MarketMate Privacy Statement
Last updated: 5 August 2026
Scope
Welcome to MarketMate's Privacy Statement. Your right to privacy and online security is important to us. This Privacy Statement describes MarketMate's collection, protection, disclosure and use of the personal information provided to or collected through our service. It applies to the MarketMate applications for Android and iOS, to marketmatehq.com, and to every online service we operate that links to or references this Privacy Statement.
MarketMate is operated by Movent (Private) Limited ("MarketMate", "we", "us", "our"), which is the controller of the personal information described here. Our contact details are at the end of this statement.
If you do not agree with any of the practices described in this Privacy Statement, please do not use our services.
Here's a quick overview:
MarketMate is a market information app. It shows share prices, index levels, charts and news for the Pakistan Stock Exchange. It is not a broker and not a bank. We do not execute trades, we do not hold money or securities for you, and we ask for no bank details, card numbers or national identity numbers. That shapes this entire statement, because the most sensitive information a finance app usually holds is information we never ask for.
You can use MarketMate without an account. Browsing prices, indices, charts and news requires no sign-up, and in that state we hold no account information about you at all. An account exists so that the lists you build follow you between your devices, and so that our support team can reply when you write to us.
If you create an account, we ask for an email address, a username and a password, and you may add a display name. We use the email address to confirm the account is yours, to send password resets, and to contact you about your account. Anything you save in the app while signed in, such as the companies you choose to follow, is stored against your account so it is there when you sign in somewhere else.
We also collect some information automatically, such as your device type, your app version and your IP address, along with anonymous diagnostic and usage information. We use it to keep the service running, to fix what breaks, to protect accounts from abuse, and to understand which parts of the app people actually use. These systems are deliberately built so that they cannot record which individual companies you look at.
We do not sell your personal information, and we do not share it with anyone for their own marketing. MarketMate carries no advertising today. We are working on an advertising-supported version, and the ADVERTISING section below explains in advance exactly what that will change, what your choices will be, and our commitment to update this statement and ask for your consent where the law requires it before any of it starts.
MarketMate and its service providers maintain operations in several countries and may process your personal information outside the country where you are located. Some of those jurisdictions may not provide the same level of data protection as your home jurisdiction. By choosing our service and providing information to us, you agree to that transfer, storage and processing. Wherever your information is held, we apply technical, organisational and contractual safeguards designed to protect it and to keep it processed in line with this Privacy Statement.
MarketMate is intended for people aged 16 and over. We do not knowingly collect personal information from anyone under 16, and the AGE REQUIREMENT section explains what happens if we learn that we have.
DATA WE COLLECT AND HOW WE USE IT
When you use MarketMate, we may collect the following information about you.
Information you provide to us
Registration information. When you create an account we ask for an email address, a username and a password, and you may optionally set a display name. We require an email address so that we can confirm the account belongs to you, contact you about it, and let you recover it if you forget your password. You can change your username and display name at any time in the app. Changing your email address is not supported in the app today, so write to us if you need it changed.
To confirm the address is yours we send you a short numeric code by email. Codes are stored only as cryptographic hashes and expire quickly. Your password is likewise stored only in a hashed form that cannot be reversed, so nobody at MarketMate can read it, and it is never written to your device.
Content you create in the app. While you are signed in, what you save in the app is stored against your account so it is available on your other devices. Today that means the list of companies you choose to follow, which holds ticker symbols and nothing else. Features currently in development will let you record more, for example entering the quantity and purchase price of a holding so the app can show you a portfolio view. If and when those ship, what you type is stored against your account, is visible only to you and to the staff described under "Access by our staff", and this statement will describe it before the feature reaches you.
Nothing you save in MarketMate is public. There is no social feature, no sharing between users and no public profile.
Support messages. If you contact us from inside the app, we receive the topic you selected and the message you wrote, stored against your account so we can reply. That is all a support message carries. There is no attachment, no image, and nothing about your device or your activity is gathered and sent along with it.
Other information. If you write to us by email, respond to a survey, or send us feedback, questions, comments or suggestions, we keep that correspondence and use it to answer you and to improve the service.
Information we collect automatically
Device and connection information. When your device requests anything from our servers, that request carries your IP address, as every internet request does, along with ordinary connection information such as your app version, your operating system version and your device model. We use it to serve the request, to keep the service available, to limit abuse, and to diagnose faults.
