Covestor Security Policy

Introduction

At Covestor our most important asset is our relationship with you. Therefore, for both you and us, it is essential we safeguard the privacy of the personal information we maintain about you.

This policy outlines the types of information Covestor collects about you and how that information is safeguarded. The policy applies to all current and former Members of Covestor.

There are 3 tiers of security at Covestor dependant on the sensitivity of the information

1. Publicly accessible

Activity and comments

Having become a Covestor member we collect and maintain information about your membership activity. This includes ratings, comments and rationale you may post, and any profile information. These are kept on our web servers and are available to other registered members who have accepted our terms and conditions.

Normalized transaction information

Normalized transaction information is where the actual $ amount of your financial transactions have been rebalanced to display relative percentage allocations. It also refers to aggregated derivative data, such as performance and sector allocations, derived by automated analysis of your data. These are kept on our web servers and are also available to other registered members who have accepted our terms and conditions.

2. Privately accessible with secure password access

Registration information

When you sign up to become a member of Covestor we collect personal information from you. This includes your name, state, country, and email address. We store this information securely on our servers and provide no public access to it except for you to maintain and edit following a secure password protected login to your account

Transaction and holdings amounts

Details of your executed transactions and holdings are maintained on our servers and are not publicly accessible. We use the raw data for calculations and normalization only. Details of actual amounts are not disclosed to other members. We store this information securely on our servers and provide no public access to it except for you to view following a secure password protected login to your account