Official Privacy Statement

Privacy Policy

Effective Date: September 23, 2026 • Last Updated: September 23, 2026

At TrackMyCards (“we”, “our”, or “us”), accessible at https://trackmycards.online, protecting your privacy and safeguarding your personal financial information is our highest priority. This Privacy Policy explains how we collect, process, store, and protect your information when you use our website, application, and credit card statement tracking services.

Google API Services User Data Policy Compliance

TrackMyCards' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We do NOT use Google user data to serve advertisements.
  • We do NOT allow humans to read your emails unless you explicitly provide consent for technical debugging, or as required by law.
  • We do NOT transfer Google user data to third parties, data brokers, or lending organizations.
  • We do NOT use Google user data to train generalized artificial intelligence (AI) or machine learning (ML) models.

1. Information We Collect

We collect only the minimum information necessary to provide our credit card bill management and payment tracking features:

Account & Authentication Data

Your primary email address (Google or Outlook) used to authenticate your session, verify identity via OTP, and deliver payment reminders.

Card Statement Metadata

Credit card issuer name (e.g., HDFC, ICICI, SBI, Axis), last 4 digits of the card, total statement amount due, minimum amount due, statement generation date, and payment due date.

2. How We Access and Use Email Inboxes

When you connect your Google or Microsoft email account to TrackMyCards, you grant strictly read-only access (via the official Google OAuth scope https://www.googleapis.com/auth/gmail.readonly).

What Our Parser Can and Cannot Do:
  • CAN search for and parse automated credit card e-statements and payment receipt emails.
  • CANNOT send, compose, forward, or reply to emails on your behalf.
  • CANNOT delete or alter any messages or folders in your inbox.
  • CANNOT read your personal correspondence, photos, private documents, or OTPs.

3. Data Security & Encryption Standards

We implement industry-leading technical and organizational security controls to protect your data:

AES-256 GCM Token Encryption at Rest
OAuth refresh tokens are encrypted using military-grade AES-256-GCM authenticated encryption before being saved into the database. Plaintext tokens are never persisted.
TLS 1.3 Encryption in Transit
All network traffic between your browser, our servers, Google APIs, and Supabase is encrypted using modern TLS 1.3 cryptographic protocols.
Row Level Security (RLS) Isolation
PostgreSQL database policies enforce strict Row Level Security. A user can strictly query and modify only the records matching their own authenticated user ID.

4. Zero Data Selling & Third-Party Disclosure

We firmly believe that your financial habits are yours alone.

We do not sell, rent, monetize, or trade your personal or financial data to any third parties, including advertisers, credit score rating agencies, loan brokers, telemarketers, or financial institutions.

Data is shared strictly with essential infrastructure sub-processors required to host our software (e.g., Supabase for database hosting, Vercel for web serving), all bound by strict confidentiality and data protection agreements.

5. Your Rights, Data Retention & Account Deletion

You maintain full ownership and control of your data at all times:

  • Disconnect Inboxes: You can disconnect any connected Gmail or Outlook account with one click from your Accounts settings. All associated tokens will be permanently deleted immediately.
  • Revoke Google Access: You can revoke TrackMyCards' access to your Google account at any time via your Google Account Permissions dashboard.
  • Complete Account Deletion: You can request full deletion of your user account, linked cards, bills, and transaction ledger by clicking “Delete Account” in your profile or emailing us at support@trackmycards.online.

6. Children's Privacy

TrackMyCards is intended for individuals who hold credit cards and are at least 18 years of age (or the age of legal majority in their jurisdiction). We do not knowingly collect personal information from individuals under 18.

7. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect improvements in our product or changes in applicable laws. If we make material modifications, we will update the “Last Updated” date at the top of this page and notify you via email or through an in-app notice.

8. Contact Us & Grievance Officer

If you have any questions, feedback, or requests regarding this Privacy Policy or our security practices, please contact us:

TrackMyCards Privacy & Security Team
Jurisdiction: Kolkata, West Bengal, India