← Back to TRACO
Privacy Policy
Last updated:
Version 1.0 · Effective
1. Data We Collect
Account & Identity
- Email address (for login, notifications, password reset)
- Name (optional, for display)
- Phone number (only for 7-day trial verification, hashed)
Device & Usage
- Device fingerprint (hashed, for trial abuse prevention)
- IP address (for security, rate limiting, geolocation)
- Browser/user agent, referrer
Trading Data
- Alerts you create: stock, prices, zone type, timestamps, status
- Vault trades: entry/exit, P&L, remarks, charts
- Broker positions (if connected): symbol, qty, avg price, unrealized P&L
Payments
- UPI transaction reference (UTR), amount, requested tier
- Payment screenshot (optional, if uploaded)
2. How We Use Your Data
- Provide the Service: alerts, Vault, analytics, broker sync
- Trial abuse prevention: phone/device/IP uniqueness checks
- Payment verification: manual review of UPI references
- Security: rate limiting, fraud detection, login alerts
- Improvement: aggregated, anonymized usage analytics
- Legal compliance: tax records, law enforcement requests
3. Data Sharing
We do not sell your data. Sharing only occurs:
- With your consent (e.g., broker connect → Dhan API)
- Payment verification (UTR shared with admin reviewers)
- Legal obligation (court order, regulatory request)
- Service providers (email via Resend, hosting on Render, DB on Supabase — all under DPAs)
4. Data Retention
- Account data: while account exists + 30 days after deletion
- Trading data (alerts, trades): indefinitely unless you delete
- Payment records: 7 years (tax/legal requirement)
- Phone (trial): hashed, retained for abuse prevention
- Logs (access, errors): 180 days (CERT-In)
5. Your Rights (DPDP Act 2023)
- Access: Request copy of your data → email support@traco.in
- Correction: Update inaccurate data in Settings
- Deletion: Delete account in Settings (irreversible)
- Portability: Export alerts/trades via CSV in Dashboard/Vault
- Withdraw consent: Disable broker, revoke trial, opt out of emails
- Grievance: Email grievance@traco.in (officer: [Your Name])
6. Security
- Passwords: bcrypt (cost 12), never stored in plaintext
- HTTPS everywhere, HSTS, CSP headers
- JWT tokens (httpOnly cookies), short expiry + refresh rotation
- Database on Supabase (SOC2, ISO27001), encrypted at rest
7. Cookies & Local Storage
auth_token (httpOnly cookie): session
refresh_token (httpOnly cookie): token rotation
traco_device_id (localStorage): trial fingerprint
- No third-party tracking cookies, no Google Analytics, no Meta Pixel
8. International Transfers
Data processed in India (Supabase Mumbai, Render Singapore). No transfers to inadequate jurisdictions without safeguards.
9. Children
Service not for under 18. We don't knowingly collect children's data.
10. Changes
Updates posted here with new version date. Material changes emailed.
11. Contact
Data Protection / Grievance Officer: grievance@traco.in
General: support@traco.in