Privacy Policy

Last updated: 2025.10.31

This Privacy Policy explains how Nodim (Tibor Tasi as representative) ("we", "us", or "our") collects, uses, and protects your personal data when you use Subtrakr ("Service"), available at subtrakr.app.

We are committed to protecting your privacy and handling your data transparently and securely, in accordance with the General Data Protection Regulation (GDPR) and other applicable laws.

By using Subtrakr, you agree to this Privacy Policy. If you do not agree, please do not use our Service.

1. Who We Are

Data Controller:

Nodim (Tibor Tasi as representative)

Address: 1092 Budapest, Erkel street 14/A A/5/2, Hungary

Email: [email protected]

This policy applies to our main domain subtrakr.app and all related subdomains.

2. Information We Collect

We collect and process the following types of personal data:

a. Account Information

When you register for Subtrakr, we collect:

  • Name
  • Email address

When you upgrade to a paid plan, we collect through Stripe:

  • Name
  • Email address
  • Billing address

b. Usage Data

We automatically collect technical and usage data such as:

  • IP address and device information
  • Browser type and operating system
  • Dates and times of access
  • Usage logs and feature interactions

c. Subscription Data

Within your account, you may add data such as:

  • Subscription or recurring expense names
  • Billing cycles
  • Payment amounts
  • Payment history and changes
  • Other configured subscription details

This data is stored solely to provide the core functionality of the Service.

3. How We Use Your Information

We use your personal data to:

  • Provide and maintain the Service
  • Process payments and manage subscriptions
  • Send transactional and account-related communications
  • Send optional marketing and product update emails (with consent)
  • Improve and analyze Service performance
  • Ensure security, prevent fraud, and fix technical issues

We do not sell or rent your personal information to any third parties.

4. Legal Basis for Processing

We process your data under one or more of the following legal bases:

  • Performance of a contract: To deliver the Service and process payments.
  • Consent: For analytics, cookies, and marketing emails.
  • Legitimate interest: To maintain security, prevent abuse, and improve the Service.
  • Legal obligation: To comply with tax or accounting laws when issuing invoices.

5. Data Storage and Location

All data is hosted on Cloudflare D1 database and related infrastructure located in the European Union.

Backups are retained for 30 days for disaster recovery.

6. Third-Party Services and Data Processors

We use trusted third-party providers to operate and improve our Service:

PurposeProviderLocationNotes
Hosting and DatabaseCloudflareEUServerless platform
Email deliveryBrevoEUTransactional and marketing emails
Payment processingStripeEU/USHandles all payment data directly
AnalyticsGoogle AnalyticsGlobalTracks usage metrics
Session analyticsMicrosoft ClarityGlobalRecords anonymized session data
Tag managementGoogle Tag ManagerGlobalLoads analytics and marketing tags
Marketing & adsFacebook Pixel, Google AdsGlobalFor retargeting campaigns
Feedback & updatesFeaturebase, HeadwayEU/USFor user communication and changelogs

Each processor complies with GDPR and offers appropriate safeguards for personal data transfers where applicable.

7. Cookies and Tracking

We use cookies and similar technologies on both our website (subtrakr.app) and web application (tracker.subtrakr.app) to support session management, analytics, and, in some cases, marketing.

On our website, cookies are used for analytics, functional, and marketing purposes. You can manage these preferences at any time through the "Cookie Settings" link in the website footer.

Our web application uses a separate technical environment with essential and limited analytics cookies required for login, security, and performance monitoring. These cookies cannot currently be managed through the website's cookie settings panel.

If you prefer, you can disable all cookies globally via your browser settings, although this may affect the functionality of both the website and the app.

For more details about the types of cookies we use and their purposes, please see our Cookie Policy.

8. Data Retention

We retain your data for as long as necessary to provide the Service.

After you delete your account, we permanently delete your personal data and associated records from active systems.

Backups may persist for up to 30 days before being fully purged.

9. Your Rights (GDPR)

You have the following rights regarding your personal data:

  • Access: Request a copy of the data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data.
  • Portability: Request your data in a structured, machine-readable format.
  • Withdraw Consent: Withdraw consent for marketing or analytics cookies at any time (where applicable).

Cookie and tracking preferences can be managed directly on our website (subtrakr.app) using the "Cookie Settings" link in the footer.

This applies only to cookies that rely on consent — such as analytics or marketing cookies on the public website.

Our web application (tracker.subtrakr.app) uses only essential and limited analytics cookies necessary for service functionality and improvement.

These operate under legitimate interest and do not require consent, so there are no in-app cookie settings.

To exercise your rights, contact us at [email protected].

We may require verification of identity before processing your request.

10. Security

We use HTTPS encryption for all network communication and apply envelope encryption for sensitive data stored in our database (such as name and email).

Access to production systems is restricted to authorized personnel only.

We regularly review our security practices to prevent unauthorized access, disclosure, or alteration.

In the event of a data breach, we will notify affected users and relevant authorities as required by GDPR.

11. Communications and Marketing

We may send:

  • Transactional emails: Account and billing notifications.
  • Marketing and product update emails: Only to users who have explicitly opted in.

You can unsubscribe from marketing communications at any time by clicking the "unsubscribe" link in our emails.

12. Third-Party Links

Our website and app may contain links to third-party sites (e.g., Featurebase, Headway, social media, Discord).

We are not responsible for the privacy practices or content of these external websites.

We recommend reviewing their privacy policies before interacting with them.

13. Children's Privacy

Subtrakr is not intended for individuals under the age of 18.

We do not knowingly collect personal information from minors. If you believe a child has provided us personal data, please contact us to have it deleted.

14. Changes to This Policy

We may update this Privacy Policy from time to time.

We will notify you of significant changes via email or through the Service.

The "Last updated" date at the top of this page indicates the most recent revision.

15. Governing Law

This Privacy Policy is governed by the laws of Hungary, without regard to conflict-of-law principles.

All matters relating to this policy shall be resolved in English.

16. Contact

If you have questions or requests regarding this Privacy Policy, please contact us at:

📧 [email protected]

🏠 Nodim (Tibor Tasi representative)

1092 Budapest, Erkel street 14/A A/5/2, Hungary

Join Discord