🗄️ Legal Document

Data storage policy for PSX IndexMate

Transparency about what data we store, how long we keep it, where it lives, and how you can remove it from PSX IndexMate. No surprises and no hidden retention.

Effective Date: 23 May 2025 Last Updated: 23 May 2026 Version: 1.0 Applies to: PSX IndexMate Web Application
🚫 No cloud analytics
🚫 No data warehousing
🚫 No third-party exposure
✅ Instant account deletion

1. Overview

PSX IndexMate stores only the minimum data required for the application to function. All data is kept in the application's configured database on the server where the application runs. No data is sent to external cloud databases, analytics platforms, or third-party data services.

The short version: We store your email, hashed password, and saved tickers — nothing else. Your data never leaves the server hosting PSX IndexMate.

2. What Is Stored

The following data is persisted in the application's configured database:

Summary of the account and application data fields stored by PSX IndexMate.
Data Item Purpose Format Stored Until
Email address Account identity & login Plain text Account deletion
Password Authentication bcrypt hash only Account deletion
Email verified flag Confirm email is valid Boolean (0/1) Account deletion
Saved tickers Restore your stock watchlist Comma-separated symbols Account deletion / user clears them
Ticker library Search & select stock symbols Symbol + company name Refreshed by admin; not user-specific
Account creation timestamp Audit trail ISO datetime (UTC) Account deletion

3. What Is NOT Stored

We explicitly do NOT store any of the following:
  • Your real name, phone number, or physical address.
  • Your IP address or geolocation data.
  • Page visit logs, click events, or session duration.
  • Investment amounts you enter — these are processed in-memory only and never persisted.
  • Portfolio allocation results — computed on the fly and returned to your browser only.
  • Browser type, device type, or operating system.
  • Any form of behavioural or usage analytics.
  • Cookies beyond the session identifier (which contains no personal data).
  • Any data from PSX market feeds — this is fetched from PSX's servers in real-time and not stored.

4. Where Data Is Stored

All user data is stored in the application's configured database on the server where PSX IndexMate is deployed. The application is designed to be self-hosted. If you are running your own instance, the data is entirely on your own infrastructure.

  • There is no external cloud database (no Firebase, RDS, MongoDB Atlas, etc.).
  • There is no data replication to remote servers.
  • There is no export of data to third-party services.
Note for hosted deployments: If you are using a shared or hosted instance of PSX IndexMate, your data resides on that host's server. Contact the instance operator for specific hosting details.

5. Retention Periods

  • Account data (email, hashed password, tickers): Retained for as long as your account exists. Permanently deleted upon account deletion.
  • Session data: Stored in server-side memory only. Automatically expired on logout or server restart. Not persisted to disk.
  • Ticker library (PSX symbol list): Not user-specific. Retained until an administrator manually refreshes it from PSX data.
  • Email verification tokens: Expire 24 hours after issuance. Not retained after use or expiry.
  • Password reset tokens: Expire 1 hour after issuance. Not retained after use or expiry.

6. Who Can Access Your Data

  • You — via your logged-in session on the PSX IndexMate web interface.
  • Server administrators — have access to the server and database environment where application data is stored. They can see your email address in the database. They cannot see your password (it is hashed). We commit to administrators not accessing user data except for legitimate maintenance or security purposes.
  • No one else.
No external organisation, company, government body, or individual has access to your data unless compelled by a valid legal order under Pakistani law.

7. No Analytics or Tracking

PSX IndexMate does not integrate any analytics, tracking, or telemetry services. Specifically:

  • No Google Analytics, Mixpanel, Amplitude, Segment, or similar services.
  • No Hotjar, FullStory, or session-recording tools.
  • No social media "like" buttons or share widgets that track you.
  • No error-reporting services that send stack traces or user context externally (errors are logged locally on the server only).

8. Data Deletion

You can permanently delete your account and all associated data at any time from the Profile & Settings page. When you delete your account:

  • Your email address is immediately removed from the database.
  • Your hashed password is immediately removed.
  • Your saved tickers are immediately removed.
  • Your session is invalidated and you are logged out.
Deletion is immediate and irreversible. We do not retain "soft-deleted" records or backups that preserve your identity after deletion (see Section 9 for backup details).

If you are unable to log in to delete your account, contact us at [email protected] and we will delete it manually.

9. Backups

Any server-level backups of the application database (taken for disaster recovery) will contain user data at the time of the backup. These backups:

  • Are used only for system recovery, never for data analysis.
  • Are not shared externally.
  • Are retained for no longer than 30 days.
  • Are encrypted at rest where the hosting environment supports it.

Note: Because backups are point-in-time snapshots, they may still contain data for accounts deleted after the backup was taken. These backups are automatically purged on the schedule above.

10. Data Breach Response

In the unlikely event of a data breach affecting user data, we will:

  • Investigate the incident immediately.
  • Notify affected users via the email address on their account within 72 hours of discovering the breach.
  • Describe what data was affected, the likely cause, and remediation steps.
  • Take appropriate action to secure the system and prevent recurrence.

If you suspect a security vulnerability, please report it responsibly via our contact page before public disclosure.

11. Policy Changes

If we update this Data Storage Policy, we will update the "Last Updated" date at the top of this page. We will not reduce your rights under this policy without explicit notice. Continued use of PSX IndexMate following any changes constitutes acceptance of the updated policy.

12. Contact Us

Questions about data storage? Contact us here or email [email protected].