1. Introduction
WayJet Inc. (“Company,” “we,” “us,” or “our”) operates the Shine AI platform (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service. By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, display name, and password when you create an account
- OAuth Data: Public profile information (name, email, profile picture) from Google, Facebook, or Apple when you sign in via OAuth
- API Keys: Third-party API keys you configure in your settings (stored encrypted; used only to make API calls on your behalf)
- Community Content: Posts, predictions, comments, and interactions you submit to community features
- Support Communications: Information you provide when contacting us for support
2.2 Information Collected Automatically
- Usage Data: Analysis requests, features used, pages visited, and interaction patterns
- Device Information: Browser type, operating system, device type, and screen resolution
- Log Data: IP address, access times, referring URLs, and error logs
- Local Storage:Client preferences (theme, language) and authentication tokens stored in your browser's localStorage
2.3 Information We Do Not Collect
- We do not collect or store credit card numbers (payments are processed by Stripe)
- We do not use third-party tracking cookies or advertising pixels
- We do not collect biometric data
- We do not purchase data from data brokers
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process your AI analysis requests and deliver results
- Manage your account and subscription
- Process payments through our payment processor (Stripe)
- Send transactional communications (account verification, security alerts, billing notices)
- Detect, prevent, and address fraud, abuse, and security issues
- Enforce our Terms of Service and community guidelines
- Generate anonymized, aggregated analytics to improve the Service
4. Third-Party Service Providers
We share information with the following categories of third-party service providers, solely to operate and improve the Service:
- AI Model Providers: We send your analysis requests (ticker symbols and market data) to AI model providers to generate analysis reports. We do not send personally identifiable information (PII) to AI providers.
- Payment Processor (Stripe):Stripe processes your payment information directly. We do not store credit card numbers. Stripe's privacy policy applies to their handling of your payment data.
- OAuth Providers (Google, Facebook, Apple): When you use social sign-in, we receive only the public profile information you authorize. We do not receive your password from these providers.
- Market Data Providers: We use third-party APIs to fetch market data. These requests do not include your personal information.
- Hosting Provider (Render):Our Service is hosted on Render's infrastructure, which stores and processes data on our behalf.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties. We may disclose your information only in the following circumstances:
- With Your Consent: When you explicitly authorize us to share information
- Legal Requirements: When required by law, subpoena, court order, or governmental regulation
- Protection of Rights: When necessary to protect the rights, safety, or property of WayJet Inc., our users, or the public
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as a business asset
- Aggregated Data: We may share anonymized, aggregated data that cannot be used to identify you
6. Data Security
We implement industry-standard security measures to protect your data, including: TLS/SSL encryption for data in transit; encrypted storage for sensitive data (API keys, passwords); bcrypt password hashing; JWT authentication with refresh token rotation; two-factor authentication (2FA/TOTP) support; role-based access controls; and regular security audits. However, no method of electronic storage or transmission over the Internet is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Upon account deletion, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, dispute resolution). Anonymized, aggregated data may be retained indefinitely for analytics and service improvement.
8. Your Rights Under GDPR (European Users)
If you are a resident of the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate personal data
- Right to Erasure: Request deletion of your personal data and account
- Right to Data Portability: Request your data in a machine-readable format
- Right to Restrict Processing: Request limitation of processing of your data
- Right to Object: Object to processing of your data for certain purposes
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
To exercise these rights, contact us at privacy@shinefin.org. We will respond within 30 days.
9. Your Rights Under CCPA (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following rights:
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you
- Right to Delete: You may request that we delete your personal information, subject to certain exceptions
- Right to Opt-Out:We do not sell personal information. If we ever change this practice, we will provide a “Do Not Sell My Personal Information” link
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights
To exercise these rights, contact us at privacy@shinefin.org. We will verify your identity before processing your request.
10. Cookies and Tracking Technologies
We use browser localStorage to store user preferences (theme, language settings) and authentication tokens. We do not use third-party tracking cookies, advertising cookies, or analytics cookies. We respect Do Not Track (DNT) browser signals. Our Service does not track users across third-party websites.
11. Children's Privacy (COPPA)
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly. If you believe we have inadvertently collected information from a child under 18, please contact us at privacy@shinefin.org.
12. International Data Transfers
Your information may be transferred to and processed in the United States and other countries where our service providers operate. These countries may have data protection laws different from those in your jurisdiction. By using the Service, you consent to the transfer of your information to the United States. We take appropriate safeguards to ensure your data is treated securely and in accordance with this Privacy Policy.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the “Last Updated” date and, where appropriate, sending an email notification. We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes are posted constitutes your acceptance of the revised Privacy Policy.
14. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us: