Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal information.
Last updated: March 4, 2026
Privacy Summary
- Transcripts: Processed in real-time and immediately discarded - we don't store them
- Payments: Handled securely by Stripe - we never see your card details
- Cookies: Only essential cookies for authentication - no tracking
- Your data: You can access, correct, or delete it anytime
- We don't sell: Your data is never sold to third parties
Information We Collect
We collect the following information when you use Earnings Call Analyzer:
**Account Information:**
• Email address (required for account creation and communication)
• Password (securely hashed - we never store plain text passwords)
• Account preferences and settings
**Payment Information:**
• Payment details are processed directly by Stripe and are NOT stored on our servers
• We only receive confirmation of payment status and subscription details from Stripe
• We do not have access to your full credit card number
**Usage Data:**
• Number of analyses performed
• Timestamps of account activity
• Basic analytics (page views, feature usage) for service improvement
**What We Do NOT Collect:**
• We do NOT store the earnings call transcripts you submit for analysis
• Transcripts are processed in real-time and immediately discarded after analysis
• We do NOT retain any of your financial data or investment decisions
• We do NOT track your browsing activity outside our service
Third-Party Services
We use the following third-party services to operate Earnings Call Analyzer:
**Anthropic (Claude AI)**
• Purpose: AI-powered analysis of earnings call transcripts
• Data shared: Transcript text (temporarily, for processing only)
• Privacy: https://www.anthropic.com/privacy
**Stripe**
• Purpose: Payment processing and subscription management
• Data shared: Payment information (processed directly by Stripe)
• Privacy: https://stripe.com/privacy
**Supabase**
• Purpose: User authentication and database storage
• Data shared: Account information, usage statistics
• Privacy: https://supabase.com/privacy
**Vercel**
• Purpose: Application hosting and delivery
• Data shared: Standard web server logs
• Privacy: https://vercel.com/legal/privacy-policy
**Resend**
• Purpose: Transactional email delivery (verification, password reset)
• Data shared: Email address, email content
• Privacy: https://resend.com/legal/privacy-policy
All third-party services are selected for their strong privacy and security practices.
Data Retention
We retain your data for the following periods:
**Account Data:**
• Retained while your account is active
• Deleted within 30 days of account deletion request
**Payment Records:**
• Transaction records retained for 7 years (legal/tax requirements)
• Managed by Stripe according to their retention policies
**Usage Analytics:**
• Aggregated, anonymized analytics retained indefinitely
• Individual usage logs deleted after 90 days
**Transcripts:**
• NOT retained - processed in real-time and immediately discarded
• No transcript data is stored on our servers or with any third party
**Email Communications:**
• Transactional email logs retained for 30 days
• Marketing preferences retained until you unsubscribe
You may request deletion of your data at any time by contacting us at support@lisatamati.com.
Security Measures
We implement industry-standard security measures to protect your data:
**Technical Security:**
• All data transmitted using TLS 1.3 encryption (HTTPS)
• Passwords hashed using bcrypt with salt
• Database encrypted at rest
• Regular security audits and vulnerability assessments
**Access Controls:**
• Strict access controls to production systems
• Multi-factor authentication for administrative access
• Principle of least privilege for all system access
**Infrastructure Security:**
• Hosted on Vercel's secure, SOC 2 compliant infrastructure
• Database hosted on Supabase's secure, SOC 2 compliant infrastructure
• Regular backups with encryption
**Incident Response:**
• Security incident response procedures in place
• Users notified within 72 hours of any data breach affecting their data
While we implement strong security measures, no system is 100% secure. We encourage you to use a strong, unique password for your account.
Your Rights
You have the following rights regarding your personal data:
**Right to Access:**
• Request a copy of all personal data we hold about you
• Receive this data in a portable, machine-readable format
**Right to Correction:**
• Request correction of inaccurate personal data
• Update your account information at any time via your account settings
**Right to Deletion:**
• Request deletion of your account and associated data
• Certain data may be retained for legal/regulatory requirements
**Right to Restriction:**
• Request restriction of processing in certain circumstances
• Object to processing based on legitimate interests
**Right to Data Portability:**
• Receive your data in a structured, commonly used format
• Transfer your data to another service provider
**Right to Withdraw Consent:**
• Withdraw consent for marketing communications at any time
• Unsubscribe links provided in all marketing emails
To exercise any of these rights, contact us at support@lisatamati.com. We will respond within 30 days.
