Business Quant Logo
About Us Pricing API
Features

Research Tools

Stock Screener Filter companies on hundreds of criteria Industry Financials Aggregated financials across industries Timeseries Tables Build custom tables across metrics and years Portfolio Follow your holdings and their performance Advanced Charting Plot and compare any metric over time

Datasets

KPI & Operating Metrics Segment revenue, operating metrics and KPIs Financial Statements Income statement, balance sheet and cash flow Economic Data Rates, inflation and other macro indicators Corporate Actions Splits, buybacks and dividends tracker
Login Start for Free
About Us Pricing API
Research Tools
Stock Screener Industry Financials Timeseries Tables Portfolio Advanced Charting
Datasets
KPI & Operating Metrics Financial Statements Economic Data Corporate Actions
Login Start for Free

Privacy Policy

  • Effective date31 July 2026
  • Last updated31 July 2026

Scope and application

This Privacy Policy explains how Business Quant (“Business Quant”, “we”, “us”, “our”) collects, uses, discloses, transfers, retains and protects personal data in connection with the businessquant.com website, the Business Quant web application, the Business Quant API and all related services (together, the “Service”).

It applies to visitors to the Service, holders of registered accounts, subscribers to paid plans, users of the API, recipients of our communications, and persons who contact us. It forms part of, and should be read together with, our Terms of Use.

“Personal data” means any information relating to an identified or identifiable natural person. Where terms such as “controller”, “processor”, “processing” and “data subject” are used, they have the meanings given to them in the applicable data protection legislation, including Regulation (EU) 2016/679 (the “GDPR”), the UK GDPR and Data Protection Act 2018, the Digital Personal Data Protection Act, 2023 of India (the “DPDP Act”), and the California Consumer Privacy Act as amended (the “CCPA”).

We do not sell personal data, we do not share personal data for cross-context behavioural advertising, we do not display third-party advertising on the Service, and we do not permit advertisers, advertising networks, exchanges or data brokers to place tags, pixels or other tracking technology on the Service. Our revenue is derived solely from subscription fees and data licensing.

Controller and contact details

For the purposes of the GDPR and comparable legislation, the controller of personal data processed in connection with the Service is:

Business Quant
E-37, Arjun Marg, DLF Phase-1, Gurugram 122002, India
[email protected]

All privacy enquiries, data subject requests and complaints should be addressed to [email protected]. We handle such requests directly rather than through a third-party intermediary.

Categories of personal data we process

A substantial part of the Service may be viewed without providing personal data. Where personal data is processed, it falls within the following categories.

Account data. Your name, email address, a cryptographically hashed representation of your password, account creation date, account status, and, where applicable, the organisation with which your account is associated and your role within it.

Subscription and transaction data. The plan held, billing period, renewal and cancellation dates, transaction identifiers, invoice and receipt records, amounts paid, currency, the country used for tax determination, and the last four digits and card type as returned to us by our payment provider. Full payment card numbers, expiry dates and security codes are collected and processed by our payment provider and are not received or stored by us.

Product usage data. Watchlists, portfolios, saved screens, saved views, display preferences, billing-period selections and comparable settings that you create in order for the Service to retain your configuration between sessions.

API and entitlement data. API keys issued to your account, and records of requests made using them, including endpoint requested, timestamp, response status, request volume and data volume transferred. This data is used for metering, entitlement enforcement, usage reporting, capacity planning and abuse investigation.

Technical and log data. IP address, browser type and version, operating system and device type, screen and viewport characteristics, language settings, referring and exit pages, pages and resources requested, dates and times of requests, response codes, and diagnostic data generated when an error occurs.

Correspondence data. The content of emails, contact form submissions, support requests and any attachments you send us, together with our replies and any notes made in handling the matter.

Marketing data. Where you have subscribed to a newsletter or comparable communication: your email address, subscription and unsubscription dates, and delivery and engagement events such as whether a message was delivered, opened or a link within it followed.

Security data. Authentication events, session identifiers, records of failed login attempts, indicators of automated or anomalous activity, and records of enforcement action taken in respect of an account.

We do not seek, and ask that you do not submit to us, any special category personal data as defined in Article 9 GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, or data concerning health, sex life or sexual orientation. We do not knowingly process such data and it has no application to the Service.

Sources of personal data

We obtain personal data from the following sources: directly from you, when you register an account, purchase a subscription, configure the Service, subscribe to a communication or contact us; automatically, through your interaction with the Service, by means of server logs, cookies and comparable technologies; and from our service providers, in particular our payment provider, which supplies transaction outcomes and limited card metadata, and our email delivery provider, which supplies delivery and engagement events.

