Legal
Privacy Policy
Last updated: 3 June 2026
1. Who we are
Tracej ("Trace", "we", "our", "us") is the operator of the Trace trading journal at tracej.com and app.tracej.com, and is the data controller for the personal information you provide when using our service.
Contact: lev.tracej@gmail.com
2. What data we collect
We collect only the data necessary to provide and improve the Trace service:
- Account data: email address and password (hashed) when you register.
- Trade data: all trading records, notes, account settings and performance data you enter into the journal.
- Usage data: pages visited, features used, session duration — collected anonymously to improve the product.
- Technical data: IP address, browser type, device type, and operating system, collected automatically when you access our service.
We do not collect payment card details directly. Payments are processed by our merchant of record Paddle.com Market Limited, and we receive only confirmation of payment status, the plan you purchased, and billing country (for tax purposes).
3. How we use your data
We use your data to:
- Create and manage your account
- Provide, maintain and improve the Trace service
- Calculate and display your trading performance statistics
- Send essential service communications (account confirmations, security alerts)
- Respond to support requests
- Comply with legal obligations
We do not sell your personal data. We do not use your trade data for any purpose other than providing you the service.
4. Legal basis for processing (GDPR)
If you are located in the European Economic Area, we process your data on the following legal bases:
- Contract performance: processing necessary to provide the service you signed up for.
- Legitimate interests: improving our product, preventing fraud, and ensuring security.
- Legal obligation: where processing is required by applicable law.
- Consent: for optional communications such as product updates and newsletters.
5. Data storage and security
Your data is stored securely using Supabase (PostgreSQL), hosted on AWS infrastructure in the EU region. We implement Row Level Security (RLS) at the database level, meaning your data is isolated from other users at the infrastructure layer — not just in application code.
We use industry-standard encryption in transit (TLS) and at rest. Passwords are never stored in plain text.
Despite our best efforts, no system is 100% secure. We encourage you to use a strong, unique password for your Trace account.
6. Data retention
We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it by law.
Anonymised and aggregated usage statistics (which cannot identify you) may be retained indefinitely for product analytics purposes.
7. Sharing your data — subprocessor list
We share your data only with the following categories of third-party subprocessors, and only to the extent necessary to operate the Service. Each is bound by a data processing agreement and is prohibited from using your data for their own purposes.
- Supabase (Supabase Inc., USA / EU regions): primary database, authentication, and file storage. Hosts trade data, voice notes, account configuration. EU region used by default.
- Vercel (Vercel Inc., USA): hosting and content delivery for tracej.com and app.tracej.com. Receives technical logs (IP, user-agent, request paths) for the duration of each HTTP request.
- Paddle.com Market Limited (UK): merchant of record for paid subscriptions. Handles checkout, payment processing, VAT/sales tax across jurisdictions, invoicing, refunds, and subscription cancellation. We receive only payment status, plan, and billing country from Paddle; Paddle's own privacy policy at paddle.com/legal/privacy covers card data, identity verification, and tax records they hold directly.
- Resend (Resend, Inc., USA): transactional email delivery (account confirmation, password reset, email change, magic link). Receives recipient email address and the rendered message body.
We do not use Google Analytics, Facebook Pixel, or any other third-party analytics, advertising, retargeting, or tracking scripts. We may disclose your data if required by law, court order, or regulatory authority.
International transfers. Where data is transferred to a country outside the EU/EEA (for example to Vercel or Resend in the United States), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure equivalent protection.
8. Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your personal data ("right to be forgotten").
- Portability: receive your data in a structured, machine-readable format.
- Restriction: request that we limit how we process your data.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: at any time where processing is based on consent.
To exercise any of these rights, contact us at lev.tracej@gmail.com. We will respond within 30 days.
EU residents can also lodge a complaint with their national data protection authority. Ukrainian residents have the equivalent rights under the Ukrainian Law "On Personal Data Protection" (No. 2297-VI) and may complain to the Ukrainian Parliament Commissioner for Human Rights.
9. Cookies
We use a minimal number of cookies required for authentication and session management. We do not use advertising or tracking cookies. See our Cookie Policy for details.
10. Children
Trace is not intended for users under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or via an in-app notification. The date at the top of this page indicates when the policy was last revised.
12. Contact and complaints
For any privacy-related questions or to exercise your rights, contact us at lev.tracej@gmail.com.
If you are in the EU and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.