Privacy Policy
Version 2026-06-08 · Last updated [PLACEHOLDER: date]
1. Who we are
Wallet Tracker (“we”, “us”) is operated by [PLACEHOLDER: legal entity / individual name] (“Operator”). This policy explains what personal data we collect, why, and your rights under the Singapore Personal Data Protection Act 2012 (PDPA).
2. What we collect
- Account email — used to identify your account and send service emails.
- Forwarded bank/card alert emails — the transaction-alert messages you choose to forward to us.
- Uploaded statements — any bank/card statement files (CSV/PDF) you upload to import transactions.
- Derived transaction data — amounts, merchants, dates, and categories parsed from the above.
- Technical data — [PLACEHOLDER: e.g. log/diagnostic data, if any].
We only process the alert emails you actively forward and the files you actively upload. We never access, connect to, or read your email inbox.
3. How we use your data
To parse and display your spending, estimate rewards, and provide the service's features. We do not sell your personal data. [PLACEHOLDER: describe any analytics or notifications.]
4. Third-party processors
We rely on the following processors, who handle data on our behalf:
- Supabase — database, authentication, and storage. [PLACEHOLDER: hosting region].
- Vercel — application hosting.
- Resend — transactional email delivery (e.g. confirmation emails).
- [PLACEHOLDER: any other processors].
5. Security
Each row of your data is protected by database row-level security (RLS), so your account can only ever read its own records. [PLACEHOLDER: encryption in transit/at rest, access controls, breach process.]
6. Retention
We keep your data for as long as your account is active, and delete it [PLACEHOLDER: retention period] after account closure, except where law requires longer.
7. Your rights
Under the PDPA you may request to access, correct, or delete your personal data, and withdraw consent at any time. To exercise these, contact our Data Protection Officer below. You can also delete your account in-app [PLACEHOLDER: confirm in-app deletion path].
8. Contact / DPO
Data Protection Officer: [PLACEHOLDER: name] · [PLACEHOLDER: contact email] · [PLACEHOLDER: mailing address].