Skip to main content

Last updated: April 10, 2026

Privacy Policy

This privacy policy describes how HoldTrakr B.V. (in formation) processes your personal data in accordance with the General Data Protection Regulation (GDPR).

1. Data controller

The data controller for your personal data is:

HoldTrakr B.V. (i.o.)

Amsterdam, Nederland

privacy@holdtrakr.com

2. What personal data do we collect?

Account data

  • Email address (required)
  • Name / display name
  • Profile picture (optional)
  • Password (hashed with bcrypt — never stored in readable form)

Financial data (creators only)

  • Uploaded broker CSV files (transaction history)
  • Calculated portfolio returns and statistics
  • Stripe Connect account ID (for payouts)

Usage data

  • IP address (for rate limiting and fraud prevention)
  • Device and browser type
  • Pages visited and time of visit

3. Purpose and legal basis for processing

PurposeDataLegal basis
Account creation and managementEmail, name, passwordContract performance
Payment processingStripe customer ID, subscription dataContract performance
Broker data verificationCSV uploads, transactionsContract performance
Fraud and abuse preventionIP-adres, gebruikspatroonLegitimate interest
Marketing (newsletter)E-mailadresConsent

4. Retention periods

  • Account data: until 30 days after deletion request (then permanently deleted)
  • Financial transaction data: 7 years (statutory retention obligation)
  • Log files / IP addresses: maximum 90 days
  • Email consent: until withdrawal via unsubscribe link

5. Who do we share your data with?

We share your personal data only with the following sub-processors, under data processing agreements:

  • Stripepayment processing (US, EU Standard Contractual Clauses)
  • Resendemail delivery (US, EU SCC)
  • Supabase / PostgreSQLdatabase hosting (EU Frankfurt)
  • Cloudflare R2file storage (EU)
  • Vercelhosting platform (US, EU SCC)

We never sell your personal data to third parties.

6. Your rights

Under the GDPR you have the following rights:

  • Accessyou can request what data we hold about you
  • Rectificationyou can have incorrect data corrected
  • Erasureyou can have your account and all data permanently deleted
  • Portabilityyou can request your data in a machine-readable format
  • Objectionyou can object to processing based on legitimate interest
  • Withdrawal of consentyou can withdraw marketing consent at any time via the unsubscribe link in our emails

You also have the right to lodge a complaint with the Dutch Data Protection Authority (AP): www.autoriteitpersoonsgegevens.nl.

7. Contact

For questions about your personal data or to exercise your rights: privacy@holdtrakr.com

8. Cookie policy

HoldTrakr uses the following cookies:

  • next-auth.session-tokenauthentication cookie, strictly necessary, session duration
  • themestored theme preference (light/dark), functional, 1 year

We do not use third-party tracking or advertising cookies.

How do we verify transaction data?

Want to know how HoldTrakr checks broker data for reliability? We use five layers of verification — from basic checks to manual review.

Read how verification works →