TracepineTracepine
Draft — this document is pending legal review and is not final.

Privacy Policy

Last updated: 2026-08-03

This policy explains what personal data Tracepine processes, why, and what rights you have. Tracepine is built EU-first: data is hosted in the EU, we set no advertising or analytics cookies, and we collect only what the service needs to chase invoices on your behalf.

1. Who we are (controller)

The service is operated by [Tracepine EOOD], a single-member limited liability company registered in Bulgaria, UIC [•], with registered address [•] ("Tracepine", "we").

For the personal data of account holders (your email address, profile and settings), Tracepine is the data controller. You can reach us about privacy at [privacy@tracepine.com].

2. Controller vs. processor — your clients' data

Tracepine is a tool you use to invoice and remind your own clients. For the client records, invoices and reminder emails you create in the app, you are the data controller and Tracepine acts as your processor: we store and process that data only to provide the service to you, on your instructions, and never use it for our own purposes.

A data processing agreement (DPA) covering this processor relationship is available at [•] and forms part of the Terms of Service.

If you received a payment reminder from one of our customers: the sender named in that email is responsible for your data as controller — they entered your contact details and chose to send the reminder. Please direct access or deletion requests to them (every reminder's reply address reaches them directly); we act only on their instructions and will forward any request we receive to the responsible customer. [Lawyer to confirm this fulfils our processor duties toward reminder recipients: •]

3. Data we process

  • Account data: email address, password (stored as a hash by our authentication provider), UI language, appearance (light/dark theme) preference, business name and payment instructions you add in Settings.
  • Invitation data: when a customer invites a collaborator to a client, we store the invited email address and role. So the emailed sign-in link can work, an account holding only that email address is created at invite time — before the invitee has accepted anything. Such an account grants no access to anything until the invitation is accepted. Invitations and never-used accounts are deleted automatically (see section 8).
  • Client data you enter (as our customer's records): client names, contact email addresses, country, language, VAT numbers, payment instructions and notes.
  • Invoice data you enter: invoice numbers, descriptions, line items, amounts, currencies, issue/due dates, payment status.
  • Reminder (chase) history: which reminder emails were scheduled and sent, when, in which language and tone, and any delivery errors.
  • Sign-in with Google (optional): if you choose it, we receive your email address and the basic profile Google shares (name, profile picture); we use the email to operate your account and do not use the rest. Google's own privacy policy governs Google's processing.
  • Signup verification: before an account is created with a password, a 6-digit code is emailed to prove the address is yours — we store it only as a salted hash, it expires after 10 minutes, and the record is deleted when signup completes.
  • Consent records: which version of the Terms and Privacy Policy you accepted, per document, with a timestamp — kept as the audit record of your agreement.
  • Technical data: authentication session cookies and, for abuse protection on the sign-in form, a short-lived rate-limit counter keyed by email address and IP address (self-expiring, see section 8). Our hosting infrastructure additionally processes standard request logs (IP address, browser information) for security and operation; these are retained briefly by the provider and are not linked to your account by us.
  • Waitlist data (landing page): email address and chosen language, used only to contact you about availability.

4. Purposes and legal bases

  • Providing the service (accounts, invoices, sending reminders): performance of a contract, Art. 6(1)(b) GDPR.
  • Pre-signup email verification (the 6-digit code): steps taken at your request prior to entering into a contract, Art. 6(1)(b) GDPR.
  • Security and abuse prevention (sign-in rate limiting): legitimate interest, Art. 6(1)(f) GDPR.
  • Creating a sign-in account for an invited collaborator before they accept: legitimate interest, Art. 6(1)(f) GDPR — the invitation cannot be delivered as a working sign-in link without it; the invitee is informed in the invitation email, and unaccepted invitations and their accounts are deleted automatically. [Lawyer to confirm basis: •]
  • Legal compliance (e.g. retaining issued invoices where required by tax law): legal obligation, Art. 6(1)(c) GDPR.
  • Waitlist emails before launch: consent, Art. 6(1)(a) GDPR — you can unsubscribe at any time.

5. What we do NOT do

  • No advertising, no sale of personal data, no profiling, no automated decision-making with legal effects.
  • No analytics or tracking cookies — see the Cookie Notice for the complete list of the (functional-only) cookies we set.
  • Reminder emails are sent to your clients on your behalf and only for the invoices you enrol — never for marketing.
  • We never reveal whether an email address has a Tracepine account: sign-in, signup and invitation flows respond identically either way, and any invitation or collaboration that ends — it expired, was withdrawn or removed by the inviter, or the invitee or collaborator deleted their account — leaves only one identical neutral "no longer active" placeholder that carries no reason and does not show whether the invitation was ever accepted.

