1. Overview & Our Core Principles
GemFilter ("we," "our," or "us") is an independent financial technology platform dedicated to providing institutional-grade stock screening, valuation modeling, and value investing education.
Unlike traditional ad-supported finance portals that monetize user attention through invasive cross-site tracking and behavioral profiling, GemFilter is architected from the ground up on three strict principles:
- Zero Surveillance: We do not build individual financial profiles, monitor your investment transactions, or sell data to third-party data brokers.
- Data Minimization: We collect only the minimum technical data necessary to deliver fast, resilient, and secure financial research tools.
- Complete Consent Autonomy: You retain explicit control over whether non-essential analytical cookies are stored on your device.
2. Data Controller & Entity Governance
For the purposes of the Digital Personal Data Protection Act, 2023 (India) and the General Data Protection Regulation (EU GDPR), the Data Controller / Data Fiduciary is:
Platform: GemFilter (Fintech Research Platform)
Founder & Lead Developer: Dev Jasani
Headquarters: Surat, Gujarat, India
Official Email: [email protected]
Product Inquiries & Feedback: [email protected]
3. Dual-Layer Privacy & Traffic Analytics Architecture
To maintain total transparency regarding how website traffic is measured, GemFilter operates an industry-standard dual-layer analytics infrastructure:
Layer 1: Cookieless Edge Telemetry (Cloudflare Web Analytics)
We utilize Cloudflare Web Analytics at the Content Delivery Network (CDN) edge. This service measures aggregate website performance (such as total pageviews, referrers, device types, and Core Web Vitals) without using cookies, localStorage, or fingerprinting.
Cloudflare does not track individual user journeys across sites and does not store IP addresses. Because no personal data is collected or processed, Layer 1 operates lawfully across all global jurisdictions without requiring cookie consent under GDPR Article 6(1)(f) and the DPDP Act.
Layer 2: Google Analytics 4 with Google Consent Mode V2
For deeper diagnostic insights (e.g., which financial valuation metrics are most used), we implement Google Analytics 4 (GA4) with Consent Mode V2 Advanced Integration:
- Prior to Consent: GA4 default state is set to
denied. No cookies are written to your device. Only anonymized, cookieless telemetry pings are transmitted to allow aggregate statistical modeling. - Upon Explicit Consent: If you select "Accept Analytics" in our Cookie Banner, GA4 writes first-party analytical cookies (
_ga,_ga_*) to measure session flow and retention. - Upon Decline: If you select "Essential Only", GA4 remains strictly in cookieless mode. No personal identifiers or tracking cookies are created.
This architecture guarantees that 100% of website visits are counted legally and anonymously through privacy-safe edge telemetry, while behavioral tracking cookies are strictly quarantined behind your affirmative consent.
4. Information We Never Collect
As a matter of technical design, GemFilter operates without accessing your private financial life. We explicitly do not collect or store:
- Bank account numbers, IFSC codes, routing numbers, or payment credentials.
- Demat account details, Zerodha/Groww/Upstox API keys, or brokerage logins.
- Personal investment portfolios, tax filings, or net worth statements.
- Government identification numbers (Aadhaar, PAN, SSN, Passport).
- Biometric data, location coordinates, or keystroke audio/video.
5. Information We May Process
The limited information we process falls strictly into two categories:
- Technical & Network Telemetry: Anonymized HTTP request headers, browser user-agent, operating system, screen resolution, referral URLs, and country-level geographic location (derived from IP address at the CDN edge before IP discard).
- Direct Communications: When you voluntarily email us at [email protected] or [email protected], we retain your email address and message contents solely to address your inquiry or feedback. We never add contact emails to marketing lists without explicit opt-in.
6. Compliance with Global Data Protection Laws
GemFilter recognizes and complies with global statutory frameworks governing digital privacy:
We adhere to the Digital Personal Data Protection Act, 2023. Processing of personal data is limited to lawful purposes with transparent notice. Users hold the right to access summary info, request correction or erasure, and register grievances.
We operate under GDPR Regulation (EU) 2016/679 and Directive 2002/58/EC. Non-essential cookies require affirmative prior consent (Opt-In). Legitimate interest (Art. 6(1)(f)) is used solely for essential CDN security and anonymous edge telemetry.
Under the California Consumer Privacy Act, we confirm: We do not sell or share consumer personal information for cross-context behavioral advertising. Users enjoy non-discrimination for exercising privacy choices.
8. Data Retention & Institutional Security
Security is an integral part of GemFilter's architectural engineering:
- Transport Encryption: All client-to-server traffic is enforced via HTTPS utilizing TLS 1.3 with automated HSTS (HTTP Strict Transport Security) preloading.
- Edge Defense: Cloudflare edge proxy provides automated DDoS suppression, bot mitigation, and Web Application Firewall (WAF) filtering.
- Telemetry Retention: Aggregated analytical metrics in Google Analytics are configured with a strict 14-month data retention policy, after which user-level data is automatically scrubbed.
9. Your Privacy Rights & How to Exercise Them
Regardless of your geographic location, GemFilter affords you comprehensive rights over your personal data:
- Right to Withdraw Consent: You can modify or revoke your cookie analytics consent at any time via the "Cookie Settings" option in our footer or on the Cookie Policy page.
- Right to Access & Erasure: If you have contacted us via email and wish for your email record to be permanently deleted from our communication inbox, email your request to [email protected].
- Right to Object: You can opt out of any non-essential data processing at zero cost.
10. Grievance Redressal & Inquiries
In accordance with the India DPDP Act 2023 and EU GDPR Article 37 requirements, any inquiries, complaints, or grievance redressal requests may be directed to our designated compliance contact: