tracken
v2.4 · Apr 2026
Sign inStart free
Legal · Privacy

Privacy Policy

We respect your privacy. This policy explains what we collect, why, and what control you have over it.

Last updated: 14 June 2026

1. Controller

The data controller responsible for your personal data is Tracken Technologies OÜ, registered in Estonia under code 17490505. You can reach us at info@tracken.ee for any privacy-related question or request.

2. What we collect

Account data: your name, email address, password hash, and authentication tokens (including Google sign-in identifiers if you use Google to log in).

Customer data: bank statements you upload, transactions, categories, classification rules, budgets, and related metadata. Bank statements may include account numbers, transaction descriptions, counterparties, and amounts.

Billing data: name and email associated with your subscription, plan, invoices, and subscription status. Card and payment details are processed and stored by Paddle, not by Tracken.

Usage data: IP address, browser and device characteristics, timestamps, request URLs, error logs, and similar technical data needed to operate and secure the service.

Cookies: a session cookie (authentication), a workspace cookie (active workspace), and a locale cookie (language preference). Tracken does not use third-party analytics or advertising cookies.

3. Why we process it (legal basis)

To provide the service you signed up for, including hosting your data, classifying transactions, and producing dashboards — performance of the contract (GDPR Art. 6(1)(b)).

To process payments and manage subscriptions — performance of the contract and compliance with tax/accounting obligations (Art. 6(1)(b) and 6(1)(c)).

To secure the service, prevent abuse, and debug errors — our legitimate interest in operating a safe service (Art. 6(1)(f)).

To send transactional emails (password resets, billing receipts, security notices) — performance of the contract.

To send product updates or marketing communications — only with your prior consent, which you can withdraw at any time.

4. AI-assisted classification

Tracken uses a layered classification pipeline: deterministic rules first, and only as a fallback for ambiguous transactions, a large language model from Anthropic (Claude).

When the LLM fallback is invoked, the transaction description and amount are sent to Anthropic for a single classification call. Anthropic processes this data as our sub-processor and does not use it to train its models.

You can disable the LLM fallback for your workspace from Settings.

5. Sub-processors

We rely on the following providers to operate the service. Each acts as a processor under GDPR Art. 28.

Vercel Inc. (United States) — application hosting and edge delivery, with EU data residency where supported.

Neon Inc. (United States) — managed PostgreSQL database; production data is stored in the EU (Frankfurt) region.

Anthropic PBC (United States) — LLM classification fallback (Claude). Used only when enabled, only for ambiguous transactions.

Resend Inc. (United States) — transactional email delivery (account, billing, security).

Paddle.com Market Limited (United Kingdom) — merchant of record for payments, invoicing, and tax compliance.

Transfers outside the EEA are protected by Standard Contractual Clauses where required.

6. How long we keep it

We keep your account and Customer Data for as long as your account is active. When you delete your account, we delete or irreversibly anonymise your personal data within 30 days, except where we are required to retain it (for example, invoices for tax purposes, which we retain for 7 years under Estonian accounting law).

Backups containing your data are rotated and overwritten on a rolling basis and are fully purged within 90 days.

7. Your rights

Under GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing based on legitimate interests. You may also withdraw consent at any time for processing that relies on it.

To exercise any of these rights, email info@tracken.ee. We respond within 30 days.

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or your local supervisory authority.

8. Security

Data is encrypted in transit (TLS) and at rest in our managed database. Passwords are stored as bcrypt hashes. Access to production systems is restricted to authorised personnel and logged.

If we ever experience a data breach affecting your personal data, we will notify you and the supervisory authority within 72 hours as required by GDPR Art. 33–34.

9. Children

Tracken is not directed to children under 18 and we do not knowingly collect personal data from them. If you believe a minor has provided us personal data, contact info@tracken.ee and we will delete it.

10. Changes to this policy

We may update this policy from time to time. When changes are material, we will notify you by email or in-product notice at least 14 days before they take effect.

11. Contact

Privacy questions and GDPR requests: info@tracken.ee.