Daily usage limits
The service stores a random browser identifier and a one-way protected network identifier to enforce daily limits. Full IP addresses are not stored in the application database. Daily counter records are automatically deleted after approximately 35 days.
Optional analytics
Google Analytics loads only after you choose Allow. It reports aggregate country or region, visit frequency, and which major tools are used. Analytics events do not contain portfolio tickers, weights, capital, simulation paths, or results. You can choose Not now and continue using the site.
Research inputs
Portfolio inputs are sent to the calculation API only to produce the requested result. The beta does not use those inputs for advertising profiles. Avoid uploading confidential or personally identifying information in a custom factor file.
Accounts and saved reports
If you choose to sign in, RiskCrafter stores your account ID, email, display name, plan status, and usage entitlement. Monthly subscribers can save private strategy snapshots and reports to their account and delete them from account history. Free anonymous use does not require an account. Google sign-in and email/password authentication are handled by Firebase Authentication. RiskCrafter's calculation API and application database do not receive or store your password.
Payments
Checkout and subscription management are hosted by Stripe. Payment card and bank details must be entered only on a Stripe-hosted page. RiskCrafter does not provide a card-entry form and rejects card numbers, CVC codes, expiry dates, or bank details sent to its API. It stores only the Stripe customer, checkout, and subscription references needed to activate and manage access.
Do not include card or bank details in feedback, custom factor files, report titles, or any other RiskCrafter input. For an incorrect or unrecognized charge, use the feedback panel without including payment details, and contact your card issuer when appropriate.
Service providers and location
Google Cloud and Firebase provide hosting, account authentication, database storage, and security logging. Stripe provides Checkout, billing management, receipts, refunds, and payment-risk services. These providers may process data outside Ontario or Canada under their own contractual and legal safeguards. RiskCrafter remains responsible for selecting and overseeing these providers for its use of personal information.
Retention and your choices
Daily limit records are retained for about 35 days. Feedback is retained for up to one year. Saved reports remain until you delete them or the account reaches its 50-report limit. Minimal billing audit records contain Stripe references, amount, currency, status, and accepted terms version, never card details, and may be retained for approximately seven years for tax, accounting, fraud, and dispute records.
You can refuse optional analytics, delete saved reports in your account, and request access, correction, account deletion, or a privacy explanation through the published support email. Some billing and security records may be retained where law or an unresolved dispute requires it.
Security incidents
RiskCrafter limits access to production data and records suspected privacy incidents. Where a breach creates a real risk of significant harm, affected people and the appropriate Canadian privacy authority will be notified as required by law.
每日使用限额
网站使用随机浏览器标识和经过单向保护的网络标识来执行每日限额。应用数据库不会保存完整 IP 地址,计数记录约 35 天后自动删除。
可选匿名统计
只有在您点击“允许”后,Google Analytics 才会加载。统计内容包括汇总后的国家或地区、访问频率和主要功能使用情况,不包含股票、权重、资金、模拟轨迹或计算结果。拒绝统计不影响网站功能。
研究输入
组合输入只会发送给计算接口以生成您请求的结果。测试版不会使用这些输入建立广告画像。请勿在自定义因子文件中上传机密信息或个人身份信息。
账户与已保存报告
如果您选择登录,RiskCrafter 会保存账户 ID、邮箱、显示名称、方案状态和计算权益。月度订阅用户可以把策略快照和报告私密保存到账户中,并可在历史记录中删除。免费匿名使用不需要账户。 Google 登录与邮箱密码验证由 Firebase Authentication 处理;RiskCrafter 的计算接口和应用数据库不会接收或保存您的密码。
付款
付款和订阅管理页面由 Stripe 托管。银行卡和银行账户信息只能在 Stripe 托管页面输入。RiskCrafter 不提供银行卡输入框,接口也会拒绝卡号、CVC、有效期或银行账户信息;平台只保存用于开通和管理权益的 Stripe 客户、付款和订阅引用。
请勿在反馈、自定义因子文件、报告标题或其他 RiskCrafter 输入中填写银行卡信息。如发现错误或不认识的扣款,请通过反馈栏联系平台且不要提供支付信息,并在必要时联系发卡机构。
服务提供方与处理地点
Google Cloud 和 Firebase 提供托管、账户认证、数据库存储及安全日志;Stripe 提供付款、账单管理、收据、退款和支付风控。这些提供方可能依据各自合同和法律保障在安省或加拿大境外处理数据。对于平台如何选择并监督这些提供方,RiskCrafter 仍承担相应的隐私责任。
保存期限与您的选择
每日额度记录约保存 35 天,反馈最多保存一年。已保存报告会保留到您主动删除,或账户达到 50 份上限。最小化账单审计只保存 Stripe 引用、金额、币种、状态和已接受条款版本,绝不保存卡片信息;因税务、会计、反欺诈及争议处理需要,可能保存约七年。
您可以拒绝可选统计、在账户中删除报告,并通过公开的支持邮箱提出访问、更正、删除账户或了解隐私处理方式的请求。法律要求保留或争议尚未解决的账单与安全记录可能无法立即删除。
安全事件
RiskCrafter 会限制生产数据访问并记录疑似隐私事件。如果事件造成重大损害的现实风险,平台将依照法律通知受影响用户和相应的加拿大隐私监管机构。