Privacy Policy

Draft — not yet in force. Last updated: —

⚠ Four blanks, then this is ready for a lawyer to read.

Everything else is decided and describes what the software actually does. Search this file for [ and replace:

And to sign, before you take the first account: a Data Processing Agreement with each sub-processor. Both offer one as a click-through — AWS via the GDPR DPA in Artifact, Stripe via its Data Processing Agreement in the Dashboard. Sign them and keep the PDFs.

Have a lawyer read it once. It is cheaper than the alternative.

1. Who is responsible

The data controller for WolfTrack TR is [LEGAL ENTITY], [REGISTERED ADDRESS], [COMPANY NUMBER].

For anything to do with your personal data — access, correction, export, deletion, or a complaint — write to our support address. We answer within one month, as the GDPR requires.

If you are in the EU and you are not satisfied with our answer, you can complain to your national supervisory authority. In France that is the CNIL, cnil.fr.

2. What this covers

This policy explains what WolfTrack TR collects, why, and what happens to it. WolfTrack TR is a trading journal: you record your own trades and the service stores and analyses them for you.

3. What we collect, and why

4. What we do not do

5. Where your data lives

On servers we rent from Amazon Web Services, in the region [AWS REGION]. Nothing is replicated to another region. Backups are held in the same region as the data they copy.

6. Who else touches it — our sub-processors

Two, and only two. Both are bound by a Data Processing Agreement and may use your data only to provide their service to us.

WhoWhat forWhat they holdWhere
Amazon Web Services Hosting, storage, backups Everything: your account, your journal, your attachments, the logs [AWS REGION]
Stripe Payments and invoicing Your email, your card details (which we never see), your billing history Stripe's own infrastructure, EU and US

If we ever add a third, this table changes first and you are told before it takes effect.

Not sub-processors, and why: the currency strength panel uses the European Central Bank's public exchange rates, read through Frankfurter, and the central bank rates table uses the public data of the Federal Reserve Bank of New York, the ECB, the Bank of England, the Bank of Japan, the Swiss National Bank, the Bank of Canada and the Bank for International Settlements. Those requests are made by our server, at most twice a day, and carry nothing about you — no account, no address, no cookie. Your browser never contacts any of them. No personal data changes hands, so none of them is in the table above.

7. Cookies

One cookie, and it is strictly necessary: the session cookie that keeps you signed in. It is marked httpOnly, Secure and SameSite=Lax, which means no script on the page can read it and it is not sent from other people's sites. There are no advertising or analytics cookies, which is why this site does not greet you with a consent banner — under the ePrivacy rules a strictly necessary cookie does not need one.

8. How long we keep it

9. Your rights

If the GDPR applies to you, you have the right of access, rectification, erasure, restriction, portability, and objection:

10. Security

Passwords are hashed with scrypt, a deliberately slow, memory-hard algorithm; they are never stored or logged in a readable form, and nobody here can read one. During the closed beta, accounts are opened by invitation; from the public launch, each email address is confirmed with a six-digit code before its account opens. Resetting a password ends every session that was open on the account. Sign-in and sign-up are rate-limited by address and by IP, and the sign-in, sign-up and password-reset forms ask you to type the characters shown in a picture. That picture is drawn by our own server: no third-party captcha service sees your visit, no cookie is set, and each picture is good for a single try. All traffic is HTTPS-only. The session lives in a cookie a script cannot read, so a cross-site scripting bug cannot walk off with it. Access to production data is limited to what is needed to operate the service.

No system is perfect. If we ever discover a breach affecting your personal data, we will notify the supervisory authority within 72 hours and tell you directly where the risk to you is high — rather than hope you do not notice.

Found a flaw? Tell us rather than use it. Report it in good faith and we will not come after you.

11. Children

WolfTrack TR is not intended for anyone under 18 and we do not knowingly create accounts for them.

12. Changes

If this policy changes in a way that matters, we will say so on this page and, for anything material, by email before it takes effect.

13. Contact

Privacy questions: our support address.