The Microcap Minute
Policies

Privacy Policy

Last updated: 10 August 2026

This policy explains what personal data The Microcap Minute and The Microcap Minute Global collect, why, and what you can do about it. The publisher is Ayush Agrawal, who is the data controller for the purposes of this policy.

Contact: hello@themicrocapminute.in

What we collect

Your email address, when you subscribe. This is the only piece of information we ask for, and it is the only one we need.

A name, if you choose to give one. It is optional and used only to address you.

Billing details, if you take a paid subscription. For newsletter subscriptions taken on Substack, these are collected and held by Substack and its payment processor Stripe. For newsletter subscriptions paid by UPI, and for Smart Investor Tracker alerts, they are processed by Zoho (Zoho Payments / Zoho Checkout). We never see or store your card number, and we have no access to it.

Delivery and engagement data, generated automatically by Substack: whether an issue was delivered, opened, and which links were clicked. We use this in aggregate to understand whether issues are arriving and being read.

Anything you put in an email to us, for as long as we need it to answer you.

We do not ask for, and do not want, your date of birth, your address, your income, your portfolio, or any other financial information. Please do not send it.

What we do not do

Why we hold it

To send you the newsletter you asked for, to take payment if you subscribe to a paid tier, to answer your emails, and to keep records we are required to keep. That is all.

Who else is involved

Running a newsletter means using other companies, and they process data on our behalf:

Each of these has its own privacy policy governing what it does with data. We choose providers that do not sell subscriber data.

For Smart Investor Tracker email alerts, two more processors are involved, both from Zoho and both hosted in Zoho’s Indian data centres:

The tracker also publishes a public Atom feed at tracker.themicrocapminute.in/feed.xml, which anyone can read without an account and which carries no personal data.

The tracker’s Filings Search page sends the words you type to our own search service, hosted on Render, a US cloud host, which returns matching filings. Queries are handled without any account or identity, are not logged with any identity, and are not sold or shared. The page also falls back to on-device search, so you can avoid this entirely.

The Classroom at school.themicrocapminute.in embeds videos from our own YouTube channel in privacy-enhanced mode (youtube-nocookie.com), so nothing is sent to Google or YouTube unless you press play. Pressing play is subject to Google’s privacy policy. The narrated audio chapters stream from the site itself.

Issues contain links to third-party sites, including StockAnalysis.com, StockCharts.com, and companies’ own pages. Some of these are affiliate links, which means we may earn a commission if you subscribe to a service after clicking one. This is disclosed in every issue.

Once you click a link you are on someone else’s website, governed by their privacy policy, not this one. They may set their own cookies and collect their own data. We have no control over and no visibility into that.

Cookies

The newsletter itself is delivered by email and sets no cookies on your device. Substack’s website sets its own cookies when you visit it, governed by Substack’s cookie and privacy policy, not by this one. Stripe sets cookies during checkout for fraud prevention.

The Smart Investor Tracker pages set no cookies either. They store a single dismissal flag in your browser’s local storage so a popup you have closed does not reappear, and that flag never leaves your device. Zoho’s checkout sets its own cookies during payment, governed by Zoho’s policy.

How long we keep things

Your email address for as long as you are subscribed, and for a short period afterwards in case you resubscribe or a billing question arises. Support correspondence for as long as it is useful to have a record. Billing records for as long as tax and accounting law requires.

If you unsubscribe and want your data deleted rather than simply deactivated, ask us and we will delete it.

Your rights

Whatever your country, you may ask us to:

Every issue carries a one-click unsubscribe link, which works immediately and needs no explanation. For anything else, email us. We will respond within thirty days and will not charge you for it.

Readers in the UK and EU have these rights under the GDPR, including the right to complain to a supervisory authority. Readers in India have comparable rights under the Digital Personal Data Protection Act, 2023. We apply the same standard to everyone regardless of where they live, because maintaining two standards would be worse than applying the higher one.

Children

The newsletter is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has subscribed, tell us and we will remove the record.

Security

We keep the subscriber list inside Substack rather than in spreadsheets or local files, and we use two-factor authentication on the accounts that can reach it. Card details are held by Stripe, a PCI-DSS Level 1 certified processor, and never touch our systems. No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that affects you, we will tell you.

Where your data goes

Substack Inc. and Stripe, Inc. are United States companies, so your email address and, for paid subscribers, your billing details are stored and processed in the United States, whatever country you read from.

Changes

If this policy changes materially, we will say so in an issue rather than quietly updating this page. The date at the top always reflects the current version.

Questions and data grievances

Email hello@themicrocapminute.in. A real person reads it.

For a formal complaint about how your personal data has been handled, the Grievance Officer under the Digital Personal Data Protection Act, 2023 is Ayush Agrawal, Publisher, at the same address. Put “Grievance” in the subject line. We acknowledge within 48 hours and aim to resolve within one month.

If you are not satisfied with the outcome, you may complain to the Data Protection Board of India, or to your own supervisory authority if you are in the UK or EU.