Privacy Policy
Last updated: 4 August 2026
This Policy explains what personal data Trakys (“we”) collects, why, who we share it with, and what rights you have. We aim to collect as little as possible.
1. Who is the data controller
The data controller for personal data processed through Trakys is Mark Semikhov (JDG). Trakys is a product brand; the legal operator is the sole proprietorship listed on our Ownership page. Contact: [email protected].
2. What we collect and why
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Email, password hash, display name | Account authentication, password reset | Performance of contract |
| IP address, user-agent, login timestamps | Security, abuse prevention, audit trail | Legitimate interest |
| Tasks, notes, transactions, files you upload | To run the Service for you | Performance of contract |
| Billing identifiers (customer and subscription IDs, invoice metadata, card brand and last four digits where our payment processor provides them) | Subscription handling, invoices, fraud prevention, support | Performance of contract / legal obligation (tax) |
| Optional profile details (birth year, interests) | Understanding who uses Trakys to guide what gets built; never public, never shared with sponsors or anyone else | Consent (optional fields, removable in Settings) |
| Supporter listing (name or alias, message, optionally the amount) | Published on the Supporters page only if you choose a public listing when contributing; moderated before it appears | Consent |
| Email opt-in choices | Optional product updates or marketing communications, if you opt in | Consent (you can withdraw anytime) |
We do not run third-party ad trackers, we do not profile you for advertising, and we never sell your data to anyone.
We measure aggregate usage of the website and the app through a third-party analytics provider — page views, referral sources and approximate region, with IP anonymisation on and advertising features off. This runs by default, on the basis of our legitimate interest in understanding how the Service is used, and you can opt out of analytics cookies at any time on the Cookie Policy page. Anonymous visit counting (no cookies, no identifiers stored on your device) continues after an opt-out, both through the provider’s cookieless pings and through our own self-hosted counter.
3. Cookies
We set a session cookie required to keep you logged in. It is classified as “strictly necessary” under EU ePrivacy rules. Analytics cookies are set by default; the Cookie Policy lists every cookie and carries the switch to turn analytics off.
4. Who we share data with (subprocessors)
- Cloud hosting and database provider — runs the servers and the database the Service stores your data in
- Payment processor — payments, invoices, billing records and fraud controls; card details go straight to them and never reach us
- Email delivery provider — transactional email such as sign-in and password-reset messages
- Object storage provider — files you upload
- Website analytics provider — aggregate traffic statistics, unless you have opted out
Each provider operates under its own privacy terms and a Data Processing Agreement with us. We rely on Standard Contractual Clauses for transfers of EU personal data outside the EEA where required.
5. Retention
Account data is kept while the account is active. After deletion we remove or anonymize your data within a commercially reasonable period, except billing, accounting, and tax records that we must keep under applicable law, and records reasonably needed for security, fraud prevention, or dispute resolution. Retention periods may vary by country, but can extend up to the maximum period required for accounting, tax, chargeback, or fraud-prevention purposes. Server logs are kept up to 90 days.
6. Your rights
Depending on your jurisdiction, including the GDPR in the EEA, UK GDPR, applicable US state privacy laws, and Ukrainian privacy law:
- Access: request a copy of your data
- Rectification: correct inaccurate data
- Erasure: delete your account and data
- Portability: download your data in a structured format
- Object / restrict: stop certain processing (for example marketing)
- Withdraw consent: at any time, with no effect on past lawful processing
- Lodge a complaint with your local data protection authority
To exercise any of these, email [email protected].
7. Security
Passwords are stored only as salted hashes using a modern, deliberately slow algorithm — we never hold your password itself. All traffic runs over TLS. Session cookies are signed and HTTPS-only. Backups are encrypted at rest. Access to production systems is limited. That said, no system can be guaranteed 100% secure.
8. Children
The Service is not intended for users under 16. We do not knowingly collect data from children. If you believe we have, please contact us and we will delete it.
9. Changes
If we make material changes to this Policy, we will use reasonable efforts to notify you by email or in-app. The current version is dated above.