Privacy Policy
Last updated: May 6, 2026
Welcome to From Zero to Investor ("we", "our", or "us"), accessible at www.fromzerotoinvestor.com. We are committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, how it is used, and what rights you have over it.
If you have any questions, please contact us at hello@fromzerotoinvestor.com.
1. Who We Are
From Zero to Investor is a personal finance and investing blog run by an individual investor. The website provides educational articles, tools, and resources about investing for informational purposes only.
Contact: hello@fromzerotoinvestor.com
2. Data We Collect
2.1. Data You Provide Directly
- Contact form: When you submit a message through our contact form, we collect your name (optional), email address (optional), and the content of your message.
- User account registration: If you create an account, we collect your email address, name, and a hashed password. If you sign in via Google or Facebook, we receive your name and email address from those providers.
- Comments: When you post a comment, we collect your display name, comment content, and optionally your email address. Your name is shown publicly alongside your comment. If you provide an email address, it is stored for administrative purposes only and is never displayed publicly. If you are a registered user, the comment is additionally linked to your account. Anonymous commenters receive a secure edit token stored in a browser cookie (see Section 4) that allows them to edit or delete their own comments.
2.2. Data Collected Automatically
- Usage data: When you visit the site, your browser may send information such as your IP address, browser type, operating system, referring URL, pages visited, and time spent on pages.
- Cookies: We and our third-party partners use cookies and similar tracking technologies. See Section 4 for details.
- Server and application logs: Our web server and application automatically record technical log entries when errors occur or for security purposes. These logs may include your IP address, browser type, the URL you were accessing, and a timestamp. Logs are used solely for diagnosing technical problems and detecting abuse.
2.3. Data We Do Not Collect
We do not collect payment information, sensitive personal data, or data from children under 16 years of age. We do not sell your personal data to third parties.
3. How We Use Your Data
- To operate and improve the website and its content.
- To respond to messages submitted via the contact form.
- To provide and manage user account functionality (login, profile, membership tier).
- To send transactional emails related to your account (activation, password reset). We do not send marketing emails.
- To analyse visitor behaviour and improve user experience (via Google Analytics).
- To display advertising relevant to our audience (via Google AdSense, where enabled).
- To prevent abuse and ensure website security.
Legal basis (GDPR): We process data on the basis of legitimate interests (analytics, security), the performance of a contract (user accounts), and your consent (cookies where applicable).
4. Cookies
We use the following categories of cookies:
- Essential cookies: Required for the website and user account sessions to function correctly. These cannot be disabled.
- Comment token cookie (
comment_tokens): Set when you post a comment without being logged in. Stores a secure edit token that lets you edit or delete your own comments within the same browser. This is a functional essential cookie; it contains no personally identifiable information — only an opaque token linked to the comment ID.
- Analytics cookies: Used by Google Analytics (via Google Tag Manager) to understand how visitors interact with the site. Data is anonymised where possible.
- Advertising cookies: Used by Google AdSense to serve relevant advertisements (where AdSense is enabled). These may track your activity across other websites.
- Third-party cookies: Embedded content from third parties (e.g. YouTube videos) may set their own cookies.
You can manage or disable cookies at any time through your browser settings. Disabling some cookies may affect the functionality of the website. You can also opt out of Google Analytics tracking using the Google Analytics Opt-out Browser Add-on and manage Google ad personalisation at adssettings.google.com.
5. Third-Party Services
We use the following third-party services which may process your data under their own privacy policies:
- Google Analytics & Google Tag Manager — website traffic analysis. Google Privacy Policy
- Google AdSense — advertising (where enabled). Google Privacy Policy
- Google OAuth — sign in with Google account. Google Privacy Policy
- Facebook OAuth — sign in with Facebook account. Meta Privacy Policy
- Affiliate partners (Interactive Brokers, Freedom24, TradingView, and others) — when you click an affiliate link we may receive a commission. These partners operate under their own privacy policies.
We do not share your personal data with these services beyond what is technically necessary for their operation on our website.
International data transfers: Some of the third-party services listed above (Google, Meta/Facebook) are based in the United States and may transfer and process your personal data there. These transfers are carried out under Standard Contractual Clauses approved by the European Commission, providing an adequate level of data protection. You can find more details in each provider's privacy policy linked above.
6. Data Retention
- Contact form messages are retained only as long as necessary to respond and are not stored in a database. In the event of a delivery failure, the message may be temporarily held in a server-side queue file while delivery is retried. Such queued files are reviewed periodically and deleted once no longer needed, and in any case within 30 days.
- Comment data (display name, comment content, and email address if provided) is retained for as long as the comment remains on the website. When you delete one of your own comments, it is permanently and immediately removed from our database along with all its replies. Deleting your user account does not automatically delete your comments — comment data is stored independently in a separate database and remains there after account deletion.
- User account data (email, name, hashed password) is retained for as long as your account exists. You may delete your account at any time (see Section 7).
- Analytics data is retained by Google according to their own data retention settings (typically 14 months by default).
- Server and application error logs are retained for up to 90 days, after which they are automatically deleted.
7. Your Rights & Account Deletion
Under the General Data Protection Regulation (GDPR) and applicable data protection law, you have the following rights:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may correct inaccurate data directly in your account profile.
- Right to erasure ("right to be forgotten") — you may request deletion of your personal data.
- Right to restriction — you may ask us to limit processing of your data in certain circumstances.
- Right to object — you may object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
- Right to data portability — where processing is based on consent or a contract, you may request your personal data in a structured, commonly used, machine-readable format.
How to Delete Your Account and Data
If you have a registered user account, you can permanently delete it — and all associated personal data — in two ways:
- Self-service (instant): Sign in to your account, go to My Account, scroll to the Danger Zone section, and click Delete My Account. You will be asked to confirm by typing
DELETE. This immediately and permanently removes your account and all personal data from our systems.
- By email request: Send a deletion request from the email address associated with your account to hello@fromzerotoinvestor.com. We will process the request within 30 days and confirm by reply.
Once deleted, your data cannot be recovered. Data held by third-party services (e.g. Google Analytics) is subject to their own deletion policies.
To exercise any other rights, please contact us at hello@fromzerotoinvestor.com. We will respond within 30 days. If you believe your rights have been infringed, you may lodge a complaint with the relevant supervisory authority in your country.
8. Data Security
We take reasonable technical and organisational measures to protect your personal data from unauthorised access, disclosure, alteration, or destruction. Passwords are stored as cryptographic hashes and are never stored in plain text. However, no method of transmission over the Internet is completely secure.
9. Comments
Our website includes a public commenting system. When you post a comment, your display name and comment content are visible to all visitors. If you provide an email address, it is stored for administrative purposes only and is never shown publicly.
Comments may be held for moderation before being published, depending on our current settings. We reserve the right to remove or reject any comment that is offensive, misleading, or otherwise inappropriate, without prior notice.
You may edit or delete your own comments at any time using the controls next to your comment. Deleting a comment permanently and immediately removes it and all its replies from our database. Note that deleting your user account does not automatically remove your comments — you must delete them separately if you wish them removed. For data retention details, see Section 6.
10. Children's Privacy
This website is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has submitted data to us, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will be revised accordingly. We encourage you to review this page periodically. Continued use of the website after changes constitutes acceptance of the updated policy.