Privacy Policy
Last updated: 28 September 2026 · Version 1.3
US Aktien Screener · us-aktien-screener.com
This is a translation for convenience. In case of doubt, the German version prevails.
Protecting personal data matters to me. This policy describes what data is processed when you visit and use this service, for what purpose and on what legal basis. It fulfils the information obligations under Art. 13 and 14 of the General Data Protection Regulation (GDPR) as well as the requirements of the Austrian Data Protection Act (DSG) and sec. 165 of the Austrian Telecommunications Act 2021 (TKG 2021).
1. The essentials first
- Only technically necessary cookies are set — no advertising or tracking cookies.
- Visitor statistics work without cookies and without recognising individual persons.
- An account is required in order to use the service. The e-mail address, plan and self-created lists are stored.
- Payments are handled by Lemon Squeezy. Card or account details are never visible to the provider.
- Personal data is neither sold nor passed on to third parties for advertising purposes.
2. Controller
The controller within the meaning of Art. 4 (7) GDPR is:
Robert Thalhammer
Grabengasse 13/3/2
2630 Ternitz
Niederösterreich, Austria
E-mail: datenschutz@us-aktien-screener.com
No data protection officer has been appointed because the statutory conditions of Art. 37 GDPR are not met. All data protection enquiries go directly to the address above.
3. Hosting and servers
This website is hosted by IONOS SE, Elgendorfer Strasse 57, 56410 Montabaur, Germany. The servers are located in Germany and therefore within the European Union. A data processing agreement pursuant to Art. 28 GDPR is in place with IONOS.
4. Operation of the web application
The application itself runs on the Streamlit Community Cloud, a service of Snowflake Inc., 106 East Babcock Street, Suite 3A, Bozeman, MT 59715, USA. The server location is the USA. When the application is accessed, connection data is transmitted to the platform operator.
The legal basis is Art. 6 (1) (b) GDPR (performance of the user agreement). Only the technically necessary connection data and the session data required to operate the application are processed; no storage beyond the session takes place on this platform. The transfer to the USA is based on the Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR.
5. Server log files
When the website is accessed, data transmitted by the browser is automatically stored in server log files:
- IP address of the requesting device
- date and time of access
- name and URL of the file retrieved
- volume of data transferred and notification of successful retrieval
- browser type, browser version and operating system
- where applicable, the previously visited page (referrer)
This data serves technical operation, troubleshooting and the prevention of attacks. The legal basis is Art. 6 (1) (f) GDPR. Log files are generally deleted automatically after no more than seven days. This data is not merged with other data sources.
6. User account and database (Supabase)
Supabase (Supabase, Inc.) is used for login, user account and stored settings. The database used for this project runs in the Frankfurt, Germany (eu-central-1) region. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.
The following is stored: e-mail address, login times, session attributes, the subscribed plan and the lists and settings you create yourself. Login uses a one-time code sent by e-mail; no password is stored.
The legal basis is Art. 6 (1) (b) GDPR. The data is deleted when the account is deleted; documents relevant for billing are retained for seven years pursuant to sec. 132 BAO.
7. Visitor statistics (IONOS WebAnalytics)
In addition, IONOS WebAnalytics is used, a service of IONOS SE, Elgendorfer Strasse 57, 56410 Montabaur, Germany. The analysis works without cookies; the IP address is truncated and not stored permanently. Processing takes place on servers in Germany.
The legal basis is Art. 6 (1) (f) GDPR. The aggregated reports are deleted after 30 days.
8. Visitor statistics (Cloudflare Web Analytics)
Cloudflare Web Analytics, a service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, is used to measure reach.
Cloudflare Web Analytics works without cookies and without recognising individual persons. Only aggregated values such as page views, country of origin, approximate loading time and browser and device type are collected. No profile is created, no cross-device tracking takes place, and the IP address is not stored.
