Privacy Policy
Effective date: April 1, 2026 · Applies to: VETTR (app.vettr.ca) and the VETTR API (api.vettr.ca)
1. Who we are
VETTR is operated by Hextrot Inc., incorporated in Ontario, Canada("we", "us", or "our"). We provide a financial intelligence platform for researching Canadian public companies listed on the TSX and TSXV.
For privacy questions, contact us at: privacy@vettr.ca
2. Information we collect
Account information
When you register, we collect your email address and a hashed password. We do not collect payment card numbers directly — billing is handled by our payment processor (Stripe).
Usage data
We log API requests, page views, search queries, watchlist and portfolio activity, and feature interactions to improve the product and detect abuse. Logs are retained for 90 days.
Device and technical data
We collect your IP address, browser user-agent, and (if you enable push notifications) a browser push subscription endpoint. We do not use persistent third-party tracking cookies.
AI chat inputs
Messages you send through the in-app AI chat are transmitted to Anthropic's API to generate responses. These messages may be processed on Anthropic's servers located in the United States. We do not use your chat inputs to train AI models.
3. How we use your information
- Authenticate your account and keep it secure
- Provide and improve the VETTR platform and its features
- Send you notifications you have subscribed to (red flag alerts, score changes, insider activity)
- Respond to support requests
- Comply with legal obligations
- Detect and prevent fraud or abuse
We do not sell your personal information to third parties.
4. Cross-border data transfers
VETTR's infrastructure is hosted on cloud services that may store and process data outside Canada, including in the United States and the European Union. Specifically:
- API and database servers are hosted on DigitalOcean infrastructure (data centre region: Toronto, Canada — TOR1). Data at rest remains in Canada.
- Frontend hosting is provided by Vercel, which may serve content via edge nodes globally. No personal data is stored on edge nodes.
- AI chat messages are transmitted to Anthropic's API, operated by Anthropic PBC, a U.S. company. These messages may be processed on U.S.-based servers. By using the AI chat feature, you consent to this transfer.
- Push notifications are delivered via browser-native Web Push, which routes through the browser vendor's push service (e.g., Google FCM for Chrome, Mozilla for Firefox).
Where transfers occur outside Canada, we rely on contractual safeguards with our sub-processors and ensure they maintain adequate data protection standards consistent with Canadian privacy law (PIPEDA / Law 25 in Quebec).
5. Quebec residents — Law 25 (Act 25)
Quebec's Act respecting the protection of personal information in the private sector(Law 25) grants Quebec residents additional rights. We have conducted a Privacy Impact Assessment (PIA) for cross-border transfers of personal information from Quebec, as required under section 17 of Law 25. A summary is available on request.
If you are a Quebec resident, you have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your information (right to be forgotten)
- Object to automated decision-making that significantly affects you
- Data portability — receive your data in a structured, commonly used format
To exercise these rights, email privacy@vettr.ca. We will respond within 30 days.
6. Retention
We retain your account data for as long as your account is active, plus 90 days after deletion to handle refund requests or legal obligations. API logs are retained for 90 days. Anonymised aggregate analytics may be retained indefinitely.
7. Security
Passwords are hashed using bcrypt. API connections use TLS. We apply the principle of least privilege to internal data access. Despite these measures, no system is fully secure — please use a strong, unique password and contact us immediately if you suspect unauthorised access.
8. Cookies and local storage
We use browser localStorage to store your JWT authentication token, UI preferences, recent search history, and push notification state. We do not use third-party advertising cookies. We use a single session cookie for authentication management (HttpOnly, SameSite=Strict).
9. Third-party services
- Anthropic — AI inference for in-app chat. Privacy policy: anthropic.com/privacy
- DigitalOcean — Server hosting. Privacy policy: digitalocean.com/legal/privacy-policy
- Vercel — Frontend hosting and CDN. Privacy policy: vercel.com/legal/privacy-policy
10. Children
VETTR is not directed at children under 13 (or under 14 in Quebec). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us to have it removed.
11. Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated by updating the effective date at the top of this page and, where appropriate, by in-app notification. Continued use of VETTR after changes are posted constitutes acceptance.
12. Contact
Privacy inquiries: privacy@vettr.ca
Hextrot Inc., Ontario, Canada
Not financial advice. VETTR provides information and analytical tools for research purposes only. Nothing on this platform constitutes investment advice, a recommendation to buy or sell any security, or a solicitation of any investment. Past performance of any company or score is not indicative of future results. Always conduct your own due diligence and consult a registered investment advisor before making investment decisions. VETTR and Hextrot Inc. are not registered as investment advisors, portfolio managers, or dealers under any applicable securities legislation.