Privacy Policy
Effective 5 April 2026 · Last updated 24 August 2026
1. Summary
vnvalue ("we", "us") uses a self-hosted Umami service to understand aggregate use of the Service while keeping data collection limited. Reading the Service requires no account: every valuation, sector page, and research note is public. You may optionally create an account by signing in with Google, in which case we store your email address, display name, and Google account identifier and nothing else. We do not sell user data, run advertising trackers, or build user profiles. This Privacy Policy explains the limited information we process and the choices available to you.
2. Information analytics does not collect
Our analytics does not ask for or collect your name, email address, phone number, date of birth, national ID, financial account information, investment portfolio, holdings, or free-text input. Account information you provide by signing in with Google is described in Section 3 and is never sent to analytics.
Analytics does not receive search text, portfolio data, free text, arbitrary or user-supplied URLs, URL query strings or fragments, or a persistent user or device identifier. It receives only the current first-party page origin and path plus the limited common context described below. We do not use session replay, heatmaps, performance telemetry, cross-site tracking, advertising, or profiling.
3. Accounts and signing in with Google
An account is entirely optional: everything the Service publishes — every valuation, sector page and research note — is fully readable signed out. An account exists so we can keep a watchlist and a portfolio for you. If you choose to sign in, Google is the only sign-in method we offer. We never see or receive your Google password.
When you sign in, Google returns three pieces of information to our authentication provider: your email address, your display name and profile picture URL, and a Google account identifier (a stable numeric ID for your account). We store the email address, the display name, and the identifier. We request only the standard "email" and "profile" scopes; we cannot read your Gmail, contacts, calendar, files, or any other Google service data.
While you are signed in, your browser holds a first-party session cookie named sb-…-auth-token (it may be split across numbered parts). It is set only after you sign in, never for signed-out visitors, and it carries your session token. A short-lived companion cookie is used during the sign-in exchange itself. These cookies are readable by scripts on our site because our authentication library requires it; they are not used for analytics, advertising, or tracking, and they are removed when you sign out.
We use account information to keep you signed in, to show you which account you are using, and to store the watchlist and portfolio you create. Your watchlist is a list of ticker symbols. Your portfolio holds the ticker symbols, quantities and average costs that you enter yourself; we never receive this from a broker or any third party, and we cannot trade on your behalf. We do not send any of it to analytics, we do not use it for advertising or profiling, and we do not sell or share it.
You may sign out at any time from the account menu, which clears the session cookie. You may delete your account, and everything listed above, immediately from the same menu; see Section 12.
4. Device storage and cookies
We use your browser's localStorage to remember three small things: (a) your theme choice (dark or light), (b) whether you have acknowledged the Methodology & Disclosure notice, and (c) a watchlist you build before signing in. These values are stored only on your device and can be cleared at any time through your browser settings. The first two are never transmitted to us. The watchlist is transmitted only if you later sign in, at which point it is copied to your account and removed from your browser.
Apart from the sign-in cookies described in Section 3, we set no cookies. Signed-out visitors receive none at all. Your display language is carried in the page address rather than a cookie, and Umami sets no analytics cookies and does not use localStorage for analytics.
5. Self-hosted aggregate analytics
Umami records the core events needed to count page views and visits or sessions. For every page view and custom product event, the browser tracker sends the website identifier, hostname, current first-party absolute page URL limited to its origin and path, page title, browser language, and screen size. It also sends a cross-site referrer with its query string and fragment removed; same-site referrers are omitted. The current page query string and URL fragment are also excluded.
On the analytics server, Umami derives the visit time, browser, operating system, device type, and approximate country, region, and city from the request's User-Agent header and IP address. These fields support aggregate usage reports rather than individualized profiles.
6. Product events and their exact fields
We record only three custom product events: search_result_selected with the selected symbol; screener_csv_exported with result_count and has_filters; and stock_report_downloaded with the stock symbol.
Each custom event includes the common page context listed in Section 4 plus its event name. Its custom data object contains only the fields named above. In particular, search text, individual filter selections, report contents, and any other free-form values are not sent. has_filters is only a yes-or-no indicator of whether any filter was active.
7. Transient IP processing and anonymous sessions
The analytics server processes the source IP address transiently to derive an approximate location and compute an anonymous session hash. The raw IP address is not written to or stored in the Umami analytics database.
The anonymous session hash uses a salt that rotates monthly. This creates a new anonymous hash after the rotation instead of a stable identifier that follows a visitor indefinitely. We do not assign a persistent distinct ID and do not fingerprint devices.
8. Analytics hosting and retention
We host Umami and its analytics database ourselves on Fly.io infrastructure in Singapore. Analytics is not sent to Umami Cloud.
Page-view, visit or session, and custom-event records, including monthly anonymous session hashes, are retained indefinitely until we manually delete them or retire the analytics service. There is no automatic retention expiry. This retention period does not apply to raw IP addresses because Umami does not store them.
9. Operational server logs
Separate from Umami analytics, our hosting provider may process standard network and web-server logs to deliver and secure the Service. These logs may include an IP address, User-Agent string, requested URL, referrer, response code, and timestamp.
Operational logs are used only for service operation, security, abuse prevention, and debugging, and are retained only as long as necessary for those purposes under our provider's practices. They are not combined with analytics to create user profiles.
10. Service providers and data sources
The Service and our self-hosted analytics stack run on Fly.io (Fly.io, Inc.) infrastructure. Fly.io processes network traffic and logs as necessary to provide that infrastructure. See Fly.io's privacy policy at https://fly.io/legal/privacy-policy/ for details.
Financial data displayed on the Service is sourced from third parties including Vietcap (VCI) and KB Securities (KBS). Those data providers are not involved in your use of the Service and do not receive analytics information from us.
Authentication is provided by Supabase (Supabase, Inc.), whose infrastructure for this Service is hosted in Singapore. Supabase stores the account information described in Section 3 on our behalf. Signing in also involves Google LLC as the identity provider: Google learns that you are signing in to this Service and returns the information listed in Section 3. See Supabase's privacy policy at https://supabase.com/privacy and Google's at https://policies.google.com/privacy for details.
We do not use Google Analytics, Meta Pixel, Umami Cloud, advertising networks, or similar third-party tracking services.
11. Data sharing and sale
We do not sell, rent, or trade analytics information, and we do not disclose it to third parties for advertising, marketing, or profiling. Our infrastructure provider processes data only as needed to host and deliver the Service.
12. Your rights and choices
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or port personal data, or object to its processing. For analytics records we may be unable to identify a particular record as yours, because analytics has no account identifier, raw IP address, or persistent distinct ID. For account information we can identify you, and you may exercise these rights by writing to legal@vnvalue.tech.
You can delete your account yourself, at any time, from the account menu: choose "Delete account" and confirm. This is immediate and irreversible. It erases your account record, the associated email address, display name and Google account identifier, your watchlist, your portfolio, and any digest subscription held under that address. Deleting your account does not affect analytics records, which are not linked to it. If you would rather we did it, or you can no longer sign in, write to legal@vnvalue.tech.
You may clear localStorage and any cookies through your browser settings. You may also block the analytics script with browser controls or a content blocker; the Service's core features will remain available.
13. Children
The Service is not directed at children under 18 and is not intended for use by them. We do not knowingly seek information from children.
14. Security
We apply commercially reasonable safeguards to protect the integrity of the Service and the self-hosted analytics database. However, no system can be guaranteed to be perfectly secure, and we cannot warrant absolute security of information transmitted over the internet.
15. International users
The Service is operated from Vietnam, and the Service and analytics database are hosted in Singapore. Information described in this Policy may therefore be processed in those jurisdictions. If you are subject to specific data-protection rules, including in the EU/EEA or the United Kingdom, you may contact us at legal@vnvalue.tech about your rights.
16. Changes to this Policy
We may revise this Privacy Policy from time to time. Revised versions become effective when posted to the Service, and the last-updated date above will change. Please review this page periodically.
17. Contact
Questions, requests, or complaints about this Privacy Policy or our analytics practices may be directed to legal@vnvalue.tech.
See also: Terms of Service.