Privacy Policy
Effective date: 8 July 2026 · Last updated: 8 July 2026
Northtape (app.marcomfin.tech) is a free market intelligence app for crypto, fintech, blockchain and regulation news. This policy explains what personal data we collect, why, who we share it with, and the rights you have over it — under the Singapore Personal Data Protection Act 2012 (PDPA), the EU General Data Protection Regulation (GDPR) and the UK GDPR.
- We collect only what the app needs: your email (and name/avatar if you sign in with Google), your watchlist, keywords, notification preferences, and if you enable them — push notification subscriptions.
- Our analytics are cookieless and aggregate. We do not run advertising trackers, sell your data, or profile you.
- AI summaries and briefs are generated from public news articles and your saved preferences; your chat questions are processed to answer them and are not used to build a profile of you.
- You can export or delete your data at any time by deleting your account or emailing us.
- Complaints: contact us first; you may also complain to the Singapore PDPC, the UK ICO, or your EU supervisory authority.
1. Who we are
Northtape is operated from Singapore and is the controller of the personal data described in this policy. Contact: privacy@marcomfin.tech.
2. Data we collect
We collect only the following, and nothing else:
- Account data — your email address and, if you sign in with Google, your display name and avatar image. Authentication tokens are stored in your own browser.
- Preferences you save — watchlist assets, alert keywords, muted sources and categories, notification cadence, and your generated daily briefs.
- Push subscription data — if you enable push notifications: the push endpoint issued by your browser, its encryption keys, and your browser's user-agent string, used solely to deliver the alerts you asked for.
- Service data — short-lived rate-limit counters tied to your account (to keep the free AI features available to everyone), and error logs.
- Aggregate analytics — cookieless page-view statistics that do not identify you and are not combined with your account (see the Cookie Policy).
We do not collect payment details (the app is free), precise location, contacts, or any special-category data.
3. Why we collect it (lawful basis)
- To provide the service you signed up for (account, preferences, briefs, alerts) — performance of a contract (GDPR Art. 6(1)(b)); deemed consent under the PDPA.
- Push notifications — your consent, given via your browser's permission prompt (GDPR Art. 6(1)(a)). Withdraw any time in your browser or notification settings.
- Service integrity (rate limits, error logs, abuse prevention) — our legitimate interest in keeping a free service available and secure (GDPR Art. 6(1)(f)).
4. Who we share it with
We do not sell or rent personal data. We share it only with processors who run the service for us, under contracts that restrict their use of it:
- Cloud hosting and content-delivery providers (application and database hosting).
- Authentication and database infrastructure providers.
- Cloudflare Web Analytics — cookieless, privacy-first pageview analytics. It receives no account data.
- AI processing providers — receive the text needed to generate a summary or brief (news article text, your question, your selected categories and watchlist asset names), not your identity.
- Browser push services (operated by your browser vendor, e.g. Google, Apple or Mozilla) — deliver the notifications you enabled.
News articles link out to their original publishers; what those sites collect is governed by their own policies. The app also contains a personal referral link to Tangem — if you follow it, Tangem's own privacy policy applies from that point.
5. International transfers
The app runs on a global edge network, so data may be processed in Singapore, the EU/EEA, the UK and the United States. Where data of EU/UK users leaves those jurisdictions, we rely on adequacy decisions or Standard Contractual Clauses. Under PDPA section 26, we only transfer personal data overseas where comparable protection applies.
6. Retention
- Account data and saved preferences — until you delete your account.
- Daily briefs — until you delete your account.
- Push subscriptions — until you disable notifications, or automatically when your browser reports the subscription dead.
- Rate-limit counters — rolling 10-minute windows, overwritten continuously.
- Cached AI article summaries — up to 7 days; they are keyed to the public article, not to you.
7. Your rights
You can access, correct, export (portability), delete, or object to the processing of your personal data, and withdraw consent where processing is based on it. Exercise any of these by emailing privacy@marcomfin.tech from your account email. We respond within 30 days. Deleting your account removes your watchlist, keywords, preferences, briefs and push subscriptions.
8. Children
Northtape is not directed at children. You must be at least 18 to use it (see the Terms of Service). We do not knowingly collect data from anyone under 18; if you believe we have, contact us and we will delete it.
9. Security
All traffic is encrypted in transit (TLS). Data is encrypted at rest by our infrastructure providers. Access to user data is restricted by row-level security so that each account can only ever read its own records, and administrative access is limited to server-side processes.
10. Complaints
Contact us first — most issues resolve fastest that way. You may also complain to the Singapore Personal Data Protection Commission (pdpc.gov.sg); if you are in the UK, the Information Commissioner's Office (ico.org.uk); if you are in the EU/EEA, your national supervisory authority.
11. Changes to this policy
We will post any changes on this page and update the "last updated" date. For material changes affecting signed-in users, we will show an in-app notice before the change takes effect.
Questions or requests: privacy@marcomfin.tech. See also our Privacy Policy, Terms of Service and Cookie Policy.
This document was drafted with the assistance of AI tooling tuned for Singapore PDPA, EU GDPR, and UK GDPR. It is not a substitute for engagement with a qualified Singapore lawyer for matters involving regulatory enforcement, contract negotiation, or litigation.