We do not purchase personal data from data brokers, list vendors or enrichment services, and we do not combine your personal data with data obtained from advertising networks.

Purposes of processing and legal bases

We process personal data only where a lawful basis applies. The purposes and their corresponding bases are as follows.

Performance of a contract with you (Article 6(1)(b) GDPR): creating and administering your account; authenticating you; providing the Service and the features of your plan; issuing and managing API keys; applying entitlements and usage limits; processing payments, renewals and cancellations; issuing invoices and receipts; and providing customer support in relation to your account.

Our legitimate interests (Article 6(1)(f) GDPR): maintaining the security, integrity and availability of the Service; detecting, investigating and preventing fraud, credential sharing, unauthorised automated access, circumvention of usage limits and other breaches of our Terms of Use; diagnosing and resolving technical faults; understanding in aggregate how the Service is used in order to improve it; conducting internal reporting and business planning; establishing, exercising and defending legal claims; and communicating with you about material changes to the Service or to our terms. In each case we have assessed that these interests are not overridden by your interests or fundamental rights, having regard to the limited scope of the data involved and the safeguards described in this policy.

Your consent (Article 6(1)(a) GDPR): sending marketing or newsletter communications where consent is required; and setting non-essential cookies where consent is required in your jurisdiction. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

Compliance with a legal obligation (Article 6(1)(c) GDPR): retaining accounting, tax and transaction records; responding to lawful requests from public authorities and courts; and complying with obligations arising under data protection law itself.

We do not process personal data for the purposes of advertising, behavioural profiling, audience segmentation or lead generation. We do not use your personal data, your usage data or the content of your correspondence to train machine learning models.

Cookies and similar technologies

Cookies are small text files placed on your device by a website. We use cookies and comparable technologies such as local storage for a limited set of purposes, which fall into the following categories.

Strictly necessary. Cookies required to authenticate you, maintain your session, apply your entitlements, balance load across our infrastructure, and protect forms and endpoints against automated abuse. The Service cannot function without these and they are not subject to consent.

Preference. Cookies and local storage entries that record choices you have made, such as your billing-period selection or display settings, so that they persist between visits.

Analytics. Cookies set in connection with Google Analytics as described in section 7, used to produce aggregate statistics about how the Service is used.

No cookie set by or on the Service is used for advertising, retargeting, audience building or cross-site tracking. Cookies may be persistent, remaining on your device until they expire or are deleted, or session-based, expiring when you close your browser.

Most browsers allow cookies to be blocked, restricted or deleted through their settings, and provide a private browsing mode. Blocking strictly necessary cookies will prevent you from signing in and from remaining signed in, and will cause parts of the Service to malfunction. We do not respond to browser “Do Not Track” signals, as no consistent standard for their interpretation exists; however, we do not carry out the cross-site tracking that such signals are directed at.

Analytics and search performance

We use two Google services, and these are the only analytics or measurement tools deployed on the Service.

Google Analytics is used to produce aggregate statistics on page views, traffic sources, navigation paths and comparable measures, in order to understand which parts of the Service are used and where users encounter difficulty. It is configured with IP anonymisation enabled. We do not enable Google Signals, advertising features, remarketing, audience sharing or the Google Display Network, and we do not use Analytics to identify individual users. Google Ireland Limited and Google LLC act as processors in respect of this data on the terms of the Google Analytics data processing terms, and processing takes place in part on infrastructure located in the United States.

Google Search Console reports on the performance of our pages within Google search results. It operates on Google's own search data and does not place cookies or other identifiers on your device.

Google publishes a browser add-on that prevents Google Analytics from collecting data. Blocking analytics cookies in your browser has an equivalent effect. No feature of the Service is dependent on analytics being enabled.

Communications and marketing

We send transactional and service messages that are necessary to operate your account, including registration confirmations, password resets, payment receipts, renewal and failed-payment notices, security alerts, and notices of material changes to the Service or to our terms. These are not marketing communications and cannot be opted out of while your account remains open, although you may close your account.

Marketing and newsletter communications are sent only where you have subscribed to them. Every such message contains an unsubscribe link, which takes effect promptly on use. You may also unsubscribe by writing to [email protected]. Withdrawing consent to marketing does not affect your subscription or your access to the Service.

Recipients and disclosure

We disclose personal data only in the circumstances set out in this section.

Service providers. We engage third parties to perform functions on our behalf. Each acts on our documented instructions, is bound by a written contract containing the obligations required by Article 28 GDPR or its equivalent, is permitted to process personal data only for the purpose for which it was engaged, and is prohibited from using it for its own purposes. The categories engaged are: hosting and infrastructure; content delivery, network security and denial-of-service mitigation; payment processing; transactional and marketing email delivery; and analytics as described in section 7.

Professional advisers. Lawyers, accountants, auditors and insurers, where necessary and subject to obligations of confidentiality.

Legal and regulatory disclosure. Where required by applicable law, by a court of competent jurisdiction, or by a regulatory, tax or law enforcement authority acting within its powers; or where necessary to establish, exercise or defend legal claims, to enforce our Terms of Use, or to protect the rights, property or safety of Business Quant, our users or the public. Where we are lawfully able to do so, we will notify you of a request for your personal data before responding to it.

Corporate transactions. In connection with a merger, acquisition, reorganisation, financing or sale of all or part of our business, personal data may be disclosed to the counterparty and its advisers subject to appropriate confidentiality undertakings, and may be transferred as part of the assets of the business. We will notify affected users before their personal data becomes subject to a materially different privacy policy as a result.

We do not disclose personal data to advertisers, advertising networks, data brokers, list vendors or analytics aggregators for their own purposes, and we do not sell, rent, licence or trade personal data in any circumstances.

International transfers

We operate from India and engage service providers established in India, the United States and the European Union. Personal data may therefore be transferred to, stored in and processed in countries other than the country in which you are located, including countries that may not provide the same level of data protection as your own.

Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on an appropriate transfer mechanism under applicable law, being either an adequacy decision of the European Commission or the competent authority in respect of the recipient country, or the Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum where applicable) incorporated into our contracts with the recipient, together with such supplementary technical and organisational measures as are appropriate. A copy of the relevant safeguards may be requested at [email protected].

Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax or reporting requirements, and to establish, exercise or defend legal claims. The criteria we apply are the duration of our relationship with you, the existence of a legal obligation to retain the data, and the applicable limitation periods.

Account data and product usage data are retained for the lifetime of the account. On closure of an account, they are deleted or irreversibly anonymised, save for records we are required to retain. Subscription and transaction records are retained for the period required by applicable accounting and tax law, which is ordinarily at least eight years from the end of the relevant financial year. Technical and log data, and API request records, are retained for a limited operational period and are then deleted or aggregated into non-identifying statistics. Correspondence is retained for as long as necessary to deal with the matter and for a reasonable period afterwards for reference and to defend claims. Marketing data is deleted on unsubscription, save for the minimum record necessary to ensure that no further messages are sent to you. Security records relating to enforcement action are retained for as long as necessary to prevent recurrence and to defend claims.

Security

We implement technical and organisational measures appropriate to the risk, including encryption of data in transit using industry-standard transport layer security; storage of passwords using a one-way cryptographic hashing function with per-user salting, such that they cannot be recovered by us; role-based access controls limiting internal access to personnel who require it for a defined purpose; segregation of production environments; logging and monitoring of access and of anomalous activity; and the ability for you to revoke and reissue your API keys at any time.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential, for using a strong and unique password, and for notifying us promptly of any suspected compromise.

Where a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within the period required by applicable law, and will notify you without undue delay where the breach is likely to result in a high risk to you.

Your rights

Subject to the conditions and exceptions in applicable law, you have the following rights in relation to your personal data. As a matter of policy we extend these rights to all users, irrespective of the jurisdiction in which they are located.

Access. To obtain confirmation as to whether we process personal data concerning you and, if so, to obtain a copy of that data together with information about the processing.

Rectification. To have inaccurate personal data corrected and incomplete data completed. Much of your account data may be corrected by you directly in your account settings.

Erasure. To have personal data erased where it is no longer necessary for the purposes for which it was collected, where consent is withdrawn and no other basis applies, or where it has been processed unlawfully; subject to data we are required to retain by law.

Restriction. To obtain restriction of processing where the accuracy of the data is contested, where processing is unlawful but you oppose erasure, or where you require the data for legal claims.

Portability. To receive personal data you have provided to us, in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.

Objection. To object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests; and to object at any time and without qualification to processing for direct marketing purposes.

Withdrawal of consent. To withdraw consent at any time where processing is based on consent.

Complaint. To lodge a complaint with the supervisory authority in your country of residence, place of work or the place of the alleged infringement. We ask that you raise the matter with us first so that we may attempt to resolve it.

Requests should be made to [email protected] from the email address registered on your account. We may request further information to verify your identity where we have reasonable doubt, and will not use that information for any other purpose. We respond without undue delay and in any event within one month of receipt, which may be extended by two further months where the request is complex or where several requests have been received, in which case we will inform you of the extension and the reasons for it. No fee is payable unless a request is manifestly unfounded or excessive.

