In short: you can use SubTrack without an account. We collect only what it needs to work — the subscription details you choose to enter and, if you create an account to back them up, your name, email and password (stored as a secure hash). We never ask for bank or card details, we show no ads, we use no third-party analytics or tracking, and we never sell your data. You can delete your account and all its data at any time.
1. Interpretation and Definitions
- Application or App means the SubTrack mobile application for Android and iOS.
- Service means the App, its backend servers and this website.
- Account means your account on the Service — either a Guest Account, created automatically when you start using the App without signing up, or a Registered Account, which has an email address and password.
- Personal Data means any information that identifies, or can reasonably be linked to, an individual.
- Service Provider means a company that processes data on our behalf, such as our hosting or email provider.
- You means the individual using the Service.
2. Information We Collect
A. Information you provide
- Account information (Registered Accounts only): your name, email address and password. Your password is never stored in readable form — we store only a one-way cryptographic hash (bcrypt). You can use the App without providing any of these.
- Subscription information: details you enter for each subscription or free trial — service name, price, currency, billing cycle, category, start date, next payment or trial end date, status (active, trial or cancelled), auto-renew setting and reminder preference.
- Usage marks: the date you last tapped “used today” on a subscription, which powers the savings insights.
- Preferences: your display currency, appearance (dark, light or system) and whether notifications are enabled.
- Support messages: anything you send us by email, including your email address.
B. Information created by the Service
- Notifications: payment reminders, trial-ending alerts, renewal confirmations and monthly summaries generated from your subscription details.
- Password-reset codes: when you request a reset, we create a 6-digit code, store only its hash, and discard it after 15 minutes, five wrong attempts or first use.
- Guest Account key: when you start without signing up, we create a Guest Account and a random secret key. The key is kept only on your device; we store a one-way hash of it, which lets your device stay connected to its Guest Account. It contains no personal information.
- Last activity date: the date your Account last used the Service, used to remove abandoned Guest Accounts (see Data Retention).
- Sign-in sessions: a signed session token and a session version number that lets us sign out your other devices when you change or reset your password.
C. Information collected automatically
- Server logs: when the App or website contacts our servers, standard request logs record your IP address, the time, the requested address, the response status and your device's user-agent string. We use these only for security, abuse prevention (for example, limiting repeated sign-in attempts) and troubleshooting.
3. Information We Do Not Collect
SubTrack does not collect, access or request:
- bank account, credit/debit card or other payment credentials;
- your location, contacts, photos, files, camera or microphone;
- advertising identifiers, or data from analytics, advertising or tracking SDKs;
- SMS, emails or purchase history from app stores or other services.
SubTrack cannot see your real bank or card transactions — it only knows what you type into it.
4. How We Use Your Information
We use your information only to:
- create and secure your account and keep you signed in;
- store and display your subscriptions, totals, calendar, analytics and insights;
- generate payment and trial reminders based on the preferences you set;
- send password-reset codes and essential account emails;
- respond to your support requests;
- protect the Service against fraud, abuse and security incidents; and
- comply with legal obligations.
We do not use your information for advertising, we do not build marketing profiles, and we do not make automated decisions that have legal or similarly significant effects on you.
5. Legal Bases for Processing
Where laws such as the EU/UK General Data Protection Regulation (GDPR) or India's Digital Personal Data Protection Act, 2023 (DPDP Act) apply, we rely on:
- Contract — to provide the Service you signed up for (account, subscriptions, reminders);
- Consent — which you give when you create an account and choose to enter data, and which you can withdraw at any time by deleting your account;
- Legitimate interests — to keep the Service secure and prevent abuse; and
- Legal obligation — where we must retain or disclose information by law.
6. How We Share Information
We do not sell, rent or trade your personal data. We share it only in these limited cases:
- Service Providers: our cloud hosting and database providers, which store data on our behalf, and our email delivery provider, which sends password-reset emails. They may use your data only to provide their service to us and are bound by confidentiality and data-protection obligations.
- Font delivery: the App loads its typeface from Google Fonts. When it does, your device connects to Google's servers, which receive your IP address as part of that request. No account or subscription data is sent. See Google's Privacy Policy.
- App stores: Google Play and the Apple App Store process your download and may provide us with aggregated, anonymous statistics under their own privacy policies.
- Legal requirements: if required by law, court order or a valid government request, or to protect the rights, property or safety of our users, the public or us.
- Business transfers: if Gree Web Solutions is involved in a merger, acquisition or sale of assets, your data may be transferred subject to this Policy, and we will notify you beforehand.
