Privacy Policy
A plain-English rundown of what we collect, why, and how you stay in control. Written by the team that builds and runs MarketsEasy — not a legal template.
01Who we are
MarketsEasy is built and run by a small team based in India, operating the site at marketseasy.in. There is no VC funding, no data-broking business behind it. We started it because we wanted a free, honest tool for Indian F&O traders that wasn't buried in ads or upsells.
When this policy says "we" or "us," it refers to the team that builds and operates MarketsEasy. If something in this policy is unclear, email us at marketseasy.dev@gmail.com and we'll answer within a few days.
This policy applies to everyone who visits marketseasy.in — whether or not you sign in. Using the site means you're okay with what's described here.
02What we collect
Only the minimum needed to run the site. We're listing everything, including things people usually skip.
Google account basics — only if you sign in
Your name, email address, and profile picture from Google. We never see your Google password, never store it, and can't reset it. Sign-in is optional — most features (option chain, OI tracker, news, calculators) work without it.
Things you save on the site
Watchlist symbols, saved indices, keyword alerts you create, theme preference (dark/light), and similar settings. These are tied to your account so you get them back on any device.
Basic analytics
Which pages get visited, how long people stay, what device/browser they used, and rough location (country/region — not street address). This is aggregate data used to figure out which features actually help people and which ones nobody uses.
IP address & user-agent (contact form + admin audit trail)
When you submit the contact form or an admin action is performed, we log the IP address and browser user-agent along with the message. This is for security (spam, abuse) and support (matching a complaint to a specific submission). Standard web server logs also contain IP + request paths for the same reasons.
Signup source (referrer + UTM tags)
When you sign up, we capture the referring URL and UTM parameters if present (e.g. whether you came from a Google search, ChatGPT, a blog, etc.). This is aggregate marketing analytics — it doesn't change how you use the site.
03Why we collect it
Straight list of what your data is used for:
- Sign you in and remember your watchlist, alerts, and preferences across devices
- Send the daily digest email if you opted in (unsubscribe link in every email)
- Answer contact-form messages you send
- Find bugs, understand which features get used, and decide what to build next
- Stop bots, abuse, and rate-limit misuse of the free AI features
- Comply with anything Indian law actually requires us to comply with
We do not sell your data. We do not use your data to train AI models. We do not build behavioural profiles to resell. If those things ever change, this policy will change first, and you'll get an email.
04Legal basis under DPDP Act 2023
India's Digital Personal Data Protection Act, 2023 (DPDP Act) applies to how we handle your data. For each activity, the lawful basis we rely on is:
- Consent — when you sign in with Google, opt into the daily digest, or fill in the contact form. You can withdraw consent at any time (unsubscribe / delete account / stop using the site).
- Legitimate use — for security, fraud prevention, and analytics needed to keep the site running. Under the DPDP Act, this covers the minimum operational logging described in Section 2.
- Compliance with law — when Indian law (including the Information Technology Act, 2000 and the SPDI Rules, 2011) requires disclosure or retention.
If you're outside India, equivalent laws (GDPR in the EU, UK GDPR, CCPA in California, etc.) may also apply and give you similar rights, which we honour in the same way.
05AI processing
Several MarketsEasy features are powered by third-party large language models. Here's exactly what happens:
- When you use the AI Trading Assistant, click AI Suggestion on a stock page, or trigger any AI feature, MarketsEasy sends the necessary market data + a short prompt to one of the following AI providers to generate a response: Groq, Google Gemini, Cerebras, OpenRouter, or NVIDIA (whichever answers fastest via our fallback chain).
- The prompts contain the market data (indices, option chain, news headlines) and — for signed-in features — your user ID (not your name or email) for rate limiting. Providers are contractually barred from using this data to train their models.
- AI responses are cached briefly on our servers to keep costs down. Cached responses expire within 2 minutes for live analysis and 24 hours for slower-changing content.
- The ChatBot on the site also uses these providers — do not paste sensitive personal information (PAN, Aadhaar, account numbers, passwords) into it. Anything you type is sent to the AI provider.
If you'd rather not have prompts sent to AI providers, avoid the AI features — the option chain, OI tracker, screener, calculators, and news feed all work without them.
08How long we keep it
- Account data — as long as your account is active. On deletion request: within 30 days.
- Contact form submissions — up to 24 months (for support follow-up + spam tracking).
- Admin audit log — up to 24 months.
- Server logs — 30 to 90 days (depending on the hosting layer).
- Analytics — Google Analytics' default 14-month retention.
- AI response cache — 2 minutes to 24 hours.
09Your rights
Under the DPDP Act (and equivalent laws in other countries), you can:
- Ask for a copy of the data we hold about you
- Ask us to correct anything wrong
- Ask us to delete your account and everything tied to it
- Withdraw consent for the daily digest (one-click unsubscribe in every email)
- Nominate a person to exercise these rights on your behalf if you can't (DPDP Act Section 14)
- Complain to the Data Protection Board of India (or your local authority) if you think we've mishandled something
Just email marketseasy.dev@gmail.com or use the contact page. We aim to respond within 7 days and complete the action within 30.
10Security
We take security seriously because we'd be equally upset if our data leaked from a site we used. In practice:
- HTTPS everywhere — enforced via HSTS.
- Session cookies are signed and HTTP-only. No plaintext passwords are ever stored (sign-in is delegated to Google).
- Database access uses connection pooling with least-privilege credentials.
- API keys are rotated when incidents are suspected.
- Public endpoints have rate limits to make bulk scraping expensive.
11Where the data lives
Our database is hosted on Supabase's Mumbai (ap-south-1) region so most personal data stays inside India. Some providers (Vercel edge, Google Analytics, the AI providers, Brevo) operate global infrastructure and may process your data in other jurisdictions including the EU and the US. Standard contractual clauses and each provider's own compliance frameworks apply to those transfers.
12Children
MarketsEasy is meant for adult traders. We do not knowingly collect data from anyone under 18. If you're a parent/guardian and you believe your child signed up, email us and we'll delete the account within a few days.
13Changes to this policy
Privacy policies date. If we change how data is handled, we'll update the "Last updated" date at the top and (for anything material — new data being collected, new sharing) send a heads-up to signed-in users. Small clarifications don't get an email. Continuing to use the site after a change means you accept the update.
14Contact
Any question, complaint, or data-rights request — please email us directly:
marketseasy.dev@gmail.comOr use the contact page. We read every message ourselves.