Additional information for California residents

This section supplements the remainder of this policy for residents of California and uses the terms defined in the CCPA.

The categories of personal information we have collected in the preceding twelve months are: identifiers, including name, email address and IP address; commercial information, being records of subscriptions purchased; internet or other electronic network activity information, being usage and log data; and, where inferred at all, only aggregate and non-identifying measures. The sources, business purposes and categories of recipient are described in sections 3, 4, 5 and 9. We retain each category as described in section 11.

We have not sold personal information, and have not shared personal information for cross-context behavioural advertising, in the preceding twelve months, and we do not do so now. We do not sell or share the personal information of consumers under 16 years of age, and the Service is not directed at minors.

California residents have the right to know what personal information is collected, used, disclosed and retained; to request deletion; to request correction; to opt out of sale or sharing, which is inapplicable to us as we do neither; to limit the use of sensitive personal information, which is inapplicable as we do not collect it; and not to receive discriminatory treatment for exercising any of these rights. We do not offer financial incentives in exchange for personal information. Requests may be made to [email protected] and may be submitted by an authorised agent on presentation of written authority.

Additional information for users in India

For the purposes of the DPDP Act, Business Quant is a Data Fiduciary in respect of the personal data described in this policy, and you are a Data Principal. This policy, together with the notice presented at the point of collection, constitutes the notice required under the DPDP Act, setting out the personal data processed, the purposes of processing, the manner in which rights may be exercised and the manner in which a complaint may be made to the Data Protection Board of India.

You have the right to obtain a summary of the personal data processed and of the processing activities undertaken, to obtain the identities of other Data Fiduciaries and Data Processors with whom your personal data has been shared, to correction, completion, updating and erasure of your personal data, to nominate another individual to exercise your rights in the event of your death or incapacity, and to grievance redressal. Requests and grievances may be addressed to [email protected], and will be acknowledged and dealt with within the period prescribed by law.

Where processing is carried out on the basis of your consent, that consent may be withdrawn at any time with effect for the future, and we will cease the relevant processing and cause our processors to do the same within a reasonable time.

Automated decision-making and profiling

We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR, and we do not profile users for marketing purposes.

Automated systems are used to meter usage against plan limits and to flag activity indicative of credential sharing, unauthorised automated access or other abuse. Where such a flag would result in the suspension or termination of an account, the matter is reviewed by a member of our team before action is taken or, where immediate action was necessary to protect the Service, promptly afterwards. You may contest any such decision by writing to [email protected] and obtaining human review.

Children

The Service is intended for investment professionals and adult private investors. It is not directed at children, and we do not knowingly collect personal data from any person under 18 years of age. If we become aware that we have collected personal data from a person under 18, we will delete it and close any associated account. A parent or guardian who believes that a child has provided personal data to us should contact [email protected].

Third-party websites

The Service contains links to websites operated by third parties, including regulatory filing repositories, company websites and official statistical publications. This policy does not apply to those websites. We do not control them and are not responsible for their content or their privacy practices. You should review the privacy policy of any third-party website before providing personal data to it.

Changes to this policy

We may amend this policy from time to time to reflect changes to the Service, to our practices, or to legal requirements. The amended version takes effect on the date it is posted at this URL and the “Last updated” date above will be revised accordingly. Where an amendment materially affects the manner in which we process personal data, we will provide notice by email or through the Service before it takes effect and, where required, will obtain your consent. We will not commence selling personal data or displaying third-party advertising by means of an amendment to this policy without express notice to you.

Contact and complaints

Questions about this policy, requests to exercise your rights, and complaints about our handling of personal data should be addressed to [email protected] or submitted through our contact page. Where you are not satisfied with our response, you retain the right to complain to your supervisory authority or, in India, to the Data Protection Board.

Business Quant Logo

The modern platform for fundamental stock research.

Product

Plans & Pricing API Documentation Data Sources Industry Classification

Company

About Us Contact Us Sitemap

Legal

Terms of Use Privacy Policy

© 2026 Business Quant. All Rights Reserved.

Create an account

Start your journey with us today. It's free!

Have an account already? Sign In

    Sign In

    Welcome back! Please enter your details.

    Forgot Password?
    Don't have an account? Create one now

    Reset Password

    Enter your email to receive a reset link.

    Back to Sign In
    60 %
    Get Pro for 60% off
    • Access all features immediately
    • Segment financials and operating data
    • Export data in CSV and XLSX formats

    Offer Ends In

    00Days
    00Hours
    00Minutes
    00Seconds

    Starting from $49 $19 / month

    Claim Discount