Yinly

Privacy Policy

Last updated: October 7, 2026

This policy explains what personal information Yinly LLC ("Yinly", "we", "us") collects, why, and what control you have over it. It covers getyinly.com and our subscription service.

We have written it to describe what we actually do, not a generic template. If something below is not listed, we do not do it.


1. The short version

  • We collect what a paid membership needs: your email address, your TradingView username, your account sign-in details, and the account, membership, purchase and billing records described in Section 2.
  • Your card details go to Stripe, not to us. The payment form on our checkout page is Stripe's own embedded component; what you type into it is sent directly to Stripe. Yinly's systems never receive or store card numbers. We do receive limited billing information from Stripe (Section 2).
  • We do not sell or share your personal information for advertising, and we set no advertising pixels. We use Cloudflare Web Analytics to understand website traffic and performance without analytics cookies.
  • We do not ask about your finances, holdings, income, or investment goals — deliberately, because Yinly is an impersonal tool and does not give personal advice.
  • Our service providers are Stripe, Supabase, Resend, Vercel, Cloudflare, Google Workspace, and TradingView (Section 5).

2. What we collect

You give us:

DataWhyWhere it lives
Email addressAccount identity, activation and account emails, receipts, service notices, supportSupabase, Stripe, Resend (for delivery), Google Workspace
TradingView usernameRequired — it is the key we grant indicator access toSupabase
PasswordSigning in. Stored only as a hash by Supabase Auth; we never see itSupabase
Google account email, if you sign in with GoogleSigning inSupabase
Support correspondenceTo answer you and keep a recordGoogle Workspace
Billing name, address and countryEntered in the Stripe payment form at checkout; used by Stripe for tax and fraud checksStripe
Card detailsEntered in the Stripe payment form and sent directly to Stripe. Never received or stored by YinlyStripe

Created when you use the Service (account, membership, purchase and billing records):

  • Account records: a Yinly account identifier, the date the account was created, and when your email was confirmed and your account activated.
  • Membership records: your Stripe customer identifier and subscription identifier, subscription status, plan, current billing period end, whether a cancellation is scheduled, whether TradingView access has been granted, and any TradingView username change request you submit.
  • Purchase records: for each checkout you start, an order record with the email address and TradingView username you entered and the plan you chose, together with the Stripe checkout session identifier. Once paid, it also holds the Stripe customer, subscription, invoice and price identifiers, the amount and currency, and timestamps. A purchase record is created before your account exists, because the account is created only after payment. Paid purchase records are part of our billing records.
  • Payment history: the date, description, amount and status of your invoices, read from Stripe when you open your account page.
  • Email delivery records: for each transactional email we send you — recipient address, type of message, timestamps, delivery status and the provider's message identifier. For activation emails we also keep an encrypted copy of the link so that a failed send can be retried without invalidating it.
  • Payment notifications: the notifications Stripe sends us about your payments and subscription, kept so that they can be processed reliably.

Collected automatically:

DataWhyWhere it lives
Server and security logs, including IP addressSecurity, abuse prevention, debugging. Kept 30 daysVercel (website), Supabase (authentication and database)
Rate-limit recordsPreventing abuse of sign-in, checkout and account endpoints. A keyed hash of your IP address or email address, the endpoint, and the time — not the address itselfSupabase
Website usage and performance measurements: page paths, referring pages, browser and device information, country, and page-load measurementsUnderstanding website traffic and improving performanceCloudflare Web Analytics

Cloudflare Web Analytics does not use cookies or browser storage to track visitors across websites. Cloudflare states that it does not log URL query strings. We do not send account email addresses, TradingView usernames, passwords, or payment details as analytics events.

From Stripe: subscription status, plan, billing period, payment success or failure, and refund and dispute status. We use this to keep your access current. In Stripe's dashboard we can also see your billing name and address and the card brand and last four digits, which we use only for billing support.

3. What we do not collect

We want to be explicit, because policies copied from other companies routinely claim otherwise:

  • Card numbers, CVV, or bank details on our systems. The payment form on our checkout page is Stripe's embedded component: card details go from your browser to Stripe, not through Yinly's servers. Yinly never receives, processes, or stores them. What we can see is the card brand and last four digits that Stripe shows us for billing support.
  • Your brokerage accounts, holdings, positions, trades, or portfolio. We have no connection to any broker and no ability to see or place trades.
  • Your income, net worth, risk tolerance, or investment objectives. We never ask. Yinly applies the same fixed rules to every chart for every subscriber; it is not tailored to anyone, and collecting this would misrepresent what the product is.
  • Government identifiers, biometrics, precise geolocation, or health data.
  • Advertising or cross-site behavioural-tracking data.
  • Information from children. The Service is for adults 18 and over.

4. Why we use it (and, for GDPR, our legal basis)

PurposeLegal basis
Provide the Service; create your account after payment; grant, maintain, and revoke your indicator accessPerformance of a contract
Take payment and manage your subscriptionPerformance of a contract
Send transactional email — activation links, purchase and account notices, receipts, renewal and price notices, access changes, outagesPerformance of a contract
Answer support requestsPerformance of a contract
Prevent fraud, abuse, duplicate purchases, and access sharing; keep the Service secureLegitimate interests
Meet tax, accounting, and other legal obligationsLegal obligation
Send marketing email, if you opt inConsent

We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not profile you.

We also use aggregate website traffic and performance reports to understand how our website is used and where its performance can be improved.

5. Who we share it with

We share personal information only with the service providers that make the business run, and only what each needs to provide its service to us under contract. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. Disclosures to the providers below are disclosures to service providers or processors, not sales and not sharing for advertising, as those terms are used in California and EU law.