Session and security information. When you sign in, we store a record of that session so we can keep you signed in and so every session can be ended if something goes wrong. That record holds a hash of your session token, never the token itself, together with the IP address and device description the session was created from, and the times it began and ended. We use it to detect stolen sessions and unauthorised access to accounts.
Diagnostic information. When the app crashes or hits a serious error, it sends a diagnostic report to our error reporting provider so we can find and fix the fault. A report contains the error, where it happened in our code, the app version, the device model and the operating system version. It does not contain your name, your email, your account identifier, your IP address, a screenshot, a recording, or a record of what you tapped.
Usage information. We collect anonymous information about how the app is used, such as which screens are opened and whether people return, together with the app version, device model and operating system version. We use it to decide what to build and to see whether a change helped. These events are not linked to your account, your email or your username.
We deliberately cannot see which companies you look at. Both the diagnostic and the usage systems are built so that a company's ticker symbol can never travel with an event. Screen names come from a fixed internal list rather than from the contents of the screen, so a company's detail screen always reports under one generic name, and any address that might carry a ticker symbol is stripped before a report leaves your device. This is enforced in our code and covered by automated tests, not merely promised here. We say so plainly because it is unusual, and because we think what you research is your business.
Content delivery. Company logos and news stories are fetched from our own delivery services as you use the app. Those services receive an ordinary web request carrying your IP address. They set no cookies, require no account, and return the same content to everyone. To reduce what any single logo request could imply, the app fetches the whole logo catalogue in the background rather than one mark at a time.
Information we do not collect
- Location of any kind, precise or approximate.
- Contacts, calendar, photos, microphone, camera, call logs or message logs. The app opens no photo picker and asks for no access to your media.
- Bank details, card numbers, account numbers or national identity numbers. The app takes no payments and performs no identity verification.
- Any advertising identifier, for as long as the app carries no advertising. See ADVERTISING below for what changes if that becomes part of the product.
- Any identifier that follows you into other companies' apps or websites. We do not track you across services, and we do not build a profile of you for anyone else.
MORE INFORMATION ABOUT HOW WE USE DATA
We process your information to provide, support and secure our service, both automatically and manually. For example, we may use your information in the following ways:
- To create and maintain your account and keep you signed in across your devices.
- To store and return the lists and other content you save in the app.
- To confirm that an email address belongs to you, and to let you recover an account you have been locked out of.
- To answer your questions and follow up on the issues you report to us.
- To detect and protect against errors, fraud, abuse and other criminal activity, including limiting how often a single address can attempt to sign in and detecting a session token that has been used from somewhere it should not be.
- To verify your identity when you contact us for help with your account.
- To diagnose and fix faults, and to monitor the health and performance of our systems.
- To analyse service usage, plan work, develop the product and understand how the app is used in aggregate.
- To communicate with you about the service, including verification codes, password resets, security notices and changes to this Privacy Statement.
- To enforce our Terms of Service.
- To comply with the law, and to establish, exercise or defend legal claims.
Access by our staff. MarketMate operates an internal administration console. Authorised staff can view account records, including your email address and username, and can suspend or restore an account. It exists so that we can answer support requests, investigate abuse and enforce our Terms. Access to it is separate from ordinary user accounts, is protected by its own identity checks, and is used for a reason, not for browsing.
NOTIFICATIONS AND COMMUNICATIONS
Email. We send you email that the service requires, such as verification codes, password resets, security notices, replies from support and notices about material changes to this Privacy Statement. These are necessary to operate your account and cannot be switched off while you hold one. If we ever start sending optional email such as product news, it will be something you choose, and every one of those messages will carry a way to unsubscribe.
Push notifications. The app asks for notification permission, and we want to be straightforward about the current state: push notifications are being built and the app does not send any yet. When they arrive they are expected to cover things you ask us to watch for, such as market open and close or a price movement on a company you follow. Delivering them will mean storing a notification token issued by Google or Apple for your device and linking it to your account, and it will mean sending the message text through Google's or Apple's push service, which is the only way any app on your phone can deliver a notification. This statement and our app store disclosures will be updated to describe it before the first notification is sent. Notifications are optional. You can decline the permission, turn them off in your device's settings at any time, and we will provide in-app controls for what they cover.
ADVERTISING
MarketMate carries no advertising today. There is no ad network in the app, no advertising identifier is read, and nothing about you is shared with an advertising company.
