ExProTrack Privacy Policy
Last updated: 03 December 2025
This policy explains how ExProTrack (“we”, “us”, “our”) collects, uses and protects personal data when you use our website and service (“Service”).
ExProTrack is a software tool for project budgeting and expense tracking for construction and project-based teams. ExProTrack is run as a sole proprietorship of Abu Bilal, based in Kerala, India.
We also use Paddle.com as our Merchant of Record. Paddle handles payments, invoices and taxes for paid plans and has its own privacy policy for that part of the data.
1. Data we collect
We may collect the following types of data:
- Account details – name, email address, hashed password, and basic profile details you choose to share.
- Business details – company name, role, contact details for you or your team.
- Usage data – log-in times, basic device and browser info, IP address, and pages you use in the app. This helps us keep the Service secure and working as expected.
- Project and expense data – project names, budgets, expense records, notes, and file attachments you upload.
- Support messages – emails or messages you send to our support address.
2. Payment data and Paddle
We do not store or process card numbers ourselves. All payments for ExProTrack plans are handled by Paddle.com, our Merchant of Record and payment partner.
Paddle may collect your card details, billing address, tax numbers and other billing data under its own terms and privacy policy. When you pay for ExProTrack, Paddle is the seller of record for the transaction and is responsible for tax handling (for example VAT or GST) on those sales.
3. How we use your data
We use your data to:
- create and manage your ExProTrack account;
- provide the Service and store your project and expense data;
- keep the Service secure and prevent misuse or fraud;
- send important service emails (for example login alerts, billing, changes to terms);
- answer support questions you send us;
- understand how the Service is used so we can fix problems and plan improvements.
4. Legal bases
We process personal data only when we have a legal reason to do so. These reasons include:
- Contract – to provide the Service you sign up for and to manage your subscription.
- Legal duty – to keep basic records for tax, accounting or other legal needs.
- Legitimate interest – to run, protect and improve the Service in a way that is fair and does not override your rights.
- Consent – for some optional emails or features. You can withdraw consent at any time by contacting us or using unsubscribe links where shown.
5. Sharing your data
We do not sell your personal data. We may share data with:
- Paddle.com – for handling payments, invoices and taxes for paid plans.
- Hosting and infrastructure providers – to run our servers, databases and backups.
- Email and support tools – to send service emails and manage support requests.
- Analytics tools – to see basic usage patterns (for example page views and error logs).
- Advisers or authorities – where required by law or to protect our rights, users or the Service.
When we use third-party providers, we try to ensure they only use your data to provide their service to us and keep it secure.
6. Data storage, location and security
We store data on secure servers and take reasonable steps to protect it from loss, misuse or unauthorised access. Access is limited to people and providers who need it for their work.
Because we use global cloud providers and Paddle, your data may be stored or processed outside your home country. Where required, we aim to use standard contract terms or similar safeguards for these transfers.
7. Data retention
We keep your account data for as long as your account is active. If you close your account, we keep only the data we need for legal, tax or audit reasons and for any ongoing disputes, then we remove or anonymise the rest.
8. Your rights
Depending on your country, you may have the right to:
- see what personal data we hold about you;
- ask us to correct data that is wrong or incomplete;
- ask us to delete some data, where we do not have to keep it by law;
- object to some types of use, such as certain direct marketing;
- ask for a copy of your data in a common format.
To use these rights, email support@exprotrack.com. We may need to confirm your identity before we act on your request.
9. Cookies
ExProTrack may use cookies or similar tools to:
- keep you logged in;
- remember simple settings;
- measure basic usage of the website and app.
You can control cookies through your browser settings. If you block some cookies, parts of the Service may not work as expected.
10. Children
ExProTrack is built for business use by adults. We do not target or knowingly collect data from children under 18. If you believe we have collected such data, please contact us and we will review and remove it where required.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we change the “Last updated” date at the top of this page. For important changes, we may also notify you by email or inside the app.
12. Contact
If you have questions about this policy or how we handle data, please email support@exprotrack.com.