ProviderRoleData
StripePayment processing, subscriptions, and the customer portal. Stripe's payment form is embedded in our checkout pageEmail, billing name and address, card details (entered directly into Stripe's form), payment and subscription data
SupabaseAuthentication (sign-in, password reset, Google sign-in) and our databaseEmail, password hash, TradingView username, and the account, membership, purchase, email-delivery and rate-limit records in Section 2
ResendSends our transactional email (activation links, purchase and account notices)Your email address and the content of those messages
VercelHosts the websiteServer logs, IP address
Cloudflare Web AnalyticsWebsite traffic and performance reportsPage paths, referring pages, browser and device information, country, and performance measurements; no account or payment details are sent as analytics events
Google WorkspaceBusiness email and supportEmail address, correspondence
TradingViewDelivers the indicatorYour TradingView username, so we can grant and revoke access

We may also disclose information where required by law, valid legal process, or to protect our rights, safety, or property — and, if we ever sell or merge the business, to the acquirer, with notice to you.

Note on TradingView: because access is delivered on their platform, your TradingView username is visible to us and access grants are recorded there. Your use of TradingView itself is governed by TradingView's own privacy policy, which we do not control.

6. How long we keep it

  • While you subscribe, plus 24 months afterwards, so we can handle billing questions, reinstatement, and disputes. This covers your account, membership, email-delivery and payment-notification records.
  • Billing and tax records, including paid purchase records, for the period required by law — generally seven years in the United States.
  • Checkout records that did not lead to a payment for no longer than the subscriber period above.
  • Security logs for 30 days.
  • Rate-limit records only as long as the limit they enforce.
  • Support correspondence for 24 months.

After that we delete it or irreversibly anonymise it.

7. Your rights

Everyone. You can ask us to give you a copy of your data, correct it, delete it, or stop marketing to you. Email support@getyinly.com. We respond within 30 days. We will not discriminate against you for exercising these rights.

California (CCPA/CPRA). You have the right to know the categories and specific pieces of personal information we collect, the sources, the purpose, and who receives it; to delete it; to correct it; to opt out of sale or sharing; and to limit the use of sensitive personal information. We do not sell or share personal information, so there is nothing to opt out of — but the right exists and you may exercise it. The only sensitive personal information we handle is your account password (held as a hash by Supabase Auth) and, through Stripe, your card details; we use them only to sign you in and take payment, never to infer anything about you, so the right to limit does not apply to that use. You may use an authorised agent.

EEA and UK (GDPR). You additionally have the right to restrict or object to processing, the right to data portability, the right to withdraw consent at any time, and the right to complain to your supervisory authority — in the UK, the Information Commissioner's Office.

International transfers. Yinly operates in the United States and our providers are largely US-based, so your data will be processed there. Where we transfer personal data out of the EEA or UK we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with the relevant provider.

8. Cookies and tracking

We use only the cookies needed to run the site. Cloudflare Web Analytics measures website traffic and performance without cookies or browser storage, and we set no advertising or tracking cookies.

CookiePurposeLifetime
Sign-in session (set by Supabase Auth)Keeps you signed in to your accountWhile you are signed in
Checkout cookieTies a guest checkout to the browser it was started in, so that only that browser can resume or change it24 hours, extended to 7 days once a payment is made
Password-reset cookieConfirms that a password reset came from a reset email15 minutes

These are strictly necessary, first-party, and never used for tracking. Stripe's embedded payment form on our checkout page, and Stripe's customer portal, set Stripe's own cookies for fraud prevention and session handling, governed by Stripe's privacy policy.

We do not run advertising, retargeting, or social media pixels, and we do not respond to Do Not Track signals because no common standard for them exists. We honour Global Privacy Control signals where required by law.

9. Security

We use encryption in transit, access controls, multi-factor authentication on administrative accounts, and providers who maintain recognised security standards. Passwords are stored only as hashes by Supabase Auth. Activation and password-reset links are single-use and expire. Sign-in, checkout and account endpoints are rate-limited using keyed hashes rather than raw addresses. Keeping card data entirely with Stripe is itself a deliberate security decision — data we never hold cannot be taken from us.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information we will notify you and the relevant authorities as required by law, including California's breach notification statute and, where applicable, the GDPR's 72-hour rule.

10. Marketing email

We send service messages — activation links, receipts, renewal notices, access changes — as part of the contract; you cannot opt out of those while you subscribe.

Marketing email is separate and opt-in. Every marketing message has an unsubscribe link that works, and we honour it promptly.

11. Changes

If we change this policy materially we will email subscribers and update the date above before the change takes effect. The current version always lives at https://getyinly.com/privacy.

12. Contact

Questions, requests, or complaints:

support@getyinly.com


Read together with the Terms of Service, Risk Disclosure, and Billing and Cancellation Policy.

Yinlysupport@getyinly.com
Product
  • The signal
  • Pricing
Resources
  • Reviews
  • FAQ
Policies
  • Terms of Service
  • Privacy Policy
  • Risk Disclosure
  • Billing & Cancellation

Yinly does not provide financial services. The tools provided are for gaining insight into chart metrics only. Yinly and its team are not registered as financial advisors and hold no formal qualifications to give financial advice. Everything provided by Yinly is for educational purposes only. Yinly is not accountable or liable for any losses or damages — you are responsible for all risks you take.

Risk Disclaimer: Trading in financial markets involves substantial risk and is not suitable for every investor. You could sustain a loss of some or all of your initial investment. Past performance is not indicative of future results. Nothing on this site constitutes financial, investment, legal, or tax advice.

Independence & Trademark Notice: Yinly is an independent product and is not affiliated with, endorsed by, or officially connected to TradingView or any other third-party platform referenced on this site. TradingView® is a registered trademark of TradingView, Inc. Reviews reflect individual experiences; results vary and are not typical.

© 2026 Yinly. All rights reserved.