Cookies & Tracking
We use minimal cookies necessary for the operation of our service:
**Essential Cookies (Required):**
• Authentication session cookies - to keep you logged in
• Security cookies - CSRF protection and fraud prevention
• These cookies are necessary for the service to function
**What We Do NOT Use:**
• No third-party advertising cookies
• No cross-site tracking cookies
• No social media tracking pixels
• No retargeting or remarketing cookies
**Analytics:**
• We use basic, privacy-respecting analytics
• No personally identifiable information is collected
• You can use browser settings to block cookies, but this may affect functionality
**Local Storage:**
• We may use browser local storage for user preferences
• This data stays on your device and is not transmitted to us
New Zealand Privacy Act 2020
As a New Zealand-based service, we comply with the Privacy Act 2020:
**Information Privacy Principles (IPPs):**
• IPP 1-4: We only collect information necessary for our service, by lawful and fair means, with your knowledge
• IPP 5: We implement reasonable security safeguards
• IPP 6: You can access your personal information upon request
• IPP 7: You can request correction of your information
• IPP 8-9: We ensure accuracy before use and do not retain data longer than necessary
• IPP 10-11: We only use and disclose information for the purposes collected
• IPP 12: We do not assign unique identifiers unless necessary
• IPP 13: Cross-border disclosure only to jurisdictions with comparable privacy protections
**Your Rights Under NZ Law:**
• Right to access your information (free of charge)
• Right to request correction
• Right to complain to the Privacy Commissioner
**Contact the NZ Privacy Commissioner:**
Office of the Privacy Commissioner
PO Box 10094, Wellington 6143
Phone: 0800 803 909
www.privacy.org.nz
GDPR Compliance (EU/EEA Users)
For users in the European Union and European Economic Area, we comply with the General Data Protection Regulation (GDPR):
**Legal Basis for Processing:**
• Contract: Processing necessary to provide our service to you
• Consent: Marketing communications (opt-in only)
• Legitimate Interest: Service improvement, fraud prevention
**Data Transfers:**
• Your data may be transferred to and processed in New Zealand, USA, and other countries
• We ensure adequate protections through Standard Contractual Clauses or equivalent mechanisms
• Third-party services used are Privacy Shield certified or have appropriate safeguards
**Your GDPR Rights:**
• Right to be informed (this policy)
• Right of access (request your data)
• Right to rectification (correct inaccuracies)
• Right to erasure ("right to be forgotten")
• Right to restrict processing
• Right to data portability
• Right to object to processing
• Rights related to automated decision-making
**Data Protection Officer:**
For GDPR-related inquiries: support@lisatamati.com
**Supervisory Authority:**
You have the right to lodge a complaint with your local data protection authority.
CCPA Compliance (California Users)
For California residents, we comply with the California Consumer Privacy Act (CCPA):
**Your CCPA Rights:**
• Right to Know: What personal information we collect and how it's used
• Right to Delete: Request deletion of your personal information
• Right to Opt-Out: We do NOT sell your personal information
• Right to Non-Discrimination: Equal service regardless of privacy choices
**Categories of Information Collected:**
• Identifiers (email address)
• Commercial information (subscription status, transaction history)
• Internet activity (usage logs, page views)
**We Do NOT:**
• Sell your personal information to third parties
• Share your information for cross-context behavioral advertising
• Use sensitive personal information for purposes other than providing our service
**How to Exercise Your Rights:**
• Email: support@lisatamati.com
• We will verify your identity before processing requests
• Authorized agents may submit requests on your behalf with proper documentation
**Response Time:**
• We respond to verifiable requests within 45 days
• Extensions of up to 45 additional days may be needed for complex requests
Contact & Updates
**Contact Us:**
For any privacy-related questions, concerns, or requests:
Email: support@lisatamati.com
Business: Lisa Tamati Enterprises, New Zealand
**Changes to This Policy:**
• We may update this Privacy Policy from time to time
• Material changes will be notified via email or prominent notice on our website
• Continued use after changes constitutes acceptance
• Previous versions available upon request
**Effective Date:**
This Privacy Policy is effective as of the "Last Updated" date shown at the top of this page.
**Questions?**
If you have any questions about this Privacy Policy or our data practices, please don't hesitate to contact us. We're committed to protecting your privacy and will respond to all inquiries promptly.
Questions About Your Privacy?
If you have any questions about this Privacy Policy or how we handle your data, please contact us at support@lisatamati.com
Lisa Tamati Enterprises, New Zealand