Privacy Policy
Draft — not yet in force. Last updated: —
Everything else is decided and describes what the software actually does. Search this file for [ and replace:
[LEGAL ENTITY]— your name, or the company's, if you incorporate[REGISTERED ADDRESS]— the postal address of the data controller[COMPANY NUMBER]— SIREN/SIRET once you have one; delete the line while you trade as an individual[AWS REGION]— the region you actually deploy to, e.g. eu-west-3 (Paris). If you pick a region outside the EU, §5 needs a transfer mechanism and that is a different conversation.
And to sign, before you take the first account: a Data Processing Agreement with each sub-processor. Both offer one as a click-through — AWS via the GDPR DPA in Artifact, Stripe via its Data Processing Agreement in the Dashboard. Sign them and keep the PDFs.
Have a lawyer read it once. It is cheaper than the alternative.
1. Who is responsible
The data controller for WolfTrack TR is [LEGAL ENTITY], [REGISTERED ADDRESS], [COMPANY NUMBER].
For anything to do with your personal data — access, correction, export, deletion, or a complaint — write to our support address. We answer within one month, as the GDPR requires.
If you are in the EU and you are not satisfied with our answer, you can complain to your national supervisory authority. In France that is the CNIL, cnil.fr.
2. What this covers
This policy explains what WolfTrack TR collects, why, and what happens to it. WolfTrack TR is a trading journal: you record your own trades and the service stores and analyses them for you.
3. What we collect, and why
- Your account. Your email address and a hash of your password — never the password itself. If you sign in with Google, we receive your email address and a stable identifier from Google, and no password at all. Lawful basis: performance of the contract.
- Your journal. Everything you enter: trades, prices, notes, scores, currency views, settings, and any screenshots or PDFs you attach. This is the content of the service and it belongs to you. Lawful basis: performance of the contract.
- Billing. If you subscribe, Stripe handles the payment. We receive a customer identifier and the status of your subscription. We never see, receive or store your card number. To give one free month per card, we do keep the identifier Stripe gives each card — its “fingerprint”, from which the number cannot be worked out — together with the account that used it for a free month. Lawful basis: performance of the contract, our legal obligation to keep invoices, and our legitimate interest in the free month not being taken again and again.
- Operational records. Ordinary server logs: IP address, timestamp, the request, and the browser's user-agent string. They exist to keep the service up and to stop people brute-forcing passwords. Lawful basis: our legitimate interest in running a service that is not trivially broken into.
- How you found us, and usage counts. When you create an account we record one word describing the link you arrived by — for example instagram if you followed the link in our Instagram profile, or direct if there was none. It is read from the address of the page and sent with the sign-up form; nothing is stored on your device to obtain it. We also keep, for each day, how many accounts opened the journal and how many sign-ins took place. These are counts: they say nothing about what you did, when, or which trades you looked at. Lawful basis: our legitimate interest in knowing which of our channels actually bring people, and whether the service is used.
- Visitor counts. For each day we count how many different people opened the site and how many opened the demo. To count someone once rather than at every page, the server computes a one-way code from your IP address and your browser's name, with a key that changes every day and never leaves our server; that code is deleted after two days, and only the day's total is kept. Nothing is stored on your device for this, no cookie is used, and neither the pages you read nor the time you spent are recorded. Lawful basis: our legitimate interest in knowing how many people the site reaches — audience measurement for our own use only, never shared.
4. What we do not do
- We do not sell your data, and we do not share it with advertisers.
- We do not use your trades to train anything, and we do not aggregate them into a product sold to anyone else.
- We do not connect to your broker. WolfTrack TR has no ability to place, modify or cancel a trade, and no access to any account of yours.
- There are no third-party analytics, no advertising pixels and no social trackers on this site. Fonts are served from our own domain, not from Google.
- We do not make automated decisions about you, and there is no profiling.
5. Where your data lives
On servers we rent from Amazon Web Services, in the region [AWS REGION]. Nothing is replicated to another region. Backups are held in the same region as the data they copy.
