Privacy Policy
Effective Date: November 1, 2025
Website: https://slimscan.app
Service Provider: SlimScan (operated by an independent development team)
1. Introduction
SlimScan.app ("we", "the Company", "the Platform") respects your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with applicable data protection laws, including Thailand's Personal Data Protection Act (PDPA), the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).
By using this website, you acknowledge and agree to this Privacy Policy.
2. Information We Collect
We collect only the information necessary to provide our services.
2.1 Personal Data
- Full Name (when creating an account)
- Email address (for account verification and communication)
- User account settings such as preferred language, account configuration, and subscription status (Free / Pro)
- Login information through Google OAuth2
2.2 Payment Data
- Payments are processed securely by Stripe.
- Your credit card information is encrypted and stored only by Stripe. SlimScan does not access or store your card details.
- Stripe complies with the PCI-DSS (Payment Card Industry Data Security Standard).
2.3 Usage Data
- IP address, browser type, operating system, and session timestamps
- Clicks, search history, and pages visited within the platform
- This data helps us improve the user experience and system performance
3. Purpose of Data Processing
We use the collected information to:
- Provide SlimScan's core features, including stock analysis, watchlist management, and AI-driven insights
- Manage subscriptions and process payments via Stripe
- Analyze user behavior to improve the platform
- Send essential notifications such as subscription renewals and important updates
- Protect system integrity and prevent unauthorized access
4. Legal Basis for Processing
We process your data based on the following legal grounds:
- User Consent
- Contractual Necessity
- Legitimate Interests of the company
- Legal Compliance
5. Data Sharing with Third Parties
We do not sell, trade, or rent users' personal data to third parties. However, we may share data with trusted service providers as necessary:
- Stripe – for secure payment processing
- External hosting and database providers – for reliable data storage and platform operations
- OpenAI API – for AI-based stock analysis (e.g., CAN SLIM insights)
- Cloud monitoring services – for performance and uptime tracking
These third-party service providers are carefully selected and bound by Data Processing Agreements (DPAs) that meet international privacy and security standards.
6. Data Protection and Security
SlimScan implements "Security by Design" and "Privacy by Design" principles, including:
- Enforced HTTPS (SSL/TLS encryption)
- Google OAuth2 authentication only (no password storage)
- Secure database with Supabase and firewall protection
- Verified Stripe Webhook signatures
- Daily backups and system monitoring for anomalies
7. Data Retention
- User data is retained as long as the account remains active.
- When a user deletes their account, all personal data will be erased within 30 days.
- Anonymous or aggregated data may be retained for analytical purposes.
8. User Rights
Under applicable data protection laws, you have the right to:
- Access your personal data
- Request corrections to inaccurate data
- Request deletion or restriction of processing
- Request a portable copy of your data
- Withdraw consent at any time
To exercise these rights, contact us at: [email protected]
9. Cookies
SlimScan uses cookies to:
- Remember user preferences (e.g., language)
- Track usage statistics (e.g., via Google Analytics or equivalent tools)
You may disable cookies in your browser; however, some site features may not function properly.
10. Stock Analysis and CAN SLIM Methodology
SlimScan follows the CAN SLIM Methodology introduced by William J. O'Neil.
We are an independent platform and not affiliated with or endorsed by Investor's Business Daily (IBD).
All content is provided for informational purposes only and does not constitute investment advice. Users are responsible for their own investment decisions.
11. Children and Minors
Our services are intended for users aged 18 and above. We do not knowingly collect or process data from minors.
12. Policy Updates
We may revise this Privacy Policy from time to time. Any updates will be posted on our website with the revised effective date.
Continued use of the platform after such changes constitutes acceptance of the updated policy.
13. Contact Us
For questions, feedback, or data-related requests, please contact us: