You agree to the privacy policy below, and the Privacy Policy for Substack, the technology provider.
Effective Date: December 31, 2025
This Privacy Policy explains how Beyond Candlesticks (the “Publication,” “we,” “us,” or “our”), a newsletter hosted on Substack, collects, uses, discloses, and protects your personal information when you subscribe to, interact with, or access our content.
We are committed to protecting your privacy and handling your data transparently and responsibly. This policy applies solely to our processing of personal data as the data controller. Substack Inc. (”Substack”) acts as our data processor for hosting and email delivery services. For details on how Substack processes your data, please review Substack’s Privacy Policy at https://substack.com/privacy.
1. Information We Collect
When you subscribe to Beyond Candlesticks via Substack, we (through Substack) may collect:
Directly provided information: Your email address, name (if provided), and any other details you share in your Substack profile or comments.
Subscription and payment information (for paid subscribers): Billing details processed securely by Substack’s payment providers (e.g., Stripe). Beyond Candlesticks does not directly access or store your full payment card information.
Interaction data: Information about how you engage with our emails (e.g., opens, clicks) and content (e.g., comments, likes), as provided by Substack’s analytics tools.
Comments and communications: Any personal information you include in comments on posts or replies to our emails.
We do not collect sensitive personal data (e.g., health, racial/ethnic origin, political opinions) unless voluntarily shared by you in comments or in another form.
2. How We Use Your Information
We use your personal information for the following purposes:
To deliver the Publication: Sending newsletters, updates, and notifications via email.
To manage subscriptions: Processing payments, upgrades/downgrades, and providing access to free or paid content.
To improve the Publication: Analyzing engagement (anonymized where possible) to refine content and delivery.
To communicate: Responding to your inquiries or comments.
Legal compliance: Meeting obligations under applicable laws (e.g., tax reporting for paid subscriptions).
Our lawful basis for processing under GDPR (if applicable) is primarily your consent (for marketing emails) and contract performance (for delivering subscribed content).
3. Sharing Your Information
We do not sell your personal information or share it for marketing purposes with third parties unrelated to delivering the Publication.
Your information may be shared with:
Substack Inc.: As our platform provider, for hosting, email delivery, analytics, and payment processing.
Substack’s service providers: Such as payment processors (e.g., Stripe) and email infrastructure providers, bound by strict data protection terms.
Legal authorities: If required by law, court order, or to protect rights/safety.
Comments you post are public and visible to other subscribers.
4. Data Retention
We retain your personal information only as long as necessary.
You can request deletion at any time (see Your Rights below).
5. Security
We take reasonable measures to protect your data, relying on Substack’s industry-standard security practices (e.g., encryption for transmissions and storage). However, no system is completely secure, and we cannot guarantee absolute security.
6. International Data Transfers
The Publication is hosted on Substack (U.S.-based). If you are in the EU/UK, your data may be transferred outside your region under mechanisms like the EU-U.S. Data Privacy Framework or standard contractual clauses. See Substack’s Privacy Policy for details.
7. Your Rights
Depending on your location, you may have rights including:
Access, correction, or deletion of your data.
Object to or restrict processing.
Withdraw consent (e.g., unsubscribe).
Data portability.
Complain to a supervisory authority (e.g., for GDPR).
To exercise rights or ask questions, contact us at: beyondcandlesticks@substack.com.
You can unsubscribe anytime via the link in any email or through your Substack account settings.
8. Children’s Privacy
The Publication is not intended for those under 18. We do not knowingly collect data from children. If we learn of such collection, we will delete it.
9. Changes to This Policy
We may update this policy occasionally. Significant changes will be notified via email or a prominent notice on the Publication. Continued use after changes constitutes acceptance.
10. Contact Us
For privacy concerns: beyondcandlesticks@substack.com.
This policy complements Substack’s terms and policies, which also apply to your use of the platform.
Thank you for trusting us with your information.

