Legal
Privacy Policy
Last updated · 3 August 2026
Provenance is our product, so we hold ourselves to the same standard we apply to data: we tell you what we collect, why we collect it, and what we will never do with it. In short: we collect what the service needs to run, and we do not sell it.
Indicator Gateway is a product of FORERANGER LTD. FORERANGER LTD is the data controller for personal information processed by the service.
Section 1What we collect
- Account information. Your name, email address and password hash when you register, your organisation if you provide it, and your subscription plan.
- Your work in the product. Portfolios and their configurations (holdings, weights, orientations, normalization choices, benchmarks, activity trails), custom indicators and their formulas, and display preferences. This is the substance of the service and is stored so you can come back to it.
- API keys. If your plan includes the Data API, we store each key's name, a short display prefix, a cryptographic hash of the key and its last-used time. The full key is shown to you once at creation and is never stored.
- Billing information. If you take a paid plan, your billing name, billing email and the subscription record. Card details are entered directly with our payment processor and are never seen or stored by us.
- Operational records. Server logs (timestamps, IP address, requested endpoints) kept for security, debugging and abuse prevention.
The indicator data you analyse (World Bank, IMF, UN, ILO, FAO, climate, governance and other series from our 22 statistical sources) is public statistical data and is not personal information.
Section 2What we don't do
- We do not sell or rent your personal information to anyone, ever.
- We do not run third-party advertising or advertising trackers.
- We do not claim ownership of your methodologies. Your portfolio configurations and custom indicator formulas are yours.
- We do not read your work except as needed to operate the service, investigate a fault you report, or comply with law.
Section 3Cookies and local storage
We use cookies for one job: keeping you signed in (an authentication token, your role and your plan). We also use your browser's local storage for device-level preferences, for example which portfolios appear in your header strip. None of this is used for cross-site tracking, and there are no marketing cookies to consent to.
Section 4How your information is used
- To provide and secure the service: authentication, computing your composites, saving your configurations.
- To respond when you contact us, including data-correction reports.
- To send service communications (security notices, material changes to terms). Product announcements are opt-in.
- To understand aggregate usage of features so we improve the right things. Aggregate means counts, not the content of your work.
Section 5Sharing and our processors
We do not sell personal information and we do not share it for advertising. We use a small number of infrastructure providers to run the service, each under contracts that limit them to processing data on our instructions. They are:
Beyond these, we disclose personal information only when the law genuinely requires it. If the business is ever transferred, this policy travels with your data and you will be notified before anything changes.
Section 5aWhere your data is held
Your account and your work are stored in the European Union. Cloudflare and Stripe operate global networks, so limited data (for example a request in transit, an email in delivery, or a payment record) may be processed outside the EU or UK by those providers under their own safeguards for international transfers, including the standard contractual clauses where they apply.
Section 6Retention and deletion
Your account data and work are kept while your account exists. Delete your account and we delete them within 30 days, except minimal records we must keep for legal or security reasons (such as invoices). Server logs rotate on a short fixed schedule.
Section 7Your rights
You may request a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Depending on your jurisdiction (for example under the GDPR), you may have further rights. We honour access, rectification, erasure, portability and objection requests for everyone, regardless of where you live. Write to us and we'll act on it.
Section 8Security
Traffic is encrypted in transit. Passwords are stored as salted hashes, sessions are token-based, and portfolio and indicator records are scoped to your account on every request. No system is perfectly secure; if we learn of a breach affecting your data, we will tell you promptly and plainly.
Section 9Changes to this policy
If we change this policy in any material way, we will notify account holders by email before the change takes effect and update the date at the top of this page. The change history is available on request.
Section 10Contact
Email is the only contact channel. Questions, requests or complaints about privacy go to info@indicatorgateway.com, addressed to FORERANGER LTD at the registered office above.