We are working on an advertising-supported version of MarketMate, and we would rather describe it now than surprise you later. When advertising is introduced, expect the following.
- Ads would be served by an advertising provider, most likely Google AdMob. To fill an ad slot, the provider's software receives information from your device, typically including your IP address, device and operating system information, the app you are using, and your device's resettable advertising identifier, which on Android is the Advertising ID and on iOS is the Identifier for Advertisers.
- That provider would act for its own purposes as well as ours, so it is more than a supplier working only on our instructions, and its own privacy policy would govern what it does with what it receives.
- In the European Economic Area, the United Kingdom and Switzerland we will ask for your consent before any personal data is used for ads personalisation, using a recognised consent interface, and you will be able to change your answer later.
- On iOS, personalised advertising requires Apple's App Tracking Transparency permission. If you decline it, we cannot access your device's advertising identifier, and you would see non-personalised ads instead. Declining will never cost you access to any part of the app.
- On Android you can reset or delete your advertising identifier, and opt out of personalised ads, in your device settings. On iOS the same control lives in Settings under Privacy and Security.
- Your account, your saved lists and the companies you research would not be handed to an advertising network. The protections described above, which keep a ticker symbol out of our diagnostic and usage systems, are ones we intend to hold to here as well.
None of this is in effect yet. This statement, the Google Play Data safety declaration and the Apple App Privacy labels will all be updated in the same release that introduces advertising, before any ad is shown to you.
MORE INFORMATION ABOUT THIRD PARTY SERVICES
We keep the list of companies that touch your information deliberately short. There is no data broker on it, no attribution vendor, and no third-party sign-in service.
| Who | What they receive | Why |
|---|---|---|
| Our error reporting provider (Sentry) | Anonymous diagnostic reports | So that we learn the app broke, and where |
| Our product analytics provider (PostHog), whose servers for our account are in the European Union | Anonymous usage events | So that we learn which parts of the app are used |
| Our email delivery provider (Resend) | Your email address and the contents of the account emails we send you | So that our email actually reaches you |
| Our network and content delivery provider (Cloudflare) | Requests to our services, including your IP address, as they pass through | Security, protection against attacks, and speed |
| Our database and server hosting providers (Supabase and Hetzner) | Our systems, and therefore the information described above, at rest and in processing | So that the service exists |
| Google Play and the Apple App Store | Whatever each collects as the app store, under its own privacy policy | Distribution, installs and updates |
Each of these acts as our service provider. They are contractually obliged to protect your information in a manner consistent with this Privacy Statement, to process it only on our instructions, and not to use it to build their own profile of you or to market to you.
Market data travels toward you, not away from you. Prices, index levels and company history reach us from the exchange's feed and are the same for every user. We never tell the exchange, a data provider, or any other company which companies you looked at.
We currently offer no sign-in with another company's account. If we add one, that provider would tell us your name and email address only with your permission, and this statement would describe it before the feature ships.
MarketMate provides no public API, so no other application can be authorised to read your MarketMate account.
MORE INFORMATION ABOUT HOW WE SHARE YOUR INFORMATION
Vendors and other partners. As set out in the table above, we use service providers to host, deliver, secure and diagnose the service. Where permitted by law and where the arrangement is not one of pure processing, such as the future advertising arrangement described above, that company's own privacy policy governs what it does with the information it receives, and we identify it here so you can read it.
We do not sell your personal information, and we do not share it with third parties for marketing purposes.
For legal matters. We will disclose personal information when required by applicable law, and we will do our best to keep any such disclosure limited and proportionate. For example, we may disclose information:
- To respond to subpoenas, court orders or bona fide legal process.
- To investigate, prevent, defend against or take other action regarding violations of our Terms of Service, illegal activity, suspected fraud, or situations involving potential threats to the legal rights or physical safety of any person or to the security of our service.
- To respond to claims that content violates the rights of a third party.
- In an emergency, to protect the health and safety of our users.
- As otherwise required by any applicable law.
Business transfer. If our company or our assets are acquired by another company, the transfer may include user information. In that case the acquiring party assumes the rights and obligations regarding that information as described in this Privacy Statement.
Non-identifiable information. We may disclose aggregated or de-identified information that cannot reasonably be used to identify you, for example the total number of people using a feature, to service providers and other third parties, and to help us understand how our service is used collectively.
SECURITY
We take the security of your information seriously, and we use technical and administrative measures designed to protect it.
