Privacy policy
Last updated: August 2026
This policy explains what personal information Basketly collects, why we collect it, how we use it, and your rights regarding it. Basketly is designed and operated for users in Canada, the United States, the United Kingdom, the European Union, and Australia. We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws for Canadian users, with applicable US state privacy laws — including California's CCPA/CPRA — for US users, with the GDPR for EU users, with the UK GDPR and Data Protection Act 2018 for UK users, and with the Privacy Act 1988 (Cth) for Australian users. Where requirements differ, we apply the stricter standard to everyone by default. This policy does not address the specific privacy laws of other countries — see Section 1 for what this means if you connect a brokerage based somewhere else.
1. Who we are
Basketly Inc. is the data controller (or "business," under US state privacy law terminology) responsible for the personal information collected through getbasketly.com and related services. Basketly is designed and operated for users in Canada, the United States, the United Kingdom, the European Union, and Australia, and this policy is written to comply with the privacy laws applicable in each of those — see Sections 9 through 13 below. Our privacy contact is contact@getbasketly.com.
Basketly connects to your brokerage through SnapTrade, our brokerage-connectivity provider, whose connection flow supports a broader range of institutions than what Basketly features directly, including brokerages based in countries beyond the five listed above. If you connect a brokerage based somewhere else, this policy still describes how we handle your data, but it does not specifically address the privacy laws of that other country, and we do not represent that our practices satisfy those laws. Basketly's product itself is also not designed to work correctly with such an account — see our Compliance notice for details.
2. Information we collect
We collect two categories of information:
2a. Information you provide directly
- Email address (when creating an account)
- Name (optional)
- Brokerage connection details (via OAuth — we never see your brokerage password)
- Custom basket compositions and investment theses you create
- Any information you include in emails or messages to us
2b. Information collected automatically
When you visit or use the platform, we automatically collect the following technical and analytics data to identify unique visitors, detect fraud, improve performance, and understand how users reach us:
- Browser fingerprint — a unique identifier derived from your browser and device characteristics, used to recognise returning visitors without cookies
- IP address — used for geolocation, fraud prevention, and security monitoring
- Browser name and version, operating system, device type, screen resolution, language
- Referrer URL and UTM parameters — marketing attribution data
- Page views, clicks, and session duration
This automatically collected data is associated with a unique visitor record in our database and may be linked to your user account if you sign up.
3. How we use your information
We use the information we collect to:
- Operate and maintain the platform and your account
- Connect your brokerage account and submit orders on your instruction
- Understand how users discover and use Basketly (analytics)
- Detect and prevent fraud, abuse, and security incidents
- Improve platform features and prioritise brokerage integrations based on user demand
- Comply with legal and regulatory obligations in Canada and the United States
- Respond to your communications and support requests
We do not use your information to make automated investment decisions on your behalf, and we do not use it to provide personalised investment advice.
4. Browser fingerprinting
We use browser fingerprinting to recognise returning visitors without relying on cookies, for account linking, fraud prevention, and aggregate analytics only. We do not use fingerprinting for advertising profiling, cross-site tracking, or to sell data to third parties. Under California's CPRA, browser fingerprinting used this way is not considered a "sale" or "share" of personal information, since it is not used for cross-context behavioural advertising.
5. Legal bases for processing
We process your personal information on the following bases:
- Consent — you provided your information voluntarily when creating an account
- Contract performance — processing necessary to operate your account and connect your brokerage
- Legitimate interests — fraud prevention, security, and platform analytics
- Legal obligation — where required by applicable law
6. Brokerage account data
When you connect your brokerage account, Basketly receives access to your brokerage account data (positions, balances, order history) through SnapTrade, a technology provider that connects to your brokerage on our behalf using OAuth authorisation. Basketly does not store your brokerage username, password, or login credentials.
This data is used solely to display your portfolio within Basketly and to submit orders on your instruction. We do not share this data with third parties for advertising or profiling purposes, and we do not sell it.
7. Data sharing
We do not sell your personal information. We share it only in these circumstances:
- Service providers — vendors who help us operate the platform (database hosting, email delivery, payment processing) under agreements that prohibit them from using your data for their own purposes
- Your Brokerage — order instructions are transmitted to your connected Brokerage on your behalf
- Legal requirements — where disclosure is required by law, court order, or regulatory authority
- Business transfers — in the event of a merger or acquisition, with notice to you beforehand
8. Data retention
We retain your personal information for as long as your account is active or as needed to provide services. Visitor and analytics data (including fingerprints) is retained for 24 months. UTM and referral data is retained for 12 months. We may retain certain data longer where required by law or for legal defence.
