SubTrack

Privacy Policy

Last updated: 2026-09-12

This Privacy Policy explains how SubTrack ("we", "us", "our") collects, uses, stores, and deletes personal data. SubTrack is operated by an individual (not a registered company) based in Visakhapatnam, Andhra Pradesh, India, who is the data controller for the purposes of this policy. We process personal data in accordance with applicable privacy laws, including the General Data Protection Regulation (GDPR) where it applies to you.

SubTrack is not directed at children, and we do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact us and we will delete it.

Data We Collect

DataPurposeLegal Basis
Email addressAccount identification, communicationContract
Display nameProfileContract
Password (hashed)AuthenticationContract
IP addressSecurity, rate limiting, session trackingLegitimate interest
Device model / user agentSession management, supportLegitimate interest
Push notification tokenDelivering notificationsConsent
Social login identities (Google, Facebook)AuthenticationContract
Consent recordsCompliance with GDPR consent obligationsLegal obligation
Audit logsSecurity, accountabilityLegitimate interest
Financial data — subscription amounts, currencies, and billing periods you enter into SubTrack for the services you track (not your underlying bank or card transaction data)Core app functionality: subscription tracking and spend insightsContract
Subscribed-service names — which merchants/services a user tracksCore app functionality; may reveal behavioral or lifestyle inferencesContract
In-app purchase history and purchaser identityManaging paid subscriptions to the app itselfContract

Financial data and subscribed-service names are collected because tracking subscriptions is SubTrack's core function — this is not incidental collection.

Data Processors

We use the following third-party services that may process your personal data:

ProcessorPurposeData Shared
OVH (hosting provider)Application and database hosting, SingaporeAll data described above
RevenueCatIn-app purchase managementPurchase history, a stable app user identifier
Firebase Cloud Messaging (Google)Push notification deliveryDevice push token, install identifier
Google OAuthSocial loginEmail, profile, Google account identifier
Facebook OAuthSocial loginEmail, profile, Facebook account identifier
MailtrapTransactional email deliveryEmail address, email content

Our application servers and database are hosted in Singapore. Depending on where you are located, using SubTrack may involve transferring your personal data outside your country or region, including to India and Singapore, and to the countries where the processors above operate. Where required, we rely on the safeguards those processors provide for international transfers (such as standard contractual clauses).

Data Retention

DataRetention PeriodNotes
User accountUntil deletion requestSoft-deleted immediately, hard-deleted after 30 days
Refresh tokensUntil expiry or logoutDeleted on account purge
Social login identitiesUntil unlinked or account purgeDeleted on account purge
Consent recordsUntil account purgeDeleted on account purge
Audit logs2 yearsActor reference anonymized on account purge
Subscription and financial recordsUntil account purgeDeleted with the account; not retained separately
Push notification tokensUntil logout, uninstall, or token rotationRotated tokens replace the prior value

Your Rights (GDPR)

Where applicable under GDPR or other applicable data protection laws, you may have the following rights:

  • Right of access — request a copy of all data we hold about you
  • Right to erasure — request deletion of your account; your data is soft-deleted immediately and permanently purged within 30 days
  • Right to withdraw consent — withdraw any previously granted consent, without affecting the lawfulness of processing based on consent before its withdrawal
  • Right to data portability — export your data in a machine-readable format
  • Right to rectification — update your profile via in-app account settings
  • Right to object — where we process your data based on our legitimate interest (for example, security and fraud prevention), you can contact us to object; we will stop unless we have compelling legitimate grounds that override your interests
  • Right to lodge a complaint — you may complain to your local data protection supervisory authority if you believe we have processed your data unlawfully

To exercise any of these rights, contact us at support@ashersoft.com.

Security

We implement the following technical measures to protect your data:

  • Passwords are hashed, never stored in plaintext
  • Tokens are signed with a JWT signing key; refresh tokens rotate on each use, with reuse detection that revokes all active sessions if a used token is replayed
  • Account lockout after repeated failed login attempts
  • Rate limiting on all authentication endpoints
  • All data in transit encrypted via TLS
  • Security events logged and monitored

Contact

For any privacy-related requests or questions, contact: support@ashersoft.com

Changes to This Policy

We will notify users of material changes to this policy via email at least 14 days before they take effect. Continued use of the service after changes take effect constitutes acceptance.