This privacy statement explains which personal data Tradestack processes, why, and what rights you have. We keep it short where we can and specific where it matters.
1. Who we are
Tradestack is provided by Vargar (Nick Quispel), Ram 11, 3225 EG Hellevoetsluis, registered with the Dutch Chamber of Commerce (KvK) under number 83288198. For anything about privacy, e-mail nickquispel@vargar.eu.
2. Our two roles
- Controller. For the data we need to run our own business: your account, billing, security logs, support and the e-mails we send about the service. This statement covers that data.
- Processor. For everything a company puts into Tradestack: its customers, sites, work orders, hours, photos, signatures, forms and certificates ("customer data"). The company that uses Tradestack decides what happens with that data, and our data processing agreement applies. If you work for one of our customers and have a question about your data, please contact your employer first; we will help them answer it.
3. What we process, why, and for how long
| Data | Purpose and legal basis | Kept |
|---|---|---|
| Name, e-mail address, password (stored only as a hash), language, role and company | Creating and running your account (performance of the contract) | As long as the account exists; deleted within 60 days after the account or company is closed |
| Company name, billing e-mail, billing address, VAT number, type and last four digits of the payment method | Subscriptions, invoices and VAT (performance of the contract; legal obligation) | Invoices and the data on them: 7 years (Dutch tax retention obligation); the rest as long as the company account exists |
| IP address, browser and device, successful and failed logins, a log of changes made in the app | Security, preventing misuse and resolving disputes (legitimate interest) | Activity log 12 months; server logs 14 days; session data up to 2 hours after your last activity |
| E-mails we send (recipient, subject, content, delivery status) | Sending invitations, password resets and notifications, and checking they arrived (performance of the contract; legitimate interest) | Content 30 days; delivery data 12 months |
| Problem reports: your description, screenshots, the page, browser, device and app version | Fixing bugs and improving Tradestack (legitimate interest) | As long as the account exists |
| Messages you send us by e-mail | Answering your question (legitimate interest) | Up to 2 years after the last contact |
Backups are part of our security. Deleted data disappears from our backups within 14 days.
4. Cookies and data on your device
We use only what is needed for Tradestack to work. There are no analytics, advertising or tracking cookies.
- A session cookie that keeps you signed in, and a security cookie (XSRF-TOKEN) against forged requests.
- Your chosen language, stored in your session.
- When you use Tradestack as an installed app or offline, pages you opened and actions you took offline are stored on your device until they are synchronised. This data is removed when you sign out or another user signs in.
Fonts and images are served from our own servers. When you pay, you are sent to Stripe's checkout page, where Stripe's own privacy policy and cookies apply.
5. Who receives data
We never sell personal data. We share it only with parties that help us provide the service:
- our sub-processors for hosting, backups and e-mail, listed in the data processing agreement;
- Stripe (Stripe Payments Europe, Ltd., Ireland), which handles payments as an independent controller. We never see or store full card or bank details;
- authorities, only when the law requires us to.
6. Outside the European Union
We host Tradestack in the EU. Some providers are based outside the EU (for example our e-mail provider, which sends from its EU region). Where data could be accessed from outside the European Economic Area, we only work with parties that offer appropriate safeguards, such as the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
7. Security
All traffic is encrypted (HTTPS). Passwords are stored as hashes and sensitive settings are encrypted. Every company only sees its own data, and private files are only available to signed-in users with access. Encrypted backups are kept off-site. Only a small number of named people can access our servers. Read more in annex 2 of the data processing agreement.
8. Your rights
You can ask us to access, correct or delete your personal data, to restrict its processing, to receive it in a machine-readable format, or you can object to processing based on our legitimate interest. Much of it you can change yourself on your profile page. For anything else, e-mail nickquispel@vargar.eu. We answer within one month.
Not happy with how we handle your data? Please tell us first. You can also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or, in Belgium, the Gegevensbeschermingsautoriteit.
9. Automated decisions
We do not make decisions about you based solely on automated processing, and we do not build profiles.
10. Changes
When we change this statement, we update the date at the top. We inform account holders by e-mail or in the app about important changes before they take effect.