This Privacy Policy explains how SubTrack ("we", "us", "our") collects, uses, stores, and deletes personal data. SubTrack is operated by an individual (not a registered company) based in Visakhapatnam, Andhra Pradesh, India, who is the data controller for the purposes of this policy. We process personal data in accordance with applicable privacy laws, including the General Data Protection Regulation (GDPR) where it applies to you.
SubTrack is not directed at children, and we do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact us and we will delete it.
Data We Collect
| Data | Purpose | Legal Basis |
|---|---|---|
| Email address | Account identification, communication | Contract |
| Display name | Profile | Contract |
| Password (hashed) | Authentication | Contract |
| IP address | Security, rate limiting, session tracking | Legitimate interest |
| Device model / user agent | Session management, support | Legitimate interest |
| Push notification token | Delivering notifications | Consent |
| Social login identities (Google, Facebook) | Authentication | Contract |
| Consent records | Compliance with GDPR consent obligations | Legal obligation |
| Audit logs | Security, accountability | Legitimate interest |
| Financial data — subscription amounts, currencies, and billing periods you enter into SubTrack for the services you track (not your underlying bank or card transaction data) | Core app functionality: subscription tracking and spend insights | Contract |
| Subscribed-service names — which merchants/services a user tracks | Core app functionality; may reveal behavioral or lifestyle inferences | Contract |
| In-app purchase history and purchaser identity | Managing paid subscriptions to the app itself | Contract |
Financial data and subscribed-service names are collected because tracking subscriptions is SubTrack's core function — this is not incidental collection.
Data Processors
We use the following third-party services that may process your personal data:
| Processor | Purpose | Data Shared |
|---|---|---|
| OVH (hosting provider) | Application and database hosting, Singapore | All data described above |
| RevenueCat | In-app purchase management | Purchase history, a stable app user identifier |
| Firebase Cloud Messaging (Google) | Push notification delivery | Device push token, install identifier |
| Google OAuth | Social login | Email, profile, Google account identifier |
| Facebook OAuth | Social login | Email, profile, Facebook account identifier |
| Mailtrap | Transactional email delivery | Email address, email content |
Our application servers and database are hosted in Singapore. Depending on where you are located, using SubTrack may involve transferring your personal data outside your country or region, including to India and Singapore, and to the countries where the processors above operate. Where required, we rely on the safeguards those processors provide for international transfers (such as standard contractual clauses).
Data Retention
| Data | Retention Period | Notes |
|---|---|---|
| User account | Until deletion request | Soft-deleted immediately, hard-deleted after 30 days |
| Refresh tokens | Until expiry or logout | Deleted on account purge |
| Social login identities | Until unlinked or account purge | Deleted on account purge |
| Consent records | Until account purge | Deleted on account purge |
| Audit logs | 2 years | Actor reference anonymized on account purge |
| Subscription and financial records | Until account purge | Deleted with the account; not retained separately |
| Push notification tokens | Until logout, uninstall, or token rotation | Rotated tokens replace the prior value |
Your Rights (GDPR)
Where applicable under GDPR or other applicable data protection laws, you may have the following rights:
- —Right of access — request a copy of all data we hold about you
- —Right to erasure — request deletion of your account; your data is soft-deleted immediately and permanently purged within 30 days
- —Right to withdraw consent — withdraw any previously granted consent, without affecting the lawfulness of processing based on consent before its withdrawal
- —Right to data portability — export your data in a machine-readable format
- —Right to rectification — update your profile via in-app account settings
- —Right to object — where we process your data based on our legitimate interest (for example, security and fraud prevention), you can contact us to object; we will stop unless we have compelling legitimate grounds that override your interests
- —Right to lodge a complaint — you may complain to your local data protection supervisory authority if you believe we have processed your data unlawfully
To exercise any of these rights, contact us at support@ashersoft.com.
Security
We implement the following technical measures to protect your data:
- —Passwords are hashed, never stored in plaintext
- —Tokens are signed with a JWT signing key; refresh tokens rotate on each use, with reuse detection that revokes all active sessions if a used token is replayed
- —Account lockout after repeated failed login attempts
- —Rate limiting on all authentication endpoints
- —All data in transit encrypted via TLS
- —Security events logged and monitored
Contact
For any privacy-related requests or questions, contact: support@ashersoft.com
Changes to This Policy
We will notify users of material changes to this policy via email at least 14 days before they take effect. Continued use of the service after changes take effect constitutes acceptance.