a GPC signal from your browser.
12) Automated Decision-Making
We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not carry out profiling for that purpose.
Automated logic is used only for operational controls: licence and scope validation, rate limiting, and abuse detection, for example an automatic suspension when a key shows credential-sharing patterns. These decisions concern service access under your contract, not your legal status, and you can always ask a person to review one by contacting privacy@csimarket.com.
Note that the AI client you connect to the MCP server may itself generate summaries or inferences from our data. Those outputs are produced by your AI provider, not by CSIMarket, and are informational only. See Terms of Use §9.
13) Children
The Services are intended for professional and adult users and are not directed to children. We do not knowingly collect personal information from anyone under 16 in the EEA or the UK, or under 13 in the United States. If you believe a child has provided us with personal information, contact privacy@csimarket.com and we will delete it.
14) Business & Enterprise Customers
For most of what this policy describes, CSIMarket is the controller. But where an enterprise or OEM licensee uses the API or MCP server to process personal information of its own users or clients, that licensee is the controller and CSIMarket acts as a processor on its documented instructions.
In that role we process only as instructed, keep the confidentiality obligations described in §10, assist with data-subject requests and breach notification, and return or delete the data at the end of the engagement.
A Data Processing Agreement incorporating the Standard Contractual Clauses is available for enterprise licensees. Request one at data.info@csimarket.com.
Enterprise customers remain responsible for the lawfulness of the data they send us and for how their own AI clients and end users handle our responses.
TODO(goran): confirm that a signed DPA template actually exists and publish a direct link here; if not, this paragraph promises something we cannot yet deliver.
15) Changes to This Policy
We may update this policy by posting a revised version at this URL with a new effective date. If a change materially affects how we use your personal information, we will give notice, by email to account holders or by a prominent notice on the site, before it takes effect.
Effective date: August 24, 2026
16) Contact
- Privacy questions, rights requests and data corrections: privacy@csimarket.com
- Licensing, redistribution, OEM, API/MCP commercial terms and DPAs: data.info@csimarket.com
- Legal notices: legal@csimarket.com
- Content and data accuracy corrections: article@csimarket.com
- Product faults, keys and troubleshooting: Customer Support
TODO(goran): if CSIMarket has no establishment in the EEA or the UK but offers services to individuals there, an Article 27 representative must be appointed and named here (EU and UK are separate appointments). Do not publish a name until one is actually engaged. TODO(goran): confirm whether a Data Protection Officer is required. Likely not, given we do not carry out large-scale monitoring of individuals or process special-category data, and record that assessment.
On this page
privacy@csimarket.com