Privacy policy

Last updated 3 October 2026

1. Who we are

[Company name], registered in Estonia under registry code [registry code], at [address], is the controller of the personal data described here. Contact us at privacy@stortrace.com.

When an operator stores their customers' data in Stortrace, the operator is the controller of that data and we process it on their behalf under our Data Processing Agreement.

2. What we collect

[Account data: name, email, password hash, organization, role.]

[Usage data: sign-in times, IP address, request logs.]

[Billing data, once billing exists: company details and payment records. Card details are held by the payment provider, not by us.]

3. Why we use it

[Purpose and legal basis for each category: contract, legitimate interest, legal obligation.]

4. Who we share it with

[Subprocessors: Microsoft Azure (West Europe), Cloudflare, email provider, payment provider. Link to the list in the DPA.]

5. Transfers outside the EEA

[Where any subprocessor processes outside the EEA, and the safeguard relied on.]

6. How long we keep it

[Retention per category. Invoices and accounting records for the period Estonian law requires.]

7. Cookies

[The session cookie and the language cookie. Both are strictly necessary; no analytics or advertising cookies.]

8. Your rights

[Access, rectification, erasure, restriction, portability, objection. How to make a request and how quickly we answer.]

You can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the supervisory authority where you live.

9. Changes

[How we tell account holders about changes to this policy.]