Every connection carrying your information is encrypted in transit. Passwords are stored only in a hashed form that cannot be reversed, and verification codes and session tokens are stored only as hashes, so a copy of our database contains no usable password, code or token. On your device, the short-lived credential that keeps you signed in is held in memory only and never written to storage, and the long-lived one is encrypted using your device's hardware-backed secure storage, the Android Keystore or the iOS Keychain, so it cannot be lifted off the device. Our servers sit behind a filtered network edge, refuse traffic that does not arrive through it, and rate-limit attempts to break into accounts. Access to production systems is restricted to the people who need it.
Please understand that while we work hard to safeguard your personal information once we receive it, no transmission of data over the internet or any other public network can be guaranteed to be completely secure. You can protect your own information by choosing a strong and unique password, by not reusing it elsewhere, and by keeping your device secure and up to date.
We will contact you, and the relevant authority, as required by applicable law in the event of a breach affecting the security, confidentiality or integrity of your personal information.
COOKIES AND SIMILAR TECHNOLOGIES
The MarketMate apps use no cookies. They contain no embedded browser, no tracking pixel and no cross-app tracking technology. What the apps store on your device is listed in the next section, and none of it follows you into another company's app or website. If advertising is introduced, the ADVERTISING section above describes the device identifiers that would then come into play, and this section will be updated at the same time.
marketmatehq.com serves this statement and our other public pages. It sets no cookies and runs no advertising or web analytics trackers.
Your browser or device may include a "Do Not Track" setting. Our collection and disclosure practices, and the choices we offer, operate as described in this Privacy Statement whether or not such a signal is received. As we run no cross-site tracking, there is at present nothing for such a signal to switch off.
WHAT IS STORED ON YOUR DEVICE
| What | Where | Protection |
|---|---|---|
| The credential that keeps you signed in for the current session | Memory only | Never written to storage. It is gone when the app closes |
| The credential that signs you back in later | App-private storage | Encrypted using the device's hardware-backed secure storage |
| The last known price board and news | App-private internal storage | So the app opens with content rather than a blank screen. Public market data only, cleared when you sign out |
| App settings | App-private storage | Small flags, such as whether we have already asked about notifications |
| Company logo images | App-private cache | An ordinary image cache |
None of this is readable by other apps. The stored board, the news and your encrypted sign-in credential are excluded from cloud backup and device transfer, so they do not travel to a new phone, and signing in on a new device means signing in again.
What you save to your account is not kept in long-term storage on the device. It lives with your account and is fetched when you sign in, so it cannot outlive your session on a shared or lost phone.
CHOICE AND ACCESS, CLOSING YOUR ACCOUNT, AND DATA RETENTION
Choice and access to your personal information
You may access, review and update the personal information you have given us. Your username, display name and email address are shown in the app under Personal information, and the first two can be changed there. If you need help updating or correcting your information, or you want a copy of the personal information we hold about you, write to privacy@marketmatehq.com and we will answer within one month.
Your choices about the data we collect
In many cases you have a choice about what you give us, and about how we use it. Those choices, and what they cost you, are as follows.
- Use the app without an account. Prices, indices, charts and news need no sign-up, and as a guest you give us no account information at all. What you lose is the ability to save anything that follows you between devices, and the ability for support to reply to you.
- Personal information. You may decline to give us your email address or other details, but you will not be able to use the features that need an account.
- Notifications. You can decline the notification permission and change it at any time in your device settings. Today nothing is lost by declining, because the app sends none yet.
- Diagnostics and usage information. We want to be straightforward here as well: there is no in-app switch for these today. The capability is built into the apps ahead of a settings control that has not shipped, and until it does, the honest position is that the released apps send the anonymous diagnostic and usage information described above. If you would rather they did not, write to privacy@marketmatehq.com and we will act on your objection. When the control ships, this statement will point you to it.
- Advertising. None is shown today. If it is introduced, your choices are described in the ADVERTISING section, and in the European Economic Area, the United Kingdom and Switzerland we will ask for your consent first.
- Stop everything. Deleting your account and uninstalling the app ends all collection.
Closing your account
You may close your MarketMate account at any time from the app, under Account, then Personal information, then Delete account. This is not a freeze, and there is no way for you to undo it.
