Legal
Privacy Policy
TrackNora (https://tracknora.com) is operated by Digital Services LLC, which is the data controller. This policy explains what we collect, what we deliberately cannot collect, and who else is involved.
Last updated: 16 August 2026
01The short version
Your bank statement is read by code running inside your browser tab. It is not uploaded, there is no server that receives it, and no copy of it exists anywhere but your own device. We could not hand your statement to anyone if we were asked to, because we never have it.
That is a design decision, not a promise about our intentions — open your browser’s network tab while converting a file and you can verify it yourself.
02What we never receive
- The statement PDF itself, or any page of it.
- Any transaction line — date, description, amount or balance.
- The name of the file, or the name of your bank.
- Any password used to open an encrypted statement PDF.
- Your card number, expiry or security code.
None of the above is sent to us, to Google Analytics, or to anyone else. The only figures that leave your device are a page count and a transaction count, which are needed to describe what you are buying and to size the job.
03What we do collect
Usage data, through Google Analytics. Standard web analytics: IP-derived approximate location, browser and device type, pages viewed, and which steps of the converter you reached. We deliberately report page addresses without their query string, so a payment reference never reaches Google.
Conversion measurement, through Google Ads. If you arrived from one of our adverts, the fact that a purchase happened — its amount and our internal job reference — is reported to Google Ads so the advert can be judged on revenue. No part of your statement is included, and the Stripe payment reference is not sent.
Payment data, through SWYPE FZE and Stripe. Payments are taken by our affiliated company SWYPE FZE ( Dubai World Trade Center, Sheikh Rashid Tower, Floor 04, No. FZBA 095 SRT, Dubai, United Arab Emirates) as merchant of record, using Stripe. Stripe collects your email address and card details directly. What comes back to us is only a confirmation that a payment completed, its amount, and our own internal job reference. Neither company ever sees your card details.
Nothing else. There is no account, no password, no profile and no database. We do not ask for your name and have nowhere to put it.
04Data stored on your own device
So that your converted data survives the trip to Stripe’s checkout and back, it is saved into your browser’s local storage (IndexedDB). This stays on your device and is never transmitted. Clearing your browser data removes it — and because we hold no copy, it cannot then be recovered.
05Cookies
Google Analytics (G-FQ0TYJEPSR) sets cookies to distinguish repeat visits from new ones. Google Ads (AW-18393127596) sets a conversion cookie so that a purchase can be attributed to the advert that brought you here. Stripe sets cookies on its own checkout pages for fraud prevention.
We do not run retargeting or behavioural advertising on this site, and we do not build advertising profiles from anything you convert.
06How the data is used
- To take payment and to confirm that a payment succeeded.
- To understand which pages people arrive on and where the converter loses them.
- To find and fix faults.
- To answer support and refund requests.
We do not sell data, and we do not share it for advertising.
07Who else processes data
- SWYPE FZE — our affiliated company, merchant of record for card payments.
- Stripe — payment processing. Stripe’s privacy policy.
- Google Analytics and Google Ads — usage measurement and advert conversion measurement. Google’s privacy policy.
- Cloudflare — hosting and delivery of this site. Cloudflare’s privacy policy.
08Retention
We operate no database, so there is no store of yours for us to keep. Payment records are retained by Stripe under their own policy and applicable financial-record law. Analytics data is retained under Google Analytics’ configured retention period.
09International transfer
Our providers operate globally, so the limited data described above may be processed on servers outside your country, where data protection law may differ. By using the Service you consent to that transfer.
10Disclosure
We may disclose the limited data we hold:
- Where required by law or in response to a valid request from a public authority.
- In connection with a merger, acquisition or sale of assets.
- To protect the rights, property or safety of the company or its users.
Note that this can never extend to your statement or its contents, which we do not hold.
11Security
The site is served over HTTPS and the download is unlocked only after a server-side check with Stripe that the payment genuinely completed. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security — but the strongest protection here is structural: the sensitive document never travels.
12Your rights (GDPR)
If you are in the European Union or European Economic Area you have the right to access, correct, delete, restrict or object to the processing of your personal data, the right to data portability, and the right to withdraw consent. Contact support@tracknora.com and we will act on it. In practice the only personal data connected to you is held by Stripe against your payment.
You can opt out of Google Analytics entirely with Google’s opt-out add-on.
13Your rights (CCPA)
If you are a California resident you may ask what data we hold about you and request its deletion. We do not sell or share personal information.
14Children
The Service is not intended for children under 13, and we do not knowingly collect data from them.
15Changes
We may update this policy. Changes are posted on this page with a new date above.
16Contact
The data controller is Digital Services LLC, 27 Takaishvili 36-38, P.O. Box 6004, Batumi, Georgia. Card payments are handled by SWYPE FZE, Dubai World Trade Center, Sheikh Rashid Tower, Floor 04, No. FZBA 095 SRT, Dubai, United Arab Emirates. Email support@tracknora.com.