Last updated: March 2026
Wall St. 101 ("we", "us", "our") operates an online financial education platform accessible globally. This Privacy Policy explains how we collect, use, and protect your personal information in accordance with the New Zealand Privacy Act 2020 and applicable international privacy frameworks including the GDPR (for EU/EEA residents).
When you create an account, we collect: your name, email address, country of residence, and password (stored securely as a hash — we never store plain-text passwords). As you use the Platform, we collect: lesson progress, quiz scores, XP and streak data, paper trading simulator activity, and usage patterns (pages visited, time spent). We do not collect financial information beyond payment processing (handled by Stripe — see Section 5).
We use your information to: (a) provide and personalise the Platform experience; (b) track your learning progress and display it on your dashboard; (c) send transactional emails (welcome, password reset, subscription confirmation); (d) send optional engagement emails (weekly learning summaries) — you can unsubscribe at any time; (e) process payments for Pro subscriptions; and (f) improve the Platform through aggregated, anonymised usage analytics.
For users in the EU/EEA: we process your data on the basis of (a) contract performance — processing necessary to provide the service you signed up for; (b) legitimate interests — improving the Platform; and (c) consent — for optional marketing communications. For NZ users: our processing is consistent with the NZ Privacy Act 2020 Information Privacy Principles.
We use the following third-party services: Supabase (database and authentication infrastructure, hosted in the US — processes your account data); Resend (transactional email delivery); Stripe (payment processing for Pro subscriptions — we do not store your card details; Stripe is PCI-DSS compliant). Each of these providers has their own privacy policies and appropriate data protection measures.
Your data may be transferred to and stored in countries outside your country of residence, including the United States. We ensure appropriate safeguards are in place for such transfers, including Standard Contractual Clauses where required under GDPR.
We use essential cookies to maintain your login session and remember preferences. We do not use advertising cookies or third-party tracking pixels. You can disable cookies in your browser settings, but this will affect your ability to remain logged in.
We retain your account data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where retention is required by law (e.g., financial records for payment disputes). Anonymised usage data may be retained indefinitely.
Depending on your location, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data ("right to be forgotten"); object to or restrict certain processing; and data portability. To exercise any of these rights, contact us at hello@wallstreet101.io. We will respond within 30 days.
We implement industry-standard security measures including encrypted data transmission (HTTPS/TLS), hashed password storage, and access controls. However, no system is 100% secure. If you suspect unauthorised access to your account, contact us immediately.
The Platform is not directed at children under 16. We do not knowingly collect personal information from children under 16. If we discover such data has been collected, we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on the Platform. Continued use after changes constitutes acceptance.
For privacy questions or to exercise your rights, contact: hello@wallstreet101.io. If you are in the EU/EEA and believe we have violated GDPR, you have the right to lodge a complaint with your local data protection authority. NZ residents may also contact the Privacy Commissioner at privacy.org.nz.