The moment you confirm, every session on every device is revoked, you are signed out, and your username is retired permanently so nobody can claim it and pretend to be you. Your account is then marked as deleted, cannot be used, and is permanently erased from our systems 30 days later by an automatic sweep. That short window exists so that a deletion made by mistake, or by somebody who got into your account, can be investigated, and so that a dispute has a record. We will not restore an account during it except in response to a request we have verified came from you.
When the record is erased, what was attached to it goes with it: your email address, your stored password hash, your saved lists and other saved content, your support messages, your verification records and your session records. The retired username is kept on its own, because reissuing it would let somebody impersonate you.
If you have uninstalled the app, or you can no longer sign in, write to privacy@marketmatehq.com and ask us to delete your account. We will use your email address to confirm the request came from you before we act on it.
Deleting your account does not reach back into the anonymous diagnostic and usage information already collected, because none of it was ever linked to your account and there is no key by which we could find yours.
Data retention
We retain your information for as long as necessary to serve you and to operate our business, in accordance with applicable law. In particular:
| What | How long |
|---|---|
| Your account and everything saved to it | While the account exists, then permanently erased 30 days after you delete it |
| Verification codes and sign-up sessions | Deleted 7 days after they are used or expire |
| Session records, including the IP address and device description they carry | Deleted 30 days after the session is revoked, rotated or expires |
| Retired usernames | Kept on their own, indefinitely, so a handle cannot be reused to impersonate |
| Diagnostic reports | On our provider's standard schedule, currently 90 days |
| Usage events | Kept as anonymous usage data, not linked to any account |
| Server and network request logs | A short operational period, for security and fault diagnosis |
We may retain personal information for longer where we must to comply with the law, prevent fraud, resolve disputes or enforce our Terms of Service.
Other legal information
We process personal data only when we have a valid legal basis under applicable data protection law. For users in the European Economic Area and the United Kingdom this means the bases set out in the GDPR, and comparable protections apply in other jurisdictions. Those bases may include:
- Contractual necessity, when processing is required to provide what you asked for, such as creating your account, keeping you signed in, storing what you save and answering your support message.
- Legitimate interests, when processing is needed to keep the service secure, available and honest, or to improve it, provided those interests are not overridden by your rights. This covers fault diagnosis, anonymous usage measurement, rate limiting and the detection of unauthorised account access. The collection described in this statement is deliberately built to be the least that answers the question.
- Consent, for example where we ask before using personal data for personalised advertising. You may withdraw consent at any time.
- Legal obligations, where the law requires us to process or retain information.
Depending on where you live, you may have the right to access a copy of your information, correct it, delete it, restrict or object to how we use it, receive it in a portable format, withdraw a consent you have given, and complain to your local data protection authority. To exercise any of these, write to privacy@marketmatehq.com. No matter where you are located, we apply appropriate safeguards and honour the rights available to you under the data protection laws that apply in your jurisdiction.
WHERE YOUR INFORMATION IS PROCESSED
We and our service providers operate in several countries, so your information may be processed outside the country you are in. Our servers are located in Germany, our usage analytics are processed in the European Union, and our email delivery, network and diagnostics providers operate from their own locations, which may include the United States and countries in the European Union. Our own team works from the country given in our contact details at the end of this statement, and administers the service from there.
Our database is hosted with Supabase in Frankfurt, Germany, in the European Union. It is therefore in the same country as our servers, so the personal information in your account does not leave Germany in the ordinary course of running the service.
Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses where applicable.
AGE REQUIREMENT
MarketMate is intended for people aged 16 and over, and it is not directed at children. You must be at least 16 to use the service and to create an account. Where the law in your country sets a higher age for consent to the processing of personal data, that higher age applies.
We do not knowingly collect personal information from anyone under 16. If we learn that we have, we will delete the account and the information without delay. If you believe someone under 16 has given us personal information, write to privacy@marketmatehq.com and we will remove it.
CHANGES
We may update this Privacy Statement from time to time. If we make material changes, we will notify you, including in the app where the change affects how the app handles your information. Changes are effective upon posting unless we say otherwise, and the date last updated appears at the top of this Privacy Statement.
CONTACT US
Got questions?
If you have questions or concerns regarding this Privacy Statement, or you want to exercise a right described in it, please contact us:
Privacy: privacy@marketmatehq.com Support: support@marketmatehq.com
Mailing address: Movent (Private) Limited FN-40, Wahdat Colony, Wahdat Road Lahore, Punjab 54000 Pakistan