SubTracker.io

Privacy Policy

Last updated: January 2026

1. General Information

This Privacy Policy explains how SubTracker.io (“we”, “us”, “our”) collects, processes, and protects personal data when you use our website and SaaS platform.

SubTracker.io is operated by:
Innopulse Consulting GmbH
Gotthardstrasse 30
6300 Zug
Switzerland
info@subtracker.io
+41 79 508 28 06

We comply with:
• the Swiss Federal Act on Data Protection (revDSG), and
• the EU General Data Protection Regulation (GDPR) where applicable.

2. Controller

The data controller within the meaning of revDSG and GDPR is:
Innopulse Consulting GmbH
Gotthardstrasse 30
6300 Zug
Switzerland

3. Scope of Data Processing

We process personal data only to the extent necessary to:
• provide and operate SubTracker.io
• fulfill contractual obligations
• ensure security and functionality
• comply with legal obligations

Personal data is never sold or shared for advertising purposes.

4. Data Collected

4.1 Website Usage Data
When visiting our website, we may collect:
• IP address (anonymized where possible)
• browser type and version
• operating system
• date and time of access
• referring URL

Legal basis:
Art. 6(1)(f) GDPR / Art. 31(1) revDSG (legitimate interest)

4.2 Account Registration & SaaS Usage
When creating an account, we collect:
• name (if provided)
• email address
• login credentials (hashed)
• subscription-related data entered by the user
• uploaded documents (contracts, files)

Legal basis:
Art. 6(1)(b) GDPR / Art. 31(2)(a) revDSG (contract performance)

4.3 Payment & Billing Data (Stripe)
Payments are processed via Stripe Payments Europe Ltd.
We do not store credit card data on our servers.

Stripe may process:
• payment method details
• transaction amounts
• VAT / MWST information (if applicable)
• billing country

Legal basis:
Art. 6(1)(b) GDPR (contract performance)
Art. 6(1)(c) GDPR (legal obligation – VAT)

Stripe acts as an independent data controller.
Stripe Privacy Policy: https://stripe.com/privacy

4.4 Communication Data
When contacting us via email or contact forms:
• name (if provided)
• email address
• message content

Legal basis:
Art. 6(1)(f) GDPR / Art. 31 revDSG (legitimate interest)

5. Cookies & Local Storage

We use technically necessary cookies only, unless additional cookies are explicitly accepted by the user.

Cookies may be used for:
• session management
• authentication
• security

No tracking or marketing cookies are used without consent.
A cookie consent banner is provided where required.

Legal basis:
Art. 6(1)(f) GDPR / Art. 31 revDSG
Consent where applicable (Art. 6(1)(a) GDPR)

6. Hosting & Infrastructure

SubTracker.io is hosted on Amazon Web Services (AWS).
Data may be processed in data centers located in:
• Switzerland
• European Union

AWS complies with:
• GDPR
• Standard Contractual Clauses (SCCs)
• ISO 27001

Legal basis:
Art. 6(1)(f) GDPR / Art. 31 revDSG

7. Data Security

We apply appropriate technical and organizational measures, including:
• TLS/SSL encryption
• access control systems
• least-privilege access
• regular security updates

8. Data Retention

Personal data is stored only as long as necessary:
• for contractual purposes
• to meet legal obligations
• or until deletion is requested and legally permitted

Account data is deleted after account termination unless statutory retention periods apply.

9. Data Sharing

We only share data with:
• hosting providers (AWS)
• payment processors (Stripe)
• authorities where legally required

No data is sold or transferred for marketing purposes.

10. International Data Transfers

Where data is transferred outside Switzerland or the EU, we ensure adequate protection via:
• adequacy decisions
• Standard Contractual Clauses (SCCs)

11. User Rights

Under revDSG and GDPR, you have the right to:
• access your data
• rectification of inaccurate data
• deletion (“right to be forgotten”)
• restriction of processing
• data portability
• object to processing
• withdraw consent at any time

Requests can be sent to:
info@subtracker.io

12. Automated Decision-Making

SubTracker.io does not use automated decision-making or profiling within the meaning of Art. 22 GDPR.

13. Changes to This Policy

We may update this Privacy Policy to reflect legal or technical changes.
The current version is always available on our website.

14. Contact

If you have questions regarding data protection, please contact:
info@subtracker.io
Innopulse Consulting GmbH, Gotthardstrasse 30, 6300 Zug, Switzerland