6. Processors and recipients

We use a small number of infrastructure providers (sub-processors) to run the service. Data is hosted in the EU:

  • Supabase (database, authentication and storage — EU region hosting).
  • Vercel (application hosting/CDN).
  • Resend (transactional email delivery — sending the reminder and sign-in emails). As any email provider must, Resend retains delivery metadata — recipient address, timestamps, delivery status — for deliverability and abuse prevention, on its own retention schedule and under our data processing agreement (see section 8).
  • Stripe (card payments — only if you connect your own Stripe account; when a client pays by card, we pass Stripe the invoice number, amount, currency and your connected account, and the client enters card details on Stripe's own page, never on ours; also subscription billing once paid plans launch).
  • Google (only if you use Sign in with Google — Google confirms your identity to us; see section 3).
  • Beyond infrastructure, data is disclosed only where the service's purpose requires it: your clients receive the reminder emails you enrol (the invoice details you entered, your business name, your payment instructions, and your email address as the reply address), and collaborators you invite to a client can see that client's records for as long as you keep them invited.
  • [Complete list with entities, locations and safeguards: •]

7. International transfers

Data is stored in the EU. Where a provider processes limited data outside the EU/EEA (for example email delivery infrastructure), we rely on the European Commission's Standard Contractual Clauses and/or an adequacy decision. [Confirm per provider: •]

8. Retention

  • Account and client data: kept while your account exists; permanently deleted when you delete your account (see section 9).
  • Issued invoices: bookkeeping law in our launch markets requires invoices to be retained for a number of years — Bulgaria: 10 years (Закон за счетоводството); Germany: accounting documents under §147 AO (8 years for invoices/Belege since the 2025 reform, 10 for books — [confirm current periods: •]); Austria: 7 years (§132 BAO). Deleted issued invoices are therefore retained in a soft-deleted state rather than being purged; never-issued drafts are permanently purged 60 days after deletion.
  • Invitations to collaborate: expire 14 days after they are sent. Whenever an invitation or an accepted collaboration ends — the invitation expires, the inviter withdraws it or removes the collaborator, or the invitee or collaborator deletes their account — the email address is removed from it (nightly at the latest); only an anonymous "no longer active" placeholder remains, identical in every case, holding no personal data and not recording whether the invitation had been accepted.
  • Accounts created for an invitation that is never accepted: deleted automatically once no invitation for that email address remains — normally the night the last invitation expires (about two weeks after it was sent), and never earlier than 7 days after the account was created. Such an account contains nothing but the email address itself.
  • Sign-in and signup rate-limit counters (keyed by email address or IP address): stop having any effect when their window ends (at most one hour) and the stored record is deleted automatically about a week after its last activity, and with account erasure.
  • Signup verification codes: expire after 10 minutes; the record (the email address and a hashed code) is deleted when signup completes, within two days of expiry if the signup is abandoned, and in any case with account erasure.
  • Consent records: kept for as long as the account exists, as the audit record of what you accepted; deleted with the account.
  • Email delivery logs (at our provider): deleting your account erases all personal data in OUR systems. Resend processes delivery metadata (recipient address, timestamps, status) under our data processing agreement for as long as our agreement with them is active, and deletes customer data within 90 days of the agreement's termination.
  • Waitlist entries: deleted on request or once no longer needed after launch.

9. Your rights

Under the GDPR you can access, rectify, export, restrict, object to, and erase your personal data:

  • Access & portability: you can request a complete machine-readable export of your account data (JSON + CSV).
  • Erasure: Settings → Danger zone → Delete my account permanently deletes your account and all data in it, immediately and irreversibly. Your email is also removed from any invitations or memberships you hold in other users' workspaces — what remains there is an anonymous "no longer active" placeholder that neither names you, nor reveals that you had an account, nor shows whether you had accepted.
  • Rectification: your account, client and invoice data is directly editable in the app.
  • For anything else, contact [privacy@tracepine.com]. We respond within one month.

10. Security

We protect personal data with technical and organizational measures appropriate to the service:

  • Encrypted transport (HTTPS/TLS) throughout.
  • Passwords are stored only as hashes by our authentication provider; sign-in and invitation links are single-use and short-lived.
  • Row-level access control in the database: every account can reach only its own records, and records explicitly shared with it.
  • EU hosting for the database and application (see section 6).
  • Automatic deletion of unused data — expired invitations, never-engaged accounts, stale verification codes and rate-limit counters.

11. Complaints

You can lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP, kzld.bg) or with your local EU supervisory authority.

12. Changes

We will announce material changes to this policy in the app and update the date at the top. The version you accepted at signup is recorded with your account.

Terms of ServiceCookie NoticeImpressum← Back to Tracepine
© 2026 Tracepine.