Privacy
Privacy Policy
Last Updated: December 16, 2025
Introduction
This Privacy Policy explains how traq.to (“we,” “us,” or “our”) collects, uses, and protects your personal information when you use our service.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and applicable data protection laws.
Data Controller
privacy/design GmbH
Huntloser Str. 20a
26209 Hatten
hello@traq.to
What Information We Collect
Information You Provide:
- Account Information: Email address, name, and password when you create an account
- Payment Information: Billing details and payment card information (processed securely by Stripe)
- Usage Data: Information about how you use our service
- Communication Data: Messages you send to our support team
Information We Collect Automatically:
- Log Data: IP address, browser type, device information, and access times
- Cookies: We use essential cookies to maintain your session and preferences
- Analytics Data: Website usage patterns and interactions (via Google Analytics, subject to your consent)
Legal Basis for Processing (GDPR)
We process your personal data based on:
- Contract Performance: To provide our service to you (GDPR Article 6.1.b)
- Legitimate Interest: To improve our service and prevent fraud (GDPR Article 6.1.f)
- Consent: Where you have given explicit consent (GDPR Article 6.1.a)
- Legal Obligation: To comply with applicable laws (GDPR Article 6.1.c)
How We Use Your Information
We use your personal data to:
- Provide and maintain our service
- Process payments and manage subscriptions
- Process your requests and transactions
- Send you service-related communications
- Improve our service and develop new features
- Ensure security and prevent fraud
- Comply with legal obligations
Data Storage and Security
Hosting Provider:
We use Google Cloud services to host our application and store your data. Google Cloud complies with GDPR requirements and has appropriate security measures in place.
Your data is stored in data centers within the European Union.
Security Measures:
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in transit (TLS/SSL)
- Access controls and authentication
- Regular security updates and monitoring
Data Retention
We retain your personal data only as long as necessary:
- Account Data: Until you delete your account, plus 30 days for backup purposes
- Payment Data: Retained by Stripe according to their retention policy and legal requirements (typically 7 years for tax purposes)
- Log Data: 14 days
- Support Communications: Up to 3 years for legal purposes
Your Rights Under GDPR
You have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data (“right to be forgotten”)
- Right to Restriction: Limit how we process your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
To exercise these rights, please contact us at hello@traq.to.
Data Sharing
We do not sell your personal data. We only share data with:
- Google Cloud: Our hosting provider, acting as a data processor
- Stripe: Our payment processor for handling payments and subscriptions. Stripe is PCI-DSS compliant and GDPR-compliant. We do not store your complete payment card details on our servers
- Google Analytics: Our analytics provider for website usage statistics (anonymized and pseudonymized data only, subject to your consent)
- Legal Authorities: When required by law or to protect our rights
International Data Transfers
Your data is stored within the EU.
If we transfer data outside the EU, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses).
Cookies
We use the following types of cookies:
- Essential Cookies: Necessary for the service to function (e.g., session management)
- Analytics Cookies: Used to understand how visitors interact with our website (see Google Analytics section below)
You can control cookies through your browser settings.
Google Analytics
What is Google Analytics?
We use Google Analytics, a web analytics service provided by Google LLC (“Google”), to understand how visitors use our website and to improve user experience.
Legal Basis
We process analytics data based on:
- Consent (GDPR Article 6.1.a): When you accept analytics cookies
- Legitimate Interest (GDPR Article 6.1.f): To analyze website performance and improve our service
What Data is Collected?
Google Analytics collects:
- Usage Information: Pages visited, time spent on pages, navigation patterns
- Technical Information: Browser type, operating system, screen resolution, language settings
- Approximate Location: Country and city (derived from IP address)
- Device Information: Device type (desktop, mobile, tablet) and device model
- Referral Source: How you arrived at our website
IP Anonymization: We have enabled IP anonymization (anonymizeIP) in Google Analytics, which means Google will shorten/anonymize your IP address within EU member states before storing it. This means your full IP address is not stored.
Data Processor
Google acts as a data processor on our behalf. Google has certified compliance with the EU-U.S. Data Privacy Framework and is GDPR-compliant.
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4, Ireland
Google Analytics data is processed in accordance with Google’s data processing terms. More information: Google Analytics Terms of Service
Data Retention
Analytics data is retained for 26 months, after which it is automatically deleted.
Your Rights and Opt-Out Options
You have the following options to control Google Analytics:
- Browser Opt-Out: Use your browser’s cookie settings to block analytics cookies
- Google Analytics Opt-Out Browser Add-on: Install the official Google Analytics Opt-out Browser Add-on
- Do Not Track: We respect the “Do Not Track” browser setting
- Withdraw Consent: You can withdraw your consent at any time through our cookie settings
Data Shared with Google
The following data may be shared with Google:
- Anonymized IP addresses
- Pseudonymized user identifiers (randomly generated)
- Pages visited and interactions
- Device and browser information
We do not share personally identifiable information (PII) with Google Analytics.
Third-Party Access
Google may use this data for its own purposes, such as improving Google Analytics and other Google services, as described in their privacy policy: Google Privacy Policy
Changes to This Policy
We may update this Privacy Policy from time to time.
We will notify you of significant changes by email or through our service.
Contact Us
For questions about this Privacy Policy or to exercise your GDPR rights, contact us at:
Email: hello@traq.to
Address: privacy/design GmbH, Huntloser Str. 20a, 26209 Hatten
Supervisory Authority
You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not complied with data protection laws.