The legal basis is Art. 6 (1) (f) GDPR. The legitimate interest lies in understanding which content is in demand and whether the website is working correctly. The data is stored for a maximum of seven days. The transfer to the USA is based on the Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR; Cloudflare is additionally certified under the EU-US Data Privacy Framework.
9. Payment processing (Lemon Squeezy)
Paid services are processed via Lemon Squeezy, operated by Lemon Squeezy LLC, 5900 Balcones Drive, Suite 100, Austin, TX 78731, USA. Lemon Squeezy acts as Merchant of Record, i.e. it is the contracting party for the payment transaction and handles the tax processing.
Payment data (in particular card or account details) is processed exclusively by Lemon Squeezy and is at no time visible to the provider. Only the information required to fulfil the order is transmitted to the provider: order number, product, time of purchase, amount, country and e-mail address.
The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR for tax retention. The transfer to the USA is based on the Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR. Lemon Squeezy's privacy policy applies in addition.
10. Automated data updates (GitHub Actions)
The regular updating of key figures runs via GitHub Actions (GitHub, Inc., 88 Colin P Kelly Jr Street, San Francisco, CA 94107, USA). Only publicly available market data is processed in the course of this, no personal data of users.
11. Data sources
The key figures displayed originate from external data sources. This source receives no data about individual users; only market data is retrieved, and it is retrieved by the provider itself.
The data is reproduced without warranty as to accuracy, completeness or timeliness. Price and key-figure data may be delayed.
Where a figure is replaced by the note "view ↗", that link leads to a publicly accessible price page of a third party. The reason is a licensing one: the provider may calculate with the price data but may not pass the figures on. A connection to that page is established only when you click; as with any page request, your IP address and browser data are then transmitted to the third party, and that party's privacy policy applies. No referrer is sent, so the destination does not learn which page the click came from. Without a click, no transmission takes place. This is not an affiliate or commission link. The legal basis is Art. 6(1)(f) GDPR.
12. Affiliate links to trading platforms
Individual pages contain recommendation links to trading platforms. If a registration or transaction results, a commission may be payable. Users incur no additional costs as a result. Such links are marked as advertising.
On clicking, the privacy policy of the respective platform applies. The identity of the person who clicked the link is not transmitted; only the attribution to a partner identifier is reported back. The selection of the linked providers does not constitute a recommendation to buy or sell financial instruments. The legal basis is Art. 6 (1) (f) GDPR.
13. Cookies
Only technically necessary cookies are used, which are required for the operation of the application — in particular a session cookie that maintains the login during the session. No consent is required for technically necessary cookies under sec. 165 (3) of the Austrian Telecommunications Act 2021 (TKG 2021).
No cookies are set for advertising, tracking or profiling purposes.
14. Contact form
A contact form is available on the website. What is transmitted is the message entered there and the sender's address; the name is optional. The host's web server forwards the message by e-mail to the provider's mailbox, where it is processed like an ordinary e-mail; it is not stored on the web server. No third-party form service is embedded.
The legal basis is Art. 6 (1) (b) GDPR for enquiries relating to a contract (for instance about a subscription or an invoice) and Art. 6 (1) (f) GDPR for other enquiries (interest in answering them). Enquiries are deleted once they have been finally dealt with and no retention obligation applies. Please do not submit login, brokerage or payment details through the form.
15. Withdrawal via the website
A “Withdraw from contract” button is available on every page for withdrawing from the contract. It leads to a short form. What is transmitted is the name, the e-mail address for the acknowledgement of receipt, the order number or the date of purchase, and the time of receipt. No reason is requested.
The statement is delivered immediately to the provider's mailbox; at the same time the customer receives an acknowledgement of receipt stating the content of the statement and the date and time of receipt. Nothing is stored on the web server in the process, and no third-party form service is embedded. To handle the withdrawal, the provider matches the details with the order at the payment service provider.
The legal basis is Art. 6 (1) (c) GDPR in conjunction with sec. 13a FAGG (withdrawal function and acknowledgement of receipt) and Art. 6 (1) (b) GDPR for handling the withdrawal. The statement and the acknowledgement form part of the records of the purchase concerned and are retained for seven years under sec. 132 BAO.
