Trackk — Privacy Policy

Effective date: TBD — set on Play Store launch Last updated: 28 May 2026

This Privacy Policy explains what personal data Trackk Technologies, a sole proprietorship of Ms. Vandana S (“we”, “our”, “us”) collects about you when you use the Trackk mobile application or related services (the “Service”), how we use it, with whom we share it, how we protect it, and the choices and rights you have.

This Policy forms part of, and should be read together with, our Terms of Service. By using the Service you acknowledge the practices described here.


Contents

  1. A One-Page Summary
  2. Information We Collect
  3. How We Use Your Information
  4. Legal Bases for Processing
  5. How We Share Your Information
  6. Where Your Data Is Stored
  7. How Long We Keep Your Data
  8. How We Protect Your Data
  9. Your Rights and Choices
  10. Children
  11. Cookies and Similar Technologies
  12. India-Specific Disclosures (DPDPA, 2023)
  13. Region-Specific Rights
  14. Permissions Disclosure (Play Store / App Store) 14A. Apple-Specific Disclosures (iOS, when available)
  15. Changes to This Policy
  16. Contact Us

1. A One-Page Summary

We’ve also written this out in plain English at the top so you don’t have to dig:

The rest of this document is the formal version.


2. Information We Collect

2.1 Information you provide

2.2 Information generated by your device, with your permission

2.3 Information collected automatically

2.4 What we do not collect


3. How We Use Your Information

We use the data described above strictly to:

Purpose Examples
Provide core features Sign-in, syncing your ledger between devices, detecting and showing transactions, computing group balances, generating reports
Personalisation Default currency, language, theme, suggested categories based on your past tagging
Service operations & security Account management, abuse prevention, rate-limiting, fraud detection on sign-in
Communications Operational emails (sign-in alerts, account-deletion confirmations), in-app messages
Legal compliance Responding to lawful requests, meeting tax/audit obligations, enforcing the Terms
Product improvement Aggregated, de-identified analytics (e.g. “X% of users use the goals feature”). We never combine this with personally identifying data for marketing

We do not:


4.1 Under India’s Digital Personal Data Protection Act, 2023

For users in India, we process personal data primarily on the basis of:

We do not currently qualify as a Significant Data Fiduciary under DPDPA § 10; if our classification changes, we will publish a notice in-app and update this Policy.

4.2 Under the GDPR / UK GDPR (when applicable)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:


5. How We Share Your Information

We share personal data only with:

5.1 Service providers (data processors)

We sign written agreements with all providers that require them to process your data only on our instructions and to keep it secure.

Google API Services User Data Policy (Limited Use)

When the optional email-scanning feature is enabled, Trackk’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

5.1A UPI apps you choose for settlement

When you tap “Settle” on a group debt and pick a UPI app to complete the payment, Trackk constructs a upi://pay?... deep-link containing the recipient’s UPI ID, name, the amount, currency, and a transaction note (e.g. “Settling Goa Trip group”). This data is handed to the UPI app you select (Google Pay, PhonePe, Paytm, BHIM, etc.); Trackk does not see, store, or route the actual payment. The UPI app’s own privacy policy governs what it does with that data thereafter.

5.2 Other users you invite

When you add someone to a group, they will see the group’s name, the expenses you’ve recorded in that group, your contribution and balance calculations, comments you post, and any display name you’ve chosen. If you have added a UPI ID to your profile, it is also shared with the members of every group you belong to so they can pay you back via their own UPI app; you can change or remove it at any time in Profile, which updates it across your groups. Apart from your display name and (if you set one) your UPI ID, they will not see your other groups, your personal transactions, your goals, your budget, your contact details (beyond what you’ve shared with them outside the app), or your account information.

We may disclose personal data:

5.4 What we never do

We do not sell personal data, and we do not share personal data with third parties for their own marketing or advertising.


6. Where Your Data Is Stored

Data may be processed in any country in which Google Firebase operates data centres or in which our service providers operate. Where transfers are made out of the EEA / UK / India, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms required by applicable data-protection law.


7. How Long We Keep Your Data

Category Retention
Account profile Until you delete your account
Transactions, groups, goals (active) Until you delete the record or your account
Group expenses where you participated Retained on the group document while the group still exists, even after you leave, but your personal identifiers are removed from your splits
Backups Up to 30 days after deletion, then permanently purged
Authentication / security logs Up to 12 months for abuse and fraud prevention
Records required by law (tax, accounting, dispute) For the period required by applicable law

When you delete your account from Profile → Delete Account, your profile, transactions, goals, budgets, subscriptions, investments, EMIs, reimbursement trips, FCM device tokens, and email-connection records are permanently deleted from active Firestore collections immediately. Your Firebase Authentication record is also deleted. Backup copies are purged within the rolling-backup rotation above (up to 30 days). Group expenses on which you participated remain on the group document so the other members’ ledgers stay intact, but your personal identifiers are removed from your splits.


8. How We Protect Your Data

We use security measures appropriate to the sensitivity of the data, including:

No system is perfectly secure. If we learn of a personal-data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority (e.g. the Indian Data Protection Board) and, where required, you, without undue delay and in accordance with applicable law.


9. Your Rights and Choices

Depending on where you live, you may have some or all of the rights listed below. Trackk extends these rights to all users globally as a matter of policy, subject to verification of identity.

