Privacy Policy

How we handle your data. The short version: we collect as little as possible, never sell it, and respect your rights.

Last updated March 30, 2026

1. Who we are

strackt is operated by Madonie Holding, registered in the Netherlands. When this policy mentions "strackt," "we," "us," or "our," it refers to Madonie Holding as the data controller responsible for your personal data.

For any privacy-related questions, contact us at [email protected].

2. What we collect

We collect different types of data depending on how you interact with us:

Information you provide

  • Waitlist & newsletter — your email address when you sign up for the waitlist or subscribe to The Log.
  • Account data — name, email address, and billing information when you create an account on the strackt platform.
  • Support & feedback — any information you share when contacting us through Featurebase or email.

Information collected automatically

  • Analytics — we use Umami, a privacy-focused analytics tool. Umami does not use cookies, does not collect personal data, and does not track you across websites. All data is aggregated and anonymous.
  • Server logs — standard web server logs including IP addresses, browser type, and pages visited. These are retained for a limited period for security and debugging purposes.

Information from third parties

  • Payment data — billing and payment information is processed by Paddle, our merchant of record. We do not store your credit card details.

3. Why we collect it

We process your data for the following purposes:

Purpose Legal basis (GDPR)
Providing and operating the strackt platform Contract performance
Sending waitlist updates and newsletters Your consent
Processing payments via Paddle Contract performance
Responding to support requests and feedback via Featurebase Legitimate interest
Sending transactional emails via Resend Contract performance
Aggregated, anonymous website analytics Legitimate interest
Security monitoring and abuse prevention Legitimate interest

4. Who we share it with

We do not sell your data. We share data only with the following processors, all necessary to operate the service:

Service Purpose Data shared
Paddle Payment processing Billing details, email
Resend Transactional email delivery Email address
Featurebase Support, feedback & roadmap Feedback submissions, chat messages, email (if provided)
Umami Anonymous website analytics No personal data
Mailcoach Waitlist & newsletter Email address

Mailcoach is self-hosted on our own infrastructure. Your newsletter data does not leave our systems.

5. How long we keep it

  • Account data — retained while your account is active, deleted within 30 days of account deletion.
  • Waitlist & newsletter — retained until you unsubscribe.
  • Server logs — retained for up to 90 days.
  • Payment records — retained as required by tax and accounting law (typically 7 years).
  • Support conversations — retained for up to 12 months after resolution.

6. Cookies

We keep cookie usage to a minimum. Our analytics tool (Umami) is cookieless and does not track you across websites.

Cookie Purpose Type
session Session management (platform login) Essential
XSRF-TOKEN Cross-site request forgery protection Essential
featurebase-* Feedback widget session persistence Functional

We do not use advertising or tracking cookies.

7. Your rights

Under the GDPR, you have the following rights:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your personal data ("right to be forgotten").
  • Restriction — ask us to limit how we process your data.
  • Portability — request your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interest.
  • Withdraw consent — unsubscribe from the newsletter at any time via the link in every email.

To exercise any of these rights, email [email protected]. We respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.

8. Data security

We take appropriate technical and organizational measures to protect your data. All connections are encrypted via TLS. Access to personal data is restricted to those who need it to operate the service.

9. International data transfers

Some of our processors operate outside the EU/EEA. Where data is transferred internationally, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses or adequacy decisions) to protect your data in accordance with the GDPR.

10. Changes to this policy

We may update this privacy policy from time to time. When we make significant changes, we will notify you via email or a notice on our website. The "last updated" date at the top of this page reflects the most recent revision.