16. Contact by e-mail
Anyone who makes contact by e-mail thereby transmits their e-mail address and the content of the message. This information is used exclusively to process the enquiry.
The legal basis is Art. 6 (1) (b) GDPR for enquiries relating to a contract and Art. 6 (1) (f) GDPR for other enquiries. E-mail traffic is processed by the respective e-mail provider, who acts as a processor in this respect. Enquiries are deleted once they have been finally dealt with. Anything kept longer is kept only because a statutory retention obligation applies — which concerns solely business correspondence that serves as an accounting record and must be retained for seven years pursuant to sec. 132 of the Austrian Federal Fiscal Code (BAO).
17. No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
18. Is providing data mandatory?
- An account is required in order to use the paid functions. Without an e-mail address no account can be created and the contract cannot be performed.
- The details requested during the payment process are required in order to make a purchase; without them the purchase cannot be processed and no invoice can be issued.
- Simply visiting the website is possible without providing any personal data.
There is no statutory obligation to provide personal data.
19. Retention periods
Personal data is stored only for as long as is necessary for the respective purpose or as required by statutory retention obligations. The specific periods are stated with the individual processing operations above. In addition:
- server log files: seven days at most, in so far as the provider keeps them itself
- e-mail enquiries: until the matter has been finally dealt with
- records of consent given: for the duration of the accountability obligation under Art. 5 (2) GDPR
- accounting and invoicing documents: seven years pursuant to sec. 132 BAO
20. Recipients and transfers to third countries
Personal data is not sold and is not passed on to third parties for advertising purposes. Disclosure takes place only to the service providers and payment services named above and to public authorities where there is a statutory obligation to do so, as well as to the tax adviser and bank to the extent necessary.
Where data is transferred to third countries outside the EU and the EEA, this takes place only on the basis of an adequacy decision of the European Commission or the Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR. The applicable basis is stated with each affected processing operation above.
21. Rights of data subjects
Under the GDPR you have the following rights:
- Access (Art. 15 GDPR): which data is being processed
- Rectification (Art. 16 GDPR): to have inaccurate data corrected
- Erasure (Art. 17 GDPR): to have data deleted, unless a retention obligation applies
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR): to receive the data in a common format
- Objection (Art. 21 GDPR) to processing based on a legitimate interest
- Withdrawal of consent (Art. 7 (3) GDPR), at any time and with effect for the future
An informal message to the e-mail address above is sufficient to exercise these rights. A reply will be given within the statutory period of one month. To prevent misuse, proof of identity may be requested in case of doubt.
Separate notice of the right to object (Art. 21 GDPR)
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out on the basis of a legitimate interest under Art. 6 (1) (f) GDPR. Where your data is processed for direct marketing purposes, you may object at any time and without giving reasons; your data will then no longer be processed for that purpose. An informal objection to the e-mail address above is sufficient.
22. Right to lodge a complaint
Anyone who believes that the processing of their data infringes data protection law may lodge a complaint with the supervisory authority:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42, 1030 Wien, Austria
Phone: +43 1 52 152-0 · E-mail: dsb@dsb.gv.at · www.dsb.gv.at
23. Data security
The website is delivered exclusively over an encrypted TLS/HTTPS connection. Accounts are secured with strong, individual passwords and — where available — two-factor authentication. On the controller's side, only the controller has access. In addition, the service providers named above have access within the scope of their respective services, bound by confidentiality and — where they act as processors — by a contract pursuant to Art. 28 GDPR.
24. Changes to this privacy policy
This privacy policy is updated whenever the processing operations change — for example when a service is added or removed. The version published on this page is the one that applies.
Controller
Robert Thalhammer
Grabengasse 13/3/2
2630 Ternitz
Niederösterreich, Austria
E-mail: datenschutz@us-aktien-screener.com
Last updated: 28 September 2026
Last updated: 28 September 2026 · Version 1.3