Privacy Policy

Your data, your control

How PakStockLab collects, uses and protects your personal and portfolio information, in plain language.

Last updated: October 2, 2026

We never sell your data

Your information is not sold, rented or traded to advertisers or data brokers.

Read-only email access

Broker email sync only reads trade confirmations, and you can disconnect it at any time.

Encrypted & isolated

Data is encrypted in transit, email tokens are encrypted at rest, and each account's data is isolated.

You stay in control

Access, correct, export or delete your data by contacting us.

01

Overview

PakStockLab (“PakStockLab”, “we”, “us” or “our”) is a research, screening and portfolio-tracking platform for investors in the Pakistan Stock Exchange (PSX). This Privacy Policy explains what personal information we collect when you use our website and services (the “Service”), why we collect it, who we share it with, and the choices you have.

By using the Service you acknowledge the practices described here. If you do not agree, please do not use the Service. This policy should be read together with our Terms of Service.

02

Information we collect

We collect only what we need to run the Service. You can view market data and company research without an account.

Information you give us

  • Account details. Your name and email address when you sign up with email, or the basic profile (name, email address and profile picture) Google shares with us when you choose “Sign in with Google”.
  • Portfolio and investment data. Holdings, buy and sell transactions, dividends, deductions, watchlists, price alerts and settings that you enter, import or sync.
  • Imported files. Broker statements, contract notes or spreadsheets you upload so we can extract your trades.
  • Messages to us. Your name, email address and the content of any message you send through our contact form or by email.

Information collected automatically

  • Usage and device data. Pages visited, features used, browser type, device type, IP address and timestamps, collected through server logs.
  • Cookies and local storage. Used to keep you signed in and remember your preferences. See Cookies & local storage.

Information from connected services

  • Broker email sync (optional). If you connect a Gmail or Outlook mailbox, we access messages from your broker that contain trade confirmations. See Broker email sync for details.
03

How we use your information

We use your information to:

  • Create and secure your account, and authenticate you when you sign in.
  • Calculate and display your portfolio value, cost basis, profit & loss, dividends and performance.
  • Send the price, change and volume alerts you set up, plus essential service notices.
  • Extract trades from documents and emails you choose to import or sync.
  • Respond to your questions, support requests and feedback.
  • Monitor, debug and improve the reliability, performance and security of the Service.
  • Detect and prevent fraud, abuse and violations of our Terms.
  • Comply with applicable legal obligations.

We do not use your portfolio data for advertising, and we do not make automated decisions about you that produce legal or similarly significant effects.

04

Broker email sync

Broker email sync is an optional feature that imports trades from the contract notes your broker emails you. It is completely separate from “Sign in with Google”, which only shares your basic profile.

  • Read-only access. We request read-only permission (Gmail gmail.readonly or Microsoft Mail.Read). We cannot send, delete or modify your email.
  • Only broker messages. We scan message metadata to identify emails from supported brokers, and only download and parse the contract-note attachments from those messages. Other emails are not stored.
  • Protected tokens. Access tokens are encrypted at rest with AES-256-GCM and are never exposed to your browser.
  • Your review first. Detected trades appear in your Import Inbox, where you can review, import or reject them.
  • Disconnect anytime. Disconnect a mailbox from the Broker Email Sync page, and revoke access from your Google or Microsoft account settings.

Google API Services User Data Policy

PakStockLab's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to provide the trade import feature you enabled. It is never used for advertising, never sold, and never read by people except with your consent, for security purposes or where required by law.

05

AI-assisted import

When a statement can't be read by our built-in parsers, you may choose AI-assisted import. The text of that document is sent to our AI inference provider solely to extract trade details such as symbol, quantity, price and fees. The results are shown to you for review before anything is saved.

We send only the document you chose to import. We do not send your wider portfolio, account credentials or email content to the AI provider.

06

How we share information

We do not sell your personal information. We share it only in the following limited cases:

  • Service providers. Trusted vendors that host and operate the Service on our behalf under confidentiality and data-protection obligations. These include Supabase (database and authentication), Vercel (hosting), Google and Microsoft (sign-in and the email sync you authorise), and our AI inference provider (AI-assisted import).
  • Legal reasons. When required by law, regulation, legal process or a valid government request, or to protect the rights, property or safety of PakStockLab, our users or the public.
  • Business transfers. In connection with a merger, acquisition or sale of assets, subject to this policy's protections.
  • With your consent. Any other sharing happens only when you ask us to.
07

Cookies & local storage

We use a small number of first-party cookies and browser storage items:

  • Essential. Authentication cookies that keep you securely signed in, plus short-lived cookies that protect sign-in and mailbox-connection flows against forgery.
  • Preferences. Local storage remembering choices such as theme, currency and table layout.

We do not use third-party advertising cookies or cross-site tracking. You can clear or block cookies in your browser settings, but essential cookies are required to sign in.

08

Data retention

We keep your account and portfolio data for as long as your account is active, so your history and performance stay accurate. If you ask us to delete your account, we delete or anonymise your personal data within 30 days, except where we must keep certain records to meet legal, security or dispute-resolution obligations.

Contact-form messages are kept only as long as needed to handle your request. Server logs are kept for a limited period for security and troubleshooting.

09

How we protect your data

  • All traffic between your browser and PakStockLab is encrypted with HTTPS/TLS.
  • Database row-level security ensures each account can only access its own portfolio data.
  • Email-sync tokens are encrypted at rest; passwords are handled by our authentication provider and never stored in plain text.
  • Access to production systems is limited to authorised personnel who need it.

No system is perfectly secure. If you believe your account has been compromised, please contact us immediately. If we become aware of a breach affecting your personal data, we will notify you as required by law.

10

Your rights & choices

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete information. Most portfolio data can be edited directly in the app.
  • Delete your account and associated data.
  • Export your data in a portable format.
  • Withdraw consent for optional features such as broker email sync, at any time.
  • Object or restrict certain processing of your information.

To make a request, email support@finvision.pk or use our contact form. We may need to verify your identity, and we aim to respond within 30 days.

11

Children's privacy

The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has given us personal information, please contact us and we will delete it.

12

International transfers

PakStockLab is built for investors in Pakistan, but some of our service providers process data on servers outside Pakistan. Where data is transferred internationally, we rely on providers that maintain appropriate safeguards to protect it in line with this policy.

13

Changes to this policy

We may update this Privacy Policy as the Service evolves or the law changes. We will change the “Last updated” date above and, for material changes, notify you by email or with a notice in the app before they take effect.

Still have questions?

Our team is happy to explain anything on this page. Also see our Terms of Service.

Contact us