Live ledger — real records, collected so far.

LEGAL · PRIVACY NOTICE

Privacy Notice

What RAKKAN keeps about you, why, who handles it for us, and how to have it deleted. We collect as little as running the Service needs.

In effect from 29 September 2026 · Terms of Use

1. Who is responsible

Calderaro is the controller of the personal data described here. Questions, requests and complaints go to [email protected]. This notice forms part of the Terms of Use.

2. What we collect

  • Account: your email address, a password (stored only as a hash by our authentication provider), the name and organisation you choose to give, your plan and any plan you requested, what you told us you would use it for, and the date and version of the Terms you accepted.
  • Use of your account: your watchlist, email alert settings, API keys (stored only as a hash, with a short prefix), webhook addresses and their delivery results, and monthly API request counts.
  • Billing: the status, plan and dates of your subscription, as Polar reports them. Card and payment details go to Polar, never to us.
  • Reports and notices: what you write in a “This is wrong” report, and the name, contact details and statement in a takedown notice.
  • Technical data: your IP address, used to rate-limit requests and block abuse; browser and device type; pages opened; and error and performance reports.
  • Session recordings, only if you allow them: a replay of how pages behaved during a visit, with all text masked and images blocked, and a performance profile of the page. See section 4.

3. Why, and on what legal basis

  • To provide the Service and your plan (performance of a contract): accounts, sign-in, watchlists, alerts, the API, webhooks, billing.
  • To keep it secure and working (legitimate interests): rate limits, CAPTCHA, fraud and abuse prevention, error reports, fixing faults.
  • To improve it (consent): session recordings and page performance profiles, only when you accept them.
  • To meet legal obligations (legal obligation, and the exercise of rights in legal proceedings): takedown notices, tax and accounting records, responses to authorities.

4. Cookies and similar technologies

  • Strictly necessary: sign-in session cookies, your display preferences, and the record of your privacy choice. These are needed for the site to work and do not need consent.
  • Security: Cloudflare Turnstile checks that sign-up, sign-in and password resets come from a person. It runs only on those forms.
  • Optional diagnostics: Sentry session replay and browser profiling. Off until you accept them, and you can change your mind at any time.

We use no advertising cookies and no cross-site tracking, and we do not sell or rent personal data.

5. Who processes it for us

We share personal data only with providers that run the Service for us, under contracts that bind them to it:

  • Supabase: database and authentication.
  • Netlify: the website. Railway: the API and background jobs.
  • Sentry: error, performance and (with consent) session reports.
  • Cloudflare: CAPTCHA (Turnstile), storage and network services.
  • Polar: payments, as merchant of record under its own privacy policy.
  • Our email provider: account and alert emails.

We may also disclose data where the law requires it, to protect our rights or others’ safety, or to a successor if the Service changes hands.

6. International transfers

These providers store and process data mainly in the United States, and may do so elsewhere. Where the law requires safeguards for such transfers (LGPD art. 33, GDPR chapter V), we rely on the providers’ standard contractual clauses or another lawful mechanism.

7. How long we keep it

  • Account data: until you delete the account, or we close it.
  • Error and performance reports: up to 90 days at Sentry.
  • Server logs: as long as our hosting providers keep them, typically days to weeks.
  • Takedown notices, billing and tax records: as long as the law requires or a legal claim could arise, even after an account is deleted.
  • Backup copies, where kept, are overwritten on their normal cycle.

8. Your rights, and deleting your data

Depending on where you live (for example under Brazil’s LGPD or the EU and UK GDPR), you may have the right to confirm we hold your data, access it, correct it, receive it in a portable form, have it deleted, restrict or object to its use, withdraw consent, and be told who it was shared with.

Delete everything yourself: the account page has a “Delete my account” button. It erases your account, profile, watchlist, alert settings, API keys, webhooks, pending emails, subscription records and plan requests at once, and cannot be undone. An active subscription must be cancelled first, so you are not charged again.

For any other request, write to [email protected]. We may need to confirm your identity first, and we answer within the time the law sets. You may also complain to your data protection authority, in Brazil the ANPD.

9. Security

We use encryption in transit, hashed passwords and keys, row-level access controls in the database, and the least access each part of the system needs. No system is perfectly secure, and we cannot guarantee the security of data sent to or stored by the Service. If a breach affects you and the law requires it, we will tell you and the authorities.

10. Children

The Service is not directed at children, and accounts require you to be at least 16. If you believe a child has given us personal data, write to us and we will delete it.

11. Changes to this notice

We will post changes here with their date. If they change materially how we use data you already gave us, we will tell account holders by email or on the site first, and ask for consent again where the law requires it.