We will respond to verifiable requests within the time required by applicable law (typically 30 days under the Indian DPDPA and the GDPR).


10. Children

The Service is intended for users aged 18 and above. The sign-up flow rejects any entered age below 18, and our Terms of Service require all Users to be 18+ as a contractual matter. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has nonetheless obtained an account, please contact support@trackk2save.com and we will delete the account and all associated data without delay.


11. Cookies and Similar Technologies

The mobile app does not use browser cookies. It uses standard local storage (AsyncStorage / Keychain / Keystore) to remember your sign-in state, preferences, and cached data. Our website (if any) may use strictly necessary cookies; details are shown in a banner the first time you visit.


12. India-Specific Disclosures (DPDPA, 2023)

For users in India, Trackk Technologies, a sole proprietorship of Ms. Vandana S is the Data Fiduciary in respect of the personal data described in this Policy. Our service providers (e.g. Google Firebase) act as Data Processors.


13. Region-Specific Rights

EEA / UK (GDPR / UK GDPR)

The Service is distributed via Google Play with a country allowlist scoped to India and selected South/Southeast Asian and Gulf markets where the SMS-detection feature works against the user’s bank-sender ecosystem (e.g. India, UAE, Saudi Arabia, Singapore, Malaysia, Sri Lanka, Bangladesh, Nepal, Bhutan, and the Maldives). The EEA and the United Kingdom are not in the v1.0 distribution allowlist. Accordingly, Trackk is not offered, marketed, or available for download in the EEA or the UK as of the effective date of this Policy, and we have not appointed an Article 27 representative.

If you nonetheless reside in the EEA or UK and have obtained the app (for example, by side-loading), you may contact us at support@trackk2save.com to exercise any rights you believe you have under the GDPR or UK GDPR; we extend the substantive rights in Section 9 globally as a matter of policy. We will publish an update to this Policy, appoint Article 27 representatives in the EU and UK, and (where required) declare a Data Protection Officer before we expand distribution to any EEA / UK country. This is targeted for release v1.1, when email-based transaction detection becomes the primary auto-detection path and the Service becomes useful to users whose banks do not send transactional SMS.

California (CCPA / CPRA)

We do not sell or share personal information for cross-context behavioural advertising. California residents have the right to know, delete, correct, and request restriction of sensitive personal information. To exercise these rights, email support@trackk2save.com with the subject line “California Privacy Request”.


14. Permissions Disclosure (Play Store / App Store)

For transparency, here is the complete list of sensitive permissions the Service may request, the feature each is used for, and whether the data leaves your device.

Permission Why we ask Leaves your device?
READ_SMS / RECEIVE_SMS (Android, optional) Detect bank/UPI/card transactions for review Raw SMS bodies never leave the device. The parsed fields (amount, merchant, timestamp) are synced to your private cloud space when you are signed in
READ_CONTACTS (Android, optional) Pick people to add as group members from your contact list Only the contact entry you tap to select is stored against that group; the rest of your address book is never read into our memory or transmitted
POST_NOTIFICATIONS (Android) / Notifications (iOS) Show a tappable card for each detected transaction No
RECEIVE_BOOT_COMPLETED, VIBRATE, WAKE_LOCK (Android) Restart the SMS listener after a reboot and deliver notifications reliably No
INTERNET Authentication, cloud sync, exchange-rate refresh, payment processing Yes — only for sign-in, sync, exchange-rate refresh, or a payment in flight
Document picker Import a JSON backup, attach a receipt image No, unless you choose to sync the attachment
FCM device token (Firebase Cloud Messaging) Deliver push notifications to your device The token is stored in Firestore against your user ID; it cannot be used to identify your device outside Firebase
Razorpay SDK (Android, when you purchase a subscription) Process the payment for a paid plan Card / UPI / bank details go directly to Razorpay; we never see them
gmail.readonly or equivalent (planned, optional) Detect bank emails — only when you connect a mailbox in Profile The relevant message content is read by our Cloud Functions in asia-south1; only parsed amount/merchant/timestamp are persisted
iOS Shortcuts deep-link (planned, iOS only, optional) Receive transaction data your Shortcut chooses to send The Shortcut runs entirely on your device; only the fields you forward are stored

We do not request ACCESS_FINE_LOCATION, CAMERA (other than when you tap “Attach receipt”), RECORD_AUDIO, READ_CALL_LOG, READ_PHONE_STATE (beyond the auto-fill of phone OTP), or any of the other high-risk permissions.


14A. Apple-Specific Disclosures (iOS, when available)

The current release of Trackk targets Android. The following disclosures will apply once the iOS version is published on the Apple App Store:


15. Changes to This Policy

We will update this Policy whenever our practices change. The Last updated date at the top will be revised. If the change is material, we will notify you in-app or by email before it takes effect and, where required by law, ask for your renewed consent.


16. Contact Us

For privacy questions, requests, or to exercise your rights:

Trackk Technologies, a sole proprietorship of Ms. Vandana S 3/336, Sri Sai Nagar, 2nd Street, Hosur, Krishnagiri District, Tamil Nadu – 635126, India Email: support@trackk2save.com Grievance Officer (India): Ms. Vandana S, support@trackk2save.com