9. Your rights — Canada (PIPEDA)
If you're a Canadian resident, under PIPEDA and applicable provincial law you have the right to:
- Access — request a copy of the personal information we hold about you
- Correction — request correction of inaccurate or incomplete information
- Withdrawal of consent — withdraw consent where consent is the legal basis
- Deletion — request deletion, subject to legal retention requirements
- Complaint — file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca
10. Your rights — United States (CCPA/CPRA and other state laws)
If you're a resident of California, or another US state with an applicable privacy law, you have rights that may include:
- Right to know — what personal information we collect, use, and disclose about you
- Right to delete — request deletion of your personal information, subject to legal exceptions
- Right to correct — request correction of inaccurate personal information
- Right to opt out — of the sale or sharing of personal information (Basketly does not sell or share personal information as defined under CCPA/CPRA)
- Right to non-discrimination — for exercising any of these rights
To exercise any of these rights, contact us at contact@getbasketly.com. We will verify your identity before processing a request and respond within the timeframe required by applicable law (generally 45 days, extendable once by 45 additional days under CCPA/CPRA).
If you're a resident of a US state without a comprehensive privacy law yet, we extend the same rights described above to you as a matter of policy.
11. Your rights — European Union (GDPR)
If you're a resident of the European Union, the General Data Protection Regulation (GDPR) gives you the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate or incomplete data
- Erasure — request deletion of your data (the "right to be forgotten"), subject to legal retention requirements
- Restriction — request that we limit how we use your data in certain circumstances
- Portability — receive your data in a structured, commonly used, machine-readable format, or have it transferred directly to another provider where technically feasible
- Objection — object to processing carried out on the basis of legitimate interests
- Withdrawal of consent — withdraw consent at any time where consent is the legal basis, without affecting the lawfulness of processing before the withdrawal
- Complaint — lodge a complaint with the data protection authority in your EU member state of residence, place of work, or where an alleged infringement occurred
Because our servers are located in North America (see Section 15), using Basketly involves transferring your personal data outside the European Economic Area. Where required, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses — with the service providers who process data on our behalf, to protect it during that transfer.
12. Your rights — United Kingdom (UK GDPR)
If you're a UK resident, the UK GDPR and the Data Protection Act 2018 give you rights materially the same as those described in Section 11 above: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. As with EU transfers, using Basketly involves transferring your data outside the UK to our North American servers; where required, we rely on the UK's International Data Transfer Agreement or equivalent safeguards. You can lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
13. Your rights — Australia (Privacy Act 1988)
If you're an Australian resident, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) give you the right to:
- Access — request access to the personal information we hold about you
- Correction — request correction of information that is inaccurate, out of date, incomplete, irrelevant, or misleading
- Complaint — make a complaint about how we've handled your personal information, first to us at contact@getbasketly.com, and if unresolved, to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au
The Privacy Act does not itself create a standalone right to erasure or data portability the way the GDPR does, but we extend the same deletion and portability rights described in Section 11 to Australian residents as a matter of policy.
14. Cookies
We use one essential cookie — the session cookie that keeps you signed in — required for authentication and platform functionality. It's not optional: disabling it will prevent you from logging into the platform. We do not use third-party advertising cookies, tracking pixels, or retargeting tags.
The first time you visit, we ask whether you're also okay with privacy-friendly analytics (Umami — cookieless, does not set a tracking cookie or build an advertising profile) to help us understand how the platform is used. If you choose "Necessary only," analytics stays off; if you choose "Accept all," it's enabled. Your choice is stored locally in your browser (not sent to our servers) and you can change it at any time by clearing your browser's local storage for this site, which brings the banner back on your next visit.
15. Data storage and security
Your data is stored on servers in North America. We use industry-standard security measures including TLS encryption in transit and encryption at rest. Access to personal data is restricted to Basketly personnel who need it to operate the platform.
No method of transmission over the internet is 100% secure. If we become aware of a data breach that creates a real risk of significant harm, we will notify affected users and the relevant regulator (the OPC for Canadian users; applicable state attorneys general for US users) as required by law.
16. Contact
Privacy questions or requests: contact@getbasketly.com
Basketly Inc., Waterloo, Ontario, Canada
Canadian users may also contact the Office of the Privacy Commissioner of Canada. US users may contact their state attorney general's office regarding applicable state privacy law rights. EU users may contact their local data protection authority; UK users may contact the ICO; Australian users may contact the OAIC — see Sections 11-13 above for details.