6. Who else touches it — our sub-processors
Two, and only two. Both are bound by a Data Processing Agreement and may use your data only to provide their service to us.
| Who | What for | What they hold | Where |
|---|---|---|---|
| Amazon Web Services | Hosting, storage, backups | Everything: your account, your journal, your attachments, the logs | [AWS REGION] |
| Stripe | Payments and invoicing | Your email, your card details (which we never see), your billing history | Stripe's own infrastructure, EU and US |
If we ever add a third, this table changes first and you are told before it takes effect.
Not sub-processors, and why: the currency strength panel uses the European Central Bank's public exchange rates, read through Frankfurter, and the central bank rates table uses the public data of the Federal Reserve Bank of New York, the ECB, the Bank of England, the Bank of Japan, the Swiss National Bank, the Bank of Canada and the Bank for International Settlements. Those requests are made by our server, at most twice a day, and carry nothing about you — no account, no address, no cookie. Your browser never contacts any of them. No personal data changes hands, so none of them is in the table above.
7. Cookies
One cookie, and it is strictly necessary: the session cookie that keeps you signed in. It is marked httpOnly, Secure and SameSite=Lax, which means no script on the page can read it and it is not sent from other people's sites. There are no advertising or analytics cookies, which is why this site does not greet you with a consent banner — under the ePrivacy rules a strictly necessary cookie does not need one.
8. How long we keep it
- Your journal and your account: for as long as the account exists.
- Once your account is deleted: the live data is deleted immediately. Backups are destroyed within thirty days at the latest, which is the full length of our backup cycle — after that window nothing of yours remains anywhere in our systems.
- Server logs: kept no longer than is useful for security and troubleshooting, and never repurposed.
- Usage counts: the marker that lets us count your account once per day is deleted after three days. What remains is the day's total — a number with nobody's name on it.
- Visitor counts: the daily code described in §3 is deleted after two days; only the day's total remains.
- Card fingerprint used for a free month: deleted after three years.
- How you found us: the one-word source recorded at sign-up is part of your account and is deleted with it.
- Invoices: kept for as long as tax law requires us to, which in France is ten years. This is the one thing deleting your account does not remove, because we are not allowed to remove it.
9. Your rights
If the GDPR applies to you, you have the right of access, rectification, erasure, restriction, portability, and objection:
- Access and portability: ask us and we send you everything you have entered, in a machine-readable file, on the free plan as well as on Pro.
- Rectification: edit anything in the app, any time.
- Erasure: ask us to delete your account and the data goes with it, on the timetable in §8.
- For these and anything else, write to our support address. We answer within one month and we will not ask you to justify yourself.
10. Security
Passwords are hashed with scrypt, a deliberately slow, memory-hard algorithm; they are never stored or logged in a readable form, and nobody here can read one. During the closed beta, accounts are opened by invitation; from the public launch, each email address is confirmed with a six-digit code before its account opens. Resetting a password ends every session that was open on the account. Sign-in and sign-up are rate-limited by address and by IP, and the sign-in, sign-up and password-reset forms ask you to type the characters shown in a picture. That picture is drawn by our own server: no third-party captcha service sees your visit, no cookie is set, and each picture is good for a single try. All traffic is HTTPS-only. The session lives in a cookie a script cannot read, so a cross-site scripting bug cannot walk off with it. Access to production data is limited to what is needed to operate the service.
No system is perfect. If we ever discover a breach affecting your personal data, we will notify the supervisory authority within 72 hours and tell you directly where the risk to you is high — rather than hope you do not notice.
Found a flaw? Tell us rather than use it. Report it in good faith and we will not come after you.
11. Children
WolfTrack TR is not intended for anyone under 18 and we do not knowingly create accounts for them.
12. Changes
If this policy changes in a way that matters, we will say so on this page and, for anything material, by email before it takes effect.
13. Contact
Privacy questions: our support address.