Legal

Privacy Policy

Effective Date: July 2, 2026

Operated by / Data Controller: Peter Kutsos, sole trader (fyzická osoba podnikající) registered in the Czech Republic, IČO: 22489959, registered office: Na vysočanských vinicích 825/10, Vysočany, 190 00 Praha 9, Czech Republic ("yap.watch," "we," "us," or "our")

Data Controller Contact: legal@yap.watch

This Privacy Policy explains how yap.watch collects, uses, discloses, retains, and protects your personal data when you use our website at https://yap.watch, our APIs, alert delivery features, and related services (collectively, the "Service"). This Privacy Policy is incorporated into and subject to our Terms of Service.

We process personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Czech Act No. 110/2019 Coll., on the Processing of Personal Data.

1. Information We Collect

1.1 Account Data

When you create an account: email address, username or display name, and authentication credentials (password hash or third-party login provider identifiers).

1.2 Billing and Transaction Data

Payments are processed by Stripe, which collects your payment details directly. We receive and store: subscription plan and status, Stripe customer and subscription identifiers, invoice and payment event data, and billing country. We do not store your card number. See Stripe's Privacy Policy.

1.3 Configuration Data

Alert preferences (tracked accounts, keywords, channels), API key status and usage settings, webhook destinations and integration configurations, dashboard preferences and saved views.

1.4 Usage and Technical Data

Collected automatically: IP address; browser type, version, and language; device type and operating system; pages visited, features used, and interaction patterns; API request logs (endpoint, timestamp, response status); session and authentication events; referring URL.

1.5 Communication Data

If you contact us, we collect the content of your communication and any information you voluntarily provide.

1.6 Third-Party Content Data

The Service processes publicly available posts, metadata, links, and market data from third-party sources to deliver its features. This data relates to public figures and public markets — not to you personally. We do not collect personal data about you from social media platforms.

2. Legal Basis for Processing (GDPR)

3. How We Use Your Data

To create, maintain, and secure your account; provide, operate, and improve the Service; process subscriptions and payments; deliver alerts via your configured channels; provide API access and enforce usage limits; generate analysis and dashboards; send transactional and service communications; send marketing communications where permitted (with an opt-out in every message); respond to support requests; monitor usage and performance; detect and prevent abuse, fraud, and security threats; establish, exercise, or defend legal claims and enforce our Terms of Service; and comply with legal obligations.

We do not sell your personal data. We do not use your personal data to train AI or machine learning models.

4. Sharing Your Data

4.1 Service Providers

Processors acting on our instructions: Stripe (payments); hosting and infrastructure providers; email and communication providers; analytics providers.

4.2 Alert Delivery Destinations

When you configure alerts to external services (Telegram, webhooks, etc.), alert content is delivered to those services at your instruction and risk. Those services act independently of us; we are not responsible for their handling of the data.

4.3 Legal, Safety, and Enforcement

We may disclose personal data where we reasonably believe it necessary to comply with law or legal process, enforce our Terms of Service, protect the rights, safety, or property of yap.watch, our users, or the public, or establish, exercise, or defend legal claims.

4.4 Business Transfers

If yap.watch or its assets are involved in a merger, acquisition, financing, reorganization, or sale (including transfer of the business to a legal entity such as an s.r.o.), personal data may be transferred to the successor. We will provide notice as required by applicable law.

5. International Data Transfers

Personal data may be processed outside the EEA (e.g., the United States) by our providers. Where this occurs we rely on appropriate safeguards: adequacy decisions, Standard Contractual Clauses, or other legally recognized mechanisms. You may request information about the safeguards by contacting us.

6. Cookies and Similar Technologies

You may change or withdraw cookie preferences at any time via the cookie settings link in the footer or your browser settings. Disabling essential cookies may break functionality. We do not use cookies for cross-site advertising.

7. Data Retention

We retain personal data for as long as necessary for the purposes described in this Policy, including providing the Service, complying with legal, tax, and accounting obligations, resolving disputes, enforcing agreements, and establishing, exercising, or defending legal claims (retention up to the expiry of applicable limitation periods, generally 3–10 years under Czech law).

Indicative periods:

We may retain de-identified or aggregated data indefinitely.

8. Your Rights (GDPR)

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection — including to direct marketing (Art. 21), withdrawal of consent (Art. 7(3)), and complaint to a supervisory authority (Art. 77). In the Czech Republic the supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, https://www.uoou.cz).

These rights are not absolute and apply within the limits of the GDPR — for example, erasure does not apply to data we must retain by law or need for legal claims (Art. 17(3)), and we may refuse or charge a reasonable fee for manifestly unfounded or excessive requests (Art. 12(5)).

How to Exercise Your Rights

Contact legal@yap.watch. We respond within one calendar month, extendable by two further months for complex or numerous requests (we will inform you of any extension within the first month). We may require verification of your identity before acting on a request.

9. Account Deletion

You may delete your account via account settings or by contacting us. Upon deletion: API keys are revoked and alert delivery stops; account data is deleted or anonymized without undue delay, except data we retain under Section 7 (e.g., billing records, data needed for legal claims or abuse prevention).

10. Children

The Service is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe we hold data of a child, contact us and we will delete it promptly.

11. Data Security

We implement appropriate technical and organizational measures, including encryption in transit (TLS) and at rest, access controls, security monitoring and logging, and PCI-DSS-compliant payment processing via Stripe. No method of transmission or storage is completely secure; to the extent permitted by law, we do not warrant absolute security. Where a personal data breach occurs, we will comply with our notification obligations under Arts. 33–34 GDPR.

12. Automated Decision-Making

The Service's AI algorithms analyze market and public-figure data — not you. We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR).

13. Third-Party Links

This Policy does not apply to third-party websites or services linked from the Service. Review their policies.

14. Changes to This Privacy Policy

We may update this Policy at any time by posting the updated version and updating the Effective Date. Material changes will be notified via the Service or email where practicable. Continued use after changes take effect constitutes acceptance; if you disagree, stop using the Service and delete your account.

15. Data Protection Officer

We are not required to appoint a Data Protection Officer under the GDPR. Data protection matters: legal@yap.watch.

16. Contact

Email: legal@yap.watch Website: https://yap.watch

Supervisory authority: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, https://www.uoou.cz