Legal
Privacy Policy
Effective date: 15 March 2026 · Last updated: 15 March 2026
GainTrace ("we", "us", or "our") is committed to protecting your privacy and ensuring your personal data is handled responsibly. This Privacy Policy explains how we collect, use, store, and share your personal data when you visit our website at gaintrace.com (the "Site") or use our services.
We process personal data in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
1. Data Controller
The data controller responsible for your personal data is:
GainTrace
Email: [email protected]
For any data protection enquiries or to exercise your rights, please contact us at the email address above.
2. Personal Data We Collect
We collect only the minimum personal data necessary for each purpose:
2.1 Data You Provide Directly
- Waitlist sign-up: Email address
- Contact forms: Name, email address, and message content
- Account creation (when available): Email address and password
2.2 Data Collected Automatically
- Usage data: Pages visited, time on page, referrer URL, and interactions (clicks, scrolls) — collected only with your consent via analytics cookies
- Device data: Browser type, operating system, screen resolution, and language preference
- IP address: Generalised to country level for analytics; full IP is not stored
2.3 Cookies & Similar Technologies
We use cookies to operate the Site and, with your consent, to analyse usage and deliver relevant content. You can manage your cookie preferences at any time using the cookie settings accessible via the cookie icon in the bottom-left corner of every page, or by clicking "Preferences" on the cookie banner.
| Category | Purpose | Legal Basis |
|---|---|---|
| Essential | Site functionality, security, cookie consent storage | Legitimate interest |
| Analytics | Understand how visitors use the Site (via Google Analytics / GTM) | Consent |
| Marketing | Deliver relevant advertisements and measure campaign performance | Consent |
We implement Google Consent Mode v2 so that no analytics or marketing data is collected until you provide explicit consent.
3. How We Use Your Data
We process your personal data for the following purposes:
| Purpose | Data Used | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Manage waitlist and send product updates | Email address | Consent |
| Respond to enquiries | Name, email, message | Legitimate interest |
| Improve Site performance and content | Anonymised analytics | Consent |
| Prevent fraud and ensure security | IP address, device data | Legitimate interest |
| Comply with legal obligations | As required | Legal obligation |
4. Data Sharing & Third Parties
We do not sell your personal data. We share data only with the following categories of service providers, each bound by data processing agreements:
- Hosting: Vercel (Site hosting and CDN) — data processed in the US and EU
- Analytics: Google Analytics / Google Tag Manager — only when you consent to analytics cookies
- Email: Our email service provider for waitlist communications — processes email addresses only
We do not transfer data to any third party for their own marketing purposes. Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
5. Data Retention
We retain personal data only for as long as necessary:
| Data Type | Retention Period | After Expiry |
|---|---|---|
| Waitlist email | Until product launch + 6 months, or until you unsubscribe | Deleted |
| Contact form submissions | 12 months from submission | Deleted |
| Analytics data | 14 months (Google Analytics default) | Anonymised / deleted |
| Cookie consent records | 24 months from last consent action | Deleted |
6. Your Rights
Under the GDPR, you have the following rights regarding your personal data. We respond to all requests within 30 days.
- Right of access — Request a copy of the personal data we hold about you
- Right to rectification — Request correction of inaccurate data
- Right to erasure — Request deletion of your personal data ("right to be forgotten")
- Right to restrict processing — Request that we limit how we use your data
- Right to data portability — Receive your data in a machine-readable format
- Right to object — Object to processing based on legitimate interest
- Right to withdraw consent — Withdraw consent at any time (for example, via cookie settings or by unsubscribing from emails)
To exercise any of these rights, email us at [email protected]. We may ask you to verify your identity before processing your request.
7. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the CCPA:
- Right to know — What personal information we collect and how it is used
- Right to delete — Request deletion of your personal information
- Right to opt-out — Opt out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination — We will not discriminate against you for exercising your rights
8. Data Security
We implement appropriate technical and organisational measures to protect your data, including:
- HTTPS/TLS encryption for all data in transit
- Encryption at rest for stored personal data
- Access controls limiting data access to authorised personnel only
- Regular security reviews and updates
No method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it to [email protected].
9. Children's Privacy
Our Site and services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at [email protected].
10. International Data Transfers
Your data may be processed in the United States and other countries where our service providers operate. When we transfer data outside the EEA, we rely on:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Other appropriate safeguards under GDPR Article 46
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page. We encourage you to review this page periodically.
12. Contact & Complaints
If you have questions about this Privacy Policy or wish to exercise your rights, contact us:
Email: [email protected]
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the EU, you can find your authority at edpb.europa.eu.