Last updated: October 7, 2026
This policy explains what personal information Yinly LLC ("Yinly", "we", "us") collects, why, and what control you have over it. It covers getyinly.com and our subscription service.
We have written it to describe what we actually do, not a generic template. If something below is not listed, we do not do it.
You give us:
| Data | Why | Where it lives |
|---|---|---|
| Email address | Account identity, activation and account emails, receipts, service notices, support | Supabase, Stripe, Resend (for delivery), Google Workspace |
| TradingView username | Required — it is the key we grant indicator access to | Supabase |
| Password | Signing in. Stored only as a hash by Supabase Auth; we never see it | Supabase |
| Google account email, if you sign in with Google | Signing in | Supabase |
| Support correspondence | To answer you and keep a record | Google Workspace |
| Billing name, address and country | Entered in the Stripe payment form at checkout; used by Stripe for tax and fraud checks | Stripe |
| Card details | Entered in the Stripe payment form and sent directly to Stripe. Never received or stored by Yinly | Stripe |
Created when you use the Service (account, membership, purchase and billing records):
Collected automatically:
| Data | Why | Where it lives |
|---|---|---|
| Server and security logs, including IP address | Security, abuse prevention, debugging. Kept 30 days | Vercel (website), Supabase (authentication and database) |
| Rate-limit records | Preventing abuse of sign-in, checkout and account endpoints. A keyed hash of your IP address or email address, the endpoint, and the time — not the address itself | Supabase |
| Website usage and performance measurements: page paths, referring pages, browser and device information, country, and page-load measurements | Understanding website traffic and improving performance | Cloudflare Web Analytics |
Cloudflare Web Analytics does not use cookies or browser storage to track visitors across websites. Cloudflare states that it does not log URL query strings. We do not send account email addresses, TradingView usernames, passwords, or payment details as analytics events.
From Stripe: subscription status, plan, billing period, payment success or failure, and refund and dispute status. We use this to keep your access current. In Stripe's dashboard we can also see your billing name and address and the card brand and last four digits, which we use only for billing support.
We want to be explicit, because policies copied from other companies routinely claim otherwise:
| Purpose | Legal basis |
|---|---|
| Provide the Service; create your account after payment; grant, maintain, and revoke your indicator access | Performance of a contract |
| Take payment and manage your subscription | Performance of a contract |
| Send transactional email — activation links, purchase and account notices, receipts, renewal and price notices, access changes, outages | Performance of a contract |
| Answer support requests | Performance of a contract |
| Prevent fraud, abuse, duplicate purchases, and access sharing; keep the Service secure | Legitimate interests |
| Meet tax, accounting, and other legal obligations | Legal obligation |
| Send marketing email, if you opt in | Consent |
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not profile you.
We also use aggregate website traffic and performance reports to understand how our website is used and where its performance can be improved.
We share personal information only with the service providers that make the business run, and only what each needs to provide its service to us under contract. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. Disclosures to the providers below are disclosures to service providers or processors, not sales and not sharing for advertising, as those terms are used in California and EU law.
| Provider | Role | Data |
|---|---|---|
| Stripe | Payment processing, subscriptions, and the customer portal. Stripe's payment form is embedded in our checkout page | Email, billing name and address, card details (entered directly into Stripe's form), payment and subscription data |
| Supabase | Authentication (sign-in, password reset, Google sign-in) and our database | Email, password hash, TradingView username, and the account, membership, purchase, email-delivery and rate-limit records in Section 2 |
| Resend | Sends our transactional email (activation links, purchase and account notices) | Your email address and the content of those messages |
| Vercel | Hosts the website | Server logs, IP address |
| Cloudflare Web Analytics | Website traffic and performance reports | Page paths, referring pages, browser and device information, country, and performance measurements; no account or payment details are sent as analytics events |
| Google Workspace | Business email and support | Email address, correspondence |
| TradingView | Delivers the indicator | Your TradingView username, so we can grant and revoke access |
We may also disclose information where required by law, valid legal process, or to protect our rights, safety, or property — and, if we ever sell or merge the business, to the acquirer, with notice to you.
Note on TradingView: because access is delivered on their platform, your TradingView username is visible to us and access grants are recorded there. Your use of TradingView itself is governed by TradingView's own privacy policy, which we do not control.
After that we delete it or irreversibly anonymise it.
Everyone. You can ask us to give you a copy of your data, correct it, delete it, or stop marketing to you. Email support@getyinly.com. We respond within 30 days. We will not discriminate against you for exercising these rights.
California (CCPA/CPRA). You have the right to know the categories and specific pieces of personal information we collect, the sources, the purpose, and who receives it; to delete it; to correct it; to opt out of sale or sharing; and to limit the use of sensitive personal information. We do not sell or share personal information, so there is nothing to opt out of — but the right exists and you may exercise it. The only sensitive personal information we handle is your account password (held as a hash by Supabase Auth) and, through Stripe, your card details; we use them only to sign you in and take payment, never to infer anything about you, so the right to limit does not apply to that use. You may use an authorised agent.
EEA and UK (GDPR). You additionally have the right to restrict or object to processing, the right to data portability, the right to withdraw consent at any time, and the right to complain to your supervisory authority — in the UK, the Information Commissioner's Office.
International transfers. Yinly operates in the United States and our providers are largely US-based, so your data will be processed there. Where we transfer personal data out of the EEA or UK we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with the relevant provider.
We use only the cookies needed to run the site. Cloudflare Web Analytics measures website traffic and performance without cookies or browser storage, and we set no advertising or tracking cookies.
| Cookie | Purpose | Lifetime |
|---|---|---|
| Sign-in session (set by Supabase Auth) | Keeps you signed in to your account | While you are signed in |
| Checkout cookie | Ties a guest checkout to the browser it was started in, so that only that browser can resume or change it | 24 hours, extended to 7 days once a payment is made |
| Password-reset cookie | Confirms that a password reset came from a reset email | 15 minutes |
These are strictly necessary, first-party, and never used for tracking. Stripe's embedded payment form on our checkout page, and Stripe's customer portal, set Stripe's own cookies for fraud prevention and session handling, governed by Stripe's privacy policy.
We do not run advertising, retargeting, or social media pixels, and we do not respond to Do Not Track signals because no common standard for them exists. We honour Global Privacy Control signals where required by law.
We use encryption in transit, access controls, multi-factor authentication on administrative accounts, and providers who maintain recognised security standards. Passwords are stored only as hashes by Supabase Auth. Activation and password-reset links are single-use and expire. Sign-in, checkout and account endpoints are rate-limited using keyed hashes rather than raw addresses. Keeping card data entirely with Stripe is itself a deliberate security decision — data we never hold cannot be taken from us.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information we will notify you and the relevant authorities as required by law, including California's breach notification statute and, where applicable, the GDPR's 72-hour rule.
We send service messages — activation links, receipts, renewal notices, access changes — as part of the contract; you cannot opt out of those while you subscribe.
Marketing email is separate and opt-in. Every marketing message has an unsubscribe link that works, and we honour it promptly.
If we change this policy materially we will email subscribers and update the date above before the change takes effect. The current version always lives at https://getyinly.com/privacy.
Questions, requests, or complaints:
Read together with the Terms of Service, Risk Disclosure, and Billing and Cancellation Policy.