Data Protection

Oct, 1 2025

Data Controller and Contact Information

FlaBrokers ("FlaBrokers", "we", "us", or "our") is the data controller for personal data collected through the website flabrokers.com and related services in the United States of America.

Owner: Asia Stewart

Postal Address: 653 Park Ave, Rochester, NY 14607, United States

Email: [email protected]

Scope and Applicability

This notice explains how we collect, use, disclose, and safeguard personal data when you access or use FlaBrokers’ websites, tools, and services. It is intended to meet applicable requirements under United States privacy laws (including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Utah Consumer Privacy Act (UCPA), and the Connecticut Data Privacy Act (CTDPA)). Where we process personal data of individuals located in the European Economic Area or the United Kingdom, this notice also provides information designed to address the General Data Protection Regulation (GDPR) and the UK GDPR.

Personal Data We Collect

We may collect and process the following categories of personal data:

  • Identifiers and contact information (e.g., name, username, email address, postal address, phone number).
  • Account and profile information (e.g., account settings, preferences, saved comparisons, watchlists, portfolio inputs you provide).
  • Commercial information (e.g., subscription status, transaction history related to our paid services, broker preferences or selections).
  • Internet, device, and network activity (e.g., IP address, device identifiers, browser type, pages viewed, referring/exit pages, timestamps, interaction with features, approximate location inferred from IP).
  • Geolocation data (approximate/general location; precise location only if you enable it in your device or browser).
  • Financial and brokerage connection data you choose to provide (e.g., API keys or tokens necessary to retrieve account balances, holdings, or historical data from third-party brokers or exchanges, strictly as authorized by you).
  • User-generated content (e.g., reviews, comments, ratings, survey responses, support requests).
  • Inferences drawn from the above (e.g., segments and preferences to improve content relevance).
  • Sensitive personal information (we do not seek to collect sensitive categories; if collected, it will be used only for limited, disclosed purposes or with your consent, and you may have rights to limit its use).

Sources of Personal Data

  • Directly from you when you create an account, complete forms, submit content, connect third-party accounts, or communicate with us.
  • Automatically from your device and browser through cookies, pixels, SDKs, and similar technologies when you use our services.
  • From third parties, such as analytics providers, advertising partners, payment processors, data aggregators, market data vendors, and (with your authorization) brokers or exchanges you connect.
  • From publicly available sources, where permitted by law.

Purposes of Processing

  • To operate, maintain, and improve our websites, tools, and services.
  • To provide comparisons, reviews, rankings, research, and market data features.
  • To authenticate users, administer accounts, and provide customer support.
  • To process payments and manage subscriptions.
  • To personalize content, measure engagement, and develop new features.
  • For analytics, debugging, and security monitoring (including fraud prevention and detection).
  • For marketing and advertising, including cross-context behavioral advertising where permitted by law.
  • To comply with legal obligations and enforce our terms, policies, and rights.
  • For corporate transactions (e.g., mergers, acquisitions, reorganizations), subject to appropriate safeguards.

Disclosures of Personal Data

We may disclose personal data to the following categories of recipients for the purposes described above:

  • Service providers and contractors (e.g., hosting, cloud infrastructure, analytics, customer support, payment processing, security, and anti-fraud partners).
  • Advertising and marketing partners (for measurement and cross-context behavioral advertising, where allowed by law and subject to your choices).
  • Affiliates and subsidiaries under common ownership or control.
  • Professional advisors (e.g., auditors, legal counsel) under confidentiality obligations.
  • Government, regulators, and law enforcement when required by law or to protect rights, safety, and security.
  • Parties to business transactions (e.g., acquirers) in connection with a merger, sale, or transfer of assets, subject to applicable law.

We do not sell personal information in exchange for money. However, we may share personal information for targeted advertising or cross-context behavioral advertising, which some U.S. state laws may treat as a "sale" or "sharing." You have the right to opt out of such activities as described in the Rights and Choices section.

Cookies and Tracking Technologies

We use cookies, pixels, SDKs, local storage, and similar technologies to enable core functionality, remember preferences, analyze traffic and usage patterns, and deliver advertisements. Categories include:

  • Strictly necessary/essential.
  • Performance and analytics.
  • Functionality.
  • Advertising and measurement.

