Tracked Capital

Legal information for the Tracked Capital website and app.

Legal

Privacy Policy

Effective date: April 17, 2026

This Privacy Policy explains how Tracked Capital collects, uses, discloses, and safeguards information when you visit our website, create an account, connect financial institutions, or otherwise use our services.

Information We Collect

We may collect the following categories of information:

  • Account and profile information, such as your name, email address, login credentials, and account preferences.
  • Financial account information that you choose to connect through Plaid, including institution names, balances, transactions, holdings, liabilities, and related account metadata.
  • Communications data, such as emails you receive from us for verification, password resets, multi-factor authentication, and weekly digest delivery.
  • Device, browser, log, and usage information, including IP address, approximate geolocation derived from IP, page requests, timestamps, and error telemetry.
  • Security and abuse-prevention data, including CAPTCHA responses submitted through Cloudflare Turnstile and session or authentication cookies needed to keep you signed in securely.

How We Use Information

  • Provide, operate, maintain, and secure the Tracked Capital website and app.
  • Authenticate users, verify email ownership, support password resets, and offer multi-factor authentication.
  • Import, organize, and display connected financial data in dashboards, budgets, account views, and investment views.
  • Send service-related emails, including verification messages, login-related messages, and optional weekly digest emails.
  • Detect fraud, prevent abuse, troubleshoot errors, enforce rate limits, and monitor system reliability.
  • Improve product quality, performance, and security.

Plaid and Financial Data

If you connect an external financial account, Tracked Capital uses Plaid to access account data on a read-only basis. We do not initiate payments, move money, or use connected credentials to transact on your behalf. Plaid may collect and process information according to its own terms and privacy notices, which you should review separately.

Third-Party Service Providers

We use service providers to help operate the service. Based on the current product setup, these may include:

  • Plaid, for read-only financial account connectivity and data retrieval.
  • Mailgun, for transactional and product emails such as account verification, password resets, multi-factor codes, and digest delivery.
  • Sentry, for error monitoring, performance diagnostics, and operational alerting.
  • Cloudflare, including Cloudflare Workers for the marketing site and Cloudflare Turnstile for bot and abuse prevention.
  • Vercel, for hosting and infrastructure supporting the authenticated application experience.
  • Neon Postgres and Upstash Redis, for application data storage and operational services such as rate limiting.

These providers may process information only as needed to deliver their services to us and subject to their own legal terms and privacy practices.

Cookies and Similar Technologies

We use cookies and similar technologies that are necessary for authentication, session management, security, and basic site operation. We may also use technical logs and monitoring data to understand failures and maintain availability.

How We Share Information

We do not sell your personal information. We may share information:

  • With service providers that help us operate the service.
  • When you direct us to do so, such as when you choose to connect an institution through Plaid.
  • To comply with law, regulation, legal process, or enforceable governmental request.
  • To protect rights, safety, security, property, users, or the integrity of the service.
  • In connection with a merger, financing, acquisition, reorganization, or sale of assets.

Data Retention

We retain information for as long as reasonably necessary to provide the service, comply with legal obligations, resolve disputes, maintain security records, and enforce agreements. Retention periods may vary depending on the type of data and operational need.

Security

We use administrative, technical, and organizational safeguards designed to protect information, including server-side token handling and encryption of Plaid access tokens at rest. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your Choices

  • You can choose whether to create an account or connect financial institutions.
  • You can disconnect linked institutions within the product.
  • You can manage certain email preferences, including weekly digest settings, in the app.

Children’s Privacy

Tracked Capital is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised effective date.

Questions

If you have questions about this Privacy Policy, please contact us through the support or contact channel made available on the Tracked Capital website or inside the app.

You can also review our Terms of Use.