7. Device Permissions and Storage
- Internet access — required to sync your account with our servers.
- Notifications (where your device asks) — used only to show payment and trial reminders. You can turn reminders off in the App or in your device settings.
- Secure on-device storage — your sign-in token, Guest Account key and theme choice are kept in your device's encrypted storage (Android Keystore / iOS Keychain) so you stay signed in. They are removed when you sign out, delete your data, or reinstall the App.
The App does not use cookies. This website does not set tracking or advertising cookies.
8. Data Retention and Deletion
Guest Accounts and backup
Data you add without signing up is stored on our servers, but it can only be reached from the installation of the App that created it. If you uninstall or reinstall the App, change phones, or clear the App's data, a Guest Account's data cannot be recovered. To keep it, create a Registered Account in the App (Profile → Sign Up): your existing data is kept and can be restored on any device by signing in.
If you sign in to an existing Registered Account while using a Guest Account, you choose whether the Guest Account's subscriptions are added to that account or discarded; the Guest Account is then deleted.
Retention periods
- We keep Registered Account data for as long as the account exists. You can edit your name, subscriptions and preferences at any time in the App.
- Guest Accounts not used for 90 days are deleted automatically, together with all their data.
- When you delete your data (in the App under Profile → Delete Account, or Delete My Data for Guest Accounts, or on our Delete Account page), your account, subscriptions, notifications and settings are deleted immediately and permanently from our live database.
- Residual copies may remain in encrypted backups for up to 30 days before they are overwritten; they are not used or restored in that time except to recover from a system failure.
- Server logs are kept for up to 30 days, unless needed longer to investigate a security incident.
- Password-reset codes expire after 15 minutes.
- Support emails are kept for up to 12 months after the conversation ends.
- We may keep information longer only where the law requires it.
9. Data Security
We protect your information with measures including:
- encryption in transit (HTTPS/TLS) between the App and our servers;
- password hashing with bcrypt, and hashed, short-lived password-reset codes;
- signed session tokens, with all other sessions revoked when you change or reset your password;
- rate limiting on sign-in and password-reset requests;
- strict separation so each user can access only their own data; and
- access to production systems limited to authorised personnel.
No method of transmission or storage is completely secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
10. Your Privacy Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy of it;
- Correct inaccurate data — most of it you can edit directly in the App;
- Delete your account and data — available instantly in the App or on our Delete Account page;
- Data portability — receive your data in a machine-readable format;
- Object to or restrict certain processing, and withdraw consent at any time;
- Nominate another person to exercise your rights in case of death or incapacity (DPDP Act); and
- Complain to your data-protection authority, such as the Data Protection Board of India or your local EU/UK supervisory authority.
California residents (CCPA/CPRA): you have the right to know, delete and correct your personal information, and to not be discriminated against for exercising these rights. We do not sell or “share” personal information for cross-context behavioural advertising.
To exercise any right, email info@greewebsolutions.com from the address linked to your account. We will respond within 30 days and may need to verify your identity first. We do not charge for these requests.
11. International Data Transfers
Our servers and Service Providers may be located outside your country. Where we transfer personal data internationally, we do so in line with applicable law — for transfers from the EEA or UK, using safeguards such as the European Commission's Standard Contractual Clauses.
12. Children's Privacy
SubTrack is not directed at children under 13 (or under 16 in the EEA and UK, or under 18 where the DPDP Act applies without verifiable parental consent). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact info@greewebsolutions.com and we will delete it.
13. Data Safety Summary
This summary matches the Data Safety and App Privacy disclosures in the app stores.
| Data type | Collected | Purpose | Shared |
|---|---|---|---|
| Name | Only with a Registered Account | Account management, personalisation | No |
| Email address | Only with a Registered Account | Account management, password reset | No |
| Subscription details you enter | Yes | App functionality | No |
| App interactions (“used today” marks) | Yes (optional) | App functionality (insights) | No |
| Payment/financial account info, location, contacts, photos | No | — | No |
| Advertising ID, analytics, crash reporting SDKs | No | — | No |
- Data is encrypted in transit.
- You can request that your data be deleted, and delete it yourself in the App.
- “Shared” excludes Service Providers that process data only on our behalf.
14. Changes to This Policy
We may update this Privacy Policy as the Service changes or the law requires. We will update the effective date above and, for material changes, notify you in the App or by email before they take effect.
15. Contact Us
For privacy questions, requests or complaints, contact:
Gree Web Solutions
Email: info@greewebsolutions.com
Website: https://greewebsolutions.com