NEOBANKSTER · LEGAL
Privacy Policy
Effective 15 September 2026 · Last updated 15 September 2026 · Version 2026-09-15
This policy explains how Neobankster handles personal data when you use neobankster.com, its account and platform subdomains, newsletters, research delivery and related services (together, the “Service”). In this policy, “Neobankster”, “we”, “us” and “our” refer to Neobankster.
Who is responsible for your data
Neobankster determines why and how personal data is processed through the Service. You can send a privacy request through the contact channel published on the Website and label it “Privacy request”.
Data we collect
- Account and waitlist data: email address, name, password credential handled by our authentication provider, email-verification state, optional organization, professional role, intended use, access status and access history.
- Newsletter and research data: email address, the form and notice you consented to, source, timestamps, confirmation or unsubscribe status, delivery state and a hashed request identifier used for abuse prevention.
- Account activity: saved items, preferences, authentication events and actions taken in private administration areas where applicable.
- Technical and security data: IP address, browser and device information, request time, pages requested and diagnostic or security logs. We hash identifiers where the feature does not need the original value.
- Optional analytics data: page views, approximate location, device and interaction information collected by Google Analytics only after you consent.
- Communications: information you choose to include when contacting Neobankster.
Why we use it and our legal bases
- To create, verify and secure an account, provide requested features and administer the waitlist: performance of our agreement and our legitimate interests in operating a secure pre-launch service.
- To send a requested verification, confirmation, research-delivery or service message: performance of your request or our agreement.
- To send newsletters and measure optional analytics: your consent, which you may withdraw at any time.
- To prevent abuse, investigate incidents, maintain audit records and comply with law: our legitimate interests and legal obligations.
We do not sell personal data or use Google Analytics for advertising or ad personalization.
Who processes data for us
We use service providers where needed to run the Service, including Cloudflare for hosting and security, Supabase for database and account authentication, Resend or a configured mail provider for transactional email, and Google Analytics after analytics consent. Providers process data under their own terms and our applicable instructions. We may also disclose information when required by law, to protect people or the Service, or as part of a business reorganization subject to appropriate safeguards.
International transfers
Some providers may process data outside your country. Where applicable, we rely on an adequacy decision, approved contractual safeguards or another lawful transfer mechanism and apply supplementary safeguards as appropriate.
How long we keep data
Account and waitlist data is kept while the account or request remains active and for a limited period afterward where needed for security, disputes or law. Newsletter data is kept until you unsubscribe or we no longer provide the newsletter; a minimal suppression record may be kept so we respect your choice. Consent and access records are retained as needed to demonstrate the request and protect the Service. Delivery tokens expire automatically, while operational logs are retained only for the period reasonably necessary for security and troubleshooting.
Your choices and rights
Depending on your location, you may ask for access, correction, deletion, restriction, portability or objection; withdraw consent; and complain to your local data-protection authority. Withdrawal does not affect processing already carried out lawfully. We may need to verify your identity before completing a request.
You can change analytics consent through Cookie settingsin the footer. Newsletter messages will include an unsubscribe route.
Security and children
We use access controls, encryption in transit, private storage, audit trails and data minimization appropriate to the Service. No system can guarantee absolute security. The Service is not directed to children under 16, and we do not knowingly collect their personal data.
Changes
We may update this policy as the Service changes. We will post the new version and effective date here and provide additional notice when a material change requires it. See the separate Cookie Policy for storage details.