Draft — this document is pending legal review and is not final.
Privacy Policy
Last updated: 2026-07-21
This policy explains what personal data Tracepine processes, why, and what rights you have. Tracepine is built EU-first: data is hosted in the EU, we set no advertising or analytics cookies, and we collect only what the service needs to chase invoices on your behalf.
1. Who we are (controller)
The service is operated by [Tracepine EOOD], a single-member limited liability company registered in Bulgaria, UIC [•], with registered address [•] ("Tracepine", "we").
For the personal data of account holders (your email address, profile and settings), Tracepine is the data controller. You can reach us about privacy at [privacy@tracepine.com].
2. Controller vs. processor — your clients' data
Tracepine is a tool you use to invoice and remind your own clients. For the client records, invoices and reminder emails you create in the app, you are the data controller and Tracepine acts as your processor: we store and process that data only to provide the service to you, on your instructions, and never use it for our own purposes.
A data processing agreement (DPA) covering this processor relationship is available at [•] and forms part of the Terms of Service.
3. Data we process
Account data: email address, password (stored as a hash by our authentication provider), UI language, business name and payment instructions you add in Settings.
Client data you enter (as our customer's records): client names, contact email addresses, country, language, VAT numbers, payment instructions and notes.
Invoice data you enter: invoice numbers, descriptions, line items, amounts, currencies, issue/due dates, payment status.
Reminder (chase) history: which reminder emails were scheduled and sent, when, in which language and tone, and any delivery errors.
Technical data: authentication session cookies and, for abuse protection on the sign-in form, a short-lived rate-limit counter keyed by email address and IP address (self-expiring, see section 8).
Waitlist data (landing page): email address and chosen language, used only to contact you about availability.
4. Purposes and legal bases
Providing the service (accounts, invoices, sending reminders): performance of a contract, Art. 6(1)(b) GDPR.
Legal compliance (e.g. retaining issued invoices where required by tax law): legal obligation, Art. 6(1)(c) GDPR.
Waitlist emails before launch: consent, Art. 6(1)(a) GDPR — you can unsubscribe at any time.
5. What we do NOT do
No advertising, no sale of personal data, no profiling, no automated decision-making with legal effects.
No analytics or tracking cookies — see the Cookie Notice for the complete list of the (functional-only) cookies we set.
Reminder emails are sent to your clients on your behalf and only for the invoices you enrol — never for marketing.
6. Processors and recipients
We use a small number of infrastructure providers (sub-processors) to run the service. Data is hosted in the EU:
Supabase (database, authentication and storage — EU region hosting).
Vercel (application hosting/CDN).
Resend (transactional email delivery — sending the reminder and sign-in emails).
Stripe (payment processing, once paid subscriptions launch).
[Complete list with entities, locations and safeguards: •]
7. International transfers
Data is stored in the EU. Where a provider processes limited data outside the EU/EEA (for example email delivery infrastructure), we rely on the European Commission's Standard Contractual Clauses and/or an adequacy decision. [Confirm per provider: •]
8. Retention
Account and client data: kept while your account exists; permanently deleted when you delete your account (see section 9).
Issued invoices: bookkeeping law in our launch markets (Bulgaria, Germany, Austria) requires invoices to be retained for a number of years (e.g. ~10 years in Germany under GoBD / §147 AO). Deleted issued invoices are therefore retained in a soft-deleted state rather than being purged; never-issued drafts are permanently purged 30 days after deletion.
Waitlist entries: deleted on request or once no longer needed after launch.
9. Your rights
Under the GDPR you can access, rectify, export, restrict, object to, and erase your personal data:
Access & portability: you can request a complete machine-readable export of your account data (JSON + CSV).
Erasure: Settings → Danger zone → Delete my account permanently deletes your account and all data in it, immediately and irreversibly.
Rectification: your account, client and invoice data is directly editable in the app.
For anything else, contact [privacy@tracepine.com]. We respond within one month.
10. Complaints
You can lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP, kzld.bg) or with your local EU supervisory authority.
11. Changes
We will announce material changes to this policy in the app and update the date at the top. The version you accepted at signup is recorded with your account.