You can manage cookies via your browser settings. Where required by law, we honor supported and recognized opt-out preference signals such as Global Privacy Control for opting out of sale/sharing for targeted advertising.

Retention of Personal Data

We retain personal data for as long as necessary to fulfill the purposes described in this notice, including to comply with legal, accounting, or reporting obligations; resolve disputes; maintain security; and enforce agreements. Retention periods are determined based on factors such as the nature of the data, the purpose of processing, and applicable legal requirements. When data is no longer needed, we will delete, de-identify, or anonymize it as appropriate.

Security

We implement reasonable and appropriate administrative, technical, and physical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. No method of transmission over the Internet or method of electronic storage is fully secure, and we cannot guarantee absolute security.

International Data Transfers

We are located in the United States. If you access our services from outside the U.S., your personal data may be transferred to and processed in the U.S. and other jurisdictions that may have data protection laws different from those in your jurisdiction. Where required by law (e.g., for EEA/UK residents), we rely on appropriate transfer mechanisms such as Standard Contractual Clauses and implement additional safeguards as appropriate.

Your Privacy Rights

Rights Under United States Law

Depending on your state of residence, you may have the following rights, subject to exceptions:

  • Right to know/access: request the categories and specific pieces of personal information we collected, the categories of sources, purposes, categories of third parties, and disclosures.
  • Right to deletion: request deletion of personal information we collected from you.
  • Right to correction: request correction of inaccurate personal information.
  • Right to portability: receive certain information in a portable format.
  • Right to opt out: opt out of sale or sharing of personal information and targeted advertising; and, where applicable, opt out of profiling in furtherance of decisions producing legal or similarly significant effects.
  • Right to limit use and disclosure of sensitive personal information (California).
  • Right to appeal (Virginia, Colorado, Connecticut) if we decline to act on your request.
  • Right to non-discrimination: you will not be discriminated against for exercising your rights.

Rights Under the GDPR (If Applicable)

  • Right of access to your personal data.
  • Right to rectification of inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten").
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object to processing, including direct marketing.
  • Right to withdraw consent at any time where processing is based on consent.
  • Right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
  • Right to lodge a complaint with a supervisory authority.

How to Exercise Your Rights

You may submit requests by emailing [email protected] or by writing to: FlaBrokers, Attn: Privacy, 653 Park Ave, Rochester, NY 14607, United States. Please include your name, the nature of your request, the state or country of residence, and sufficient information for us to verify your identity and process your request. We will respond within the timeframes required by applicable law (generally within 45 days, with extensions where permitted).

Authorized Agents (California): If you use an authorized agent to submit a request, we may require proof of the agent’s authorization and verification of your identity directly with us, unless prohibited by law.

Appeals (Virginia, Colorado, Connecticut): If we deny your request, you may appeal by replying to our decision email or writing to the address above with the subject line "Privacy Request Appeal." We will respond within the time required by law and provide reasons for our decision.

Opt-Out Preferences: To opt out of sale/sharing or targeted advertising, you may email us or use available account or browser-based controls. We honor recognized opt-out preference signals such as Global Privacy Control where required.

Children’s Privacy

Our services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will take appropriate steps to delete it.

Brokerage, Exchange, and Financial Connections

When you choose to connect a broker or exchange account, or otherwise provide API keys/tokens or portfolio data, we process such information solely to perform the services you request, such as retrieving balances, holdings, or historical performance. We do not take custody of your assets, and we do not place trades without your direction. You may revoke access at any time through your broker/exchange or by contacting us. Third-party services you use are governed by their own terms and privacy policies.

Automated Decision-Making and Profiling

We do not engage in automated decision-making that produces legal or similarly significant effects about you without human involvement. We may use profiling to analyze or predict preferences for analytics and advertising; you can opt out of targeted advertising as described above.

California "Shine the Light"

California residents may request information regarding our disclosures of personal information to third parties for their direct marketing purposes in the preceding calendar year, if applicable. To make such a request, contact us at [email protected].

Updates to This Notice

We may update this notice from time to time to reflect changes in our practices or legal requirements. We will post the updated version with a new effective date. Your continued use of our services after an update constitutes acceptance of the revised notice.

Effective Date

October 1, 2025