The Income Stack

Privacy Policy

This policy explains what The Income Stack collects, why, who it is shared with, and the control you have over it.

Last updated August 20, 2026

1. Who we are

The Income Stack (https://instack.app) is operated by Colo Transport Co., 15629 Josephine Street, Thornton, CO 80602. In this policy “we” and “us” mean that entity, and “you” means the person using the service.

We are a personal financial planning and portfolio-tracking tool. We are not a broker-dealer, investment adviser, custodian, or tax adviser. We do not hold your money or securities, and we cannot place trades.

2. Information you give us

  • Account information. The email address you sign up with, and authentication data handled by our identity provider. We never see or store your password in readable form.
  • Planning inputs. Information you type in to model your own finances: dates of birth or target ages, tax filing status, household and spouse details, income and expenses, savings goals, real-estate details, and notes you write on holdings.
  • Manually entered accounts and holdings. Positions, share counts, and cost basis you enter yourself for accounts you have not linked.
  • Correspondence. Messages you send us for support.

3. Brokerage information, and what we never receive

You may optionally link a brokerage account through SnapTrade, a third-party account-aggregation provider. This is the most sensitive connection in the product, so it is worth being precise about how it works.

  • Your brokerage credentials never reach our servers. You enter them with your brokerage or with SnapTrade directly. We receive an access token, not a username and password, and we cannot see or recover your brokerage login.
  • The connection is read-only. We request permission to read positions, balances, and transaction history. We do not request, and do not have, permission to place, modify, or cancel trades, or to move money in or out of any account.
  • What we store. Account nickname, account type, balances, positions (symbol, quantity, cost basis, market value), and transaction history including trades and dividends. Where a brokerage supplies a full account number, we store only what is needed to identify the account.
  • You can disconnect at any time from the accounts screen, which revokes our access going forward.

SnapTrade processes this data as an independent provider under its own privacy policy, available at snaptrade.com/privacy.

4. Information collected automatically

  • Operational logs. IP address, browser type, pages requested, and timestamps, generated by our hosting provider and retained for security and debugging.
  • Session cookies. Strictly necessary cookies that keep you signed in. We do not use advertising cookies, and we do not run third-party advertising or cross-site tracking pixels.

5. How we use your information

  • To operate your account and keep you signed in.
  • To display your holdings, dividends, and balances, and to keep them current.
  • To run the projections, scenarios, and reports you ask for.
  • To send service messages you have asked for or that are required to run your account.
  • To secure the service, investigate abuse, and debug faults.
  • To meet legal and regulatory obligations.

We do not use your financial data to build advertising profiles, and we do not perform automated decision-making that produces legal or similarly significant effects about you.

6. We do not sell your personal information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the Colorado Privacy Act and the California Consumer Privacy Act. We have not done so in the preceding twelve months.

7. Who we share information with

We share personal information only with service providers who process it on our behalf, under contract, for the purposes below:

  • Supabase — authentication and database hosting.
  • Vercel — application hosting, delivery, and operational logging.
  • SnapTrade — brokerage account connectivity, when you choose to link an account.
  • Resend — transactional email delivery.
  • RentCast — property value estimates, when you add a property. It receives a property address, not your identity.
  • OpenAI — powers an optional portfolio-comparison summary. It receives only the holdings data needed for that summary, and only when you request one. It is not used to train models on your data.
  • Market data providers (Massive, Finnhub, Yahoo Finance) — supply prices, dividends, and corporate actions. These receive ticker symbols only. They are not told who is asking, and they receive nothing about your holdings, quantities, or identity.

We may also disclose information if required by law or valid legal process, or to protect the rights, safety, or property of our users or ourselves. If the business is transferred, your information may transfer with it, and this policy will continue to apply until you are told otherwise.

8. Security

Data is encrypted in transit with TLS and at rest by our hosting providers. Access to production data is restricted, database rows are isolated per user, and brokerage access tokens are stored server-side and are never exposed to the browser.

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your own login credentials confidential.

9. Retention

We keep your information for as long as your account is open. When you delete your account we delete your personal and financial data within 30 days, except where we must keep records to comply with a legal obligation or to resolve a dispute. Operational logs age out on a shorter cycle.

10. Your rights

Depending on where you live — including under the Colorado Privacy Act, the California Consumer Privacy Act, and the GDPR — you may have the right to:

  • Access the personal information we hold about you.
  • Correct information that is inaccurate.
  • Delete your account and the information associated with it.
  • Obtain a portable copy of information you provided.
  • Opt out of the sale or targeted-advertising uses of your data — which we do not engage in.
  • Appeal a decision we make about one of these requests.

You can delete linked brokerage connections yourself at any time from the accounts screen. For anything else, write to support@instack.app. We respond within 45 days and will not discriminate against you for exercising these rights.

11. Children

The service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has given us information, write to support@instack.app and we will delete it.

12. International users

We operate in the United States, and information is processed there. If you access the service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection law may differ from that of your own country.

13. Changes to this policy

If we make a material change we will update the date at the top of this page and, where the change significantly affects how we handle your information, notify you in the application or by email before it takes effect.

14. Contact

Privacy questions and data-rights requests: support@instack.app. General support: support@instack.app. Postal mail: Colo Transport Co., 15629 Josephine Street, Thornton, CO 80602.

The Income Stack provides planning and projection tools for educational purposes. It is not a broker-dealer, investment adviser, or tax adviser, and nothing it produces is investment, legal, or tax advice.