Legal / Privacy

Privacy Policy

This policy explains what personal data Tripwire processes, why it is needed, and the choices and rights available to you.

Last updated: September 1, 2026

1. Data controller and contact

The data controller for Tripwire is [Company Name / Villads Hvidt], with its registered address at [registered address].

Privacy questions and requests can be sent to [privacy@your-domain.example]. These bracketed details are placeholders and must be replaced before launch.

2. Data we collect

  • Account data: your email address and authentication identifiers supplied through Clerk. Clerk manages credentials and sessions; Tripwire does not store your password.
  • Trading-plan data: tickers, market, entry price, shares, targets, stop-losses, thesis text, trigger timestamps, cooldowns, and followed/overrode decisions that you submit or that the service generates to provide its core functionality.
  • Notification data: browser push-subscription endpoints and encryption keys, plus delivery-related operational information needed to send alerts.
  • Payment records: tier, payment status, amount, order/event identifiers, and refund status received from Lemon Squeezy. Tripwire never receives or stores your complete card or other raw payment credentials.
  • Technical data: limited server and security logs needed to operate, protect, and troubleshoot the service.

3. Why we use data and our GDPR bases

We process personal data only to:

  • create and secure your account;
  • store your pre-committed exit plans and trigger history;
  • check market-price thresholds and deliver push/email alerts;
  • process purchases, entitlements, refunds, and required records;
  • respond to support, privacy, and security requests; and
  • comply with applicable legal obligations.

Under the GDPR, these activities rely primarily on performance of our contract with you, compliance with legal obligations, and legitimate interests in operating and securing Tripwire. Where consent is the appropriate basis, you may withdraw it without affecting earlier lawful processing.

Tripwire does not sell personal data, build advertising profiles, or use your data for third-party behavioral advertising.

4. Service providers and payments

We use carefully selected providers to deliver Tripwire, including Clerk for authentication, MongoDB Atlas for data storage, Vercel for hosting and scheduled jobs, Resend for email, browser push services for notifications, and Twelve Data for market prices. They process data only as needed to provide their services under their applicable terms and data-protection commitments.

Lemon Squeezy is the Merchant of Record for Tripwire purchases. Lemon Squeezy processes payment details, collects and remits applicable VAT/sales tax, and administers payment and refund handling under its policies. Its own privacy notice governs the payment data it collects directly from you.

Some providers may process data outside the EEA. Where GDPR transfer rules apply, we rely on an adequacy decision or appropriate safeguards such as approved standard contractual clauses.

5. Cookies and tracking

V1 uses only cookies or similar storage that are necessary for account authentication, session security, and essential service operation, primarily through Clerk. Tripwire does not use analytics, advertising, or cross-site tracking cookies in V1. If optional tracking is ever introduced, it will not run before any legally required consent.

6. Retention and deletion

Account, position, exit-plan, trigger, and notification data is kept while your account is active or as needed to provide the service. Trigger decisions and thesis snapshots are retained to preserve the record you asked Tripwire to create. When you request deletion, we delete or anonymize data that is no longer needed, subject to backups, fraud prevention, dispute resolution, and legal recordkeeping duties.

Payment and tax records may need to be retained for the period required by applicable accounting, tax, and consumer-protection law. Lemon Squeezy controls retention of payment data in its role as Merchant of Record.

7. Your rights

Depending on your location, including under the GDPR, you may have the right to access, correct, export, or delete your personal data; restrict or object to certain processing; withdraw consent; and lodge a complaint with your local data-protection authority.

Send requests to [privacy@your-domain.example]. We may need to verify your identity before fulfilling a request. Mandatory legal retention may limit immediate deletion of specific records.

8. Security

Tripwire uses reasonable technical and organizational safeguards, including managed authentication, encrypted HTTPS transport, access-controlled server-side secrets, user-scoped database queries, and signature verification for payment webhooks. No online system is completely secure, so absolute security cannot be guaranteed.

9. Changes to this policy

We may update this policy when the service, providers, or legal requirements change. The revised policy will be posted here with a new “Last updated” date. Material changes will be communicated where required by law.

10. Contact

Contact [Company Name / Villads Hvidt] at [privacy@your-domain.example] or [registered address] about this policy or your data.