Privacy Policy
Last updated: September 4, 2026 · Effective from: September 4, 2026
⚠️ Placeholder text. This document is a reasonable starting draft for a GDPR-compliant EU-based developer-API business. It is not legal advice. Please have it reviewed and customised by a qualified data-protection lawyer (DPO if you have one) before publication, particularly the controller details, retention periods, sub-processor list and lawful-basis section.
1. Controller
The data controller is Third Trail Limited, a private company limited by shares registered in Ireland under company number 819504, with registered office at Innisfree, Coolmona, Donoughmore, Co. Cork, P32 Y718, Ireland. VAT ID: [VAT number — to be added once registered].
Contact us about your personal data: dpo (at) thirdtrail.life
2. What personal data we hold
We hold the following personal data about you when you use thirdtrail:
| Category | Specific fields | Source |
|---|---|---|
| Identity | email address, username, first name, last name (if you choose to provide them) | provided by you at sign-up or via your account page |
| Account metadata | account creation date, last login date, account state (active / deactivated / pending deletion) | generated by the Service |
| Authentication | salted+hashed password; verified email addresses; linked social-login provider IDs (if you use Google/GitHub) | provided by you or your identity provider; password never stored in plaintext |
| Subscription / billing | plan you subscribed to; subscription dates; Stripe customer ID and subscription ID | generated by the Service and Stripe |
| API credentials | label, public 12-character prefix, SHA-256 hash of the secret. We never store API key plaintext. | generated by the Service |
| API usage | per-call timestamp, endpoint, HTTP status code, response time; daily-rollup totals per product | generated by the Service when you call our APIs |
| Communications | email correspondence with support; emails we send you about your account (reactivation keys, billing) | provided by you / generated by the Service |
| Diagnostic / security logs | request IPs, user-agent strings, error traces (retention limited) | generated by our infrastructure |
| Website analytics only if you consent |
a randomly generated Google Analytics client identifier, pages viewed, referring page, approximate location (country/region, derived from your IP address), device and browser type, and session timing | collected by Google Analytics in your browser, and only after you accept analytics cookies. See section 9. |
We do NOT hold your card details, bank details, or any payment instrument data — those are held directly by Stripe (see "Sub-processors" below).
3. Why we hold it (lawful basis)
- Performance of a contract (Art. 6(1)(b) GDPR) — identity, account metadata, authentication, subscription/billing, API credentials. Necessary to provide you the Service.
- Legal obligation (Art. 6(1)(c)) — retention of billing-related data for tax and accounting purposes per applicable law.
- Legitimate interests (Art. 6(1)(f)) — API usage logs (for billing reconciliation, fraud prevention and capacity planning); diagnostic / security logs (for service security and reliability). You may object at any time by emailing dpo (at) thirdtrail.life.
- Consent (Art. 6(1)(a), and Reg. 5 of S.I. 336/2011) — website analytics. Nothing is requested from Google and no analytics cookie is set until you accept; you can withdraw at any time from the Cookie settings link in the footer of every page, which also deletes the cookies. Withdrawal does not affect the lawfulness of processing carried out before it. Consent would also be sought for optional marketing emails, which we do not currently send.
4. How long we keep it (retention)
- Account data: for the lifetime of your account.
- Deletion-pending data: 30 days after you request deletion, then permanently deleted (you can cancel during this period — see Terms, section 9).
- API usage events: 24 months, then aggregated and the per-event rows deleted.
- Daily usage rollups: for the lifetime of your account.
- Billing-related data (invoices, subscription history): 7 years after the relevant transaction, as required by accounting / VAT law in Ireland.
- Diagnostic / security logs: 90 days.
- Email correspondence with support: 24 months.
- Website analytics: the analytics cookies expire 2 years after your last visit, or immediately if you withdraw consent. On the Google side, our property is configured to delete both event-level and user-level data after 14 months, the longest Google offers and the shortest that still allows a year-on-year comparison; only aggregated reports, which cannot be traced back to you, remain after that.
5. Who we share it with (sub-processors)
| Sub-processor | Purpose | Location / transfer mechanism |
|---|---|---|
| Stripe Payments Europe Ltd | Subscription billing, card processing, customer records | Ireland (EEA). Some support functions may involve transfer to Stripe US under Stripe's EU Standard Contractual Clauses. |
| Amazon Web Services (AWS) EMEA SARL | Cloud hosting, database, file storage and transactional email | Ireland (EEA). EU-based by configuration. |
| Google Ireland Limited only if you consent |
Website analytics (Google Analytics 4) — visit counts and which pages are read | Ireland (EEA), under the Google Ads Data Processing Terms. Onward transfer to Google LLC in the United States is covered by the EU–US Data Privacy Framework, to which Google LLC is certified, and by EU Standard Contractual Clauses. Google states that it does not log or store the IP addresses of EEA visitors. |
We do not sell your personal data. We do not share it with third parties beyond what is listed above except where required by law or to comply with a binding court order.
6. International transfers
All primary processing occurs within the EEA. Any transfer outside the EEA — Stripe US support functions, and Google Analytics data reaching Google LLC in the United States if you have accepted analytics cookies — is governed by EU Standard Contractual Clauses (SCCs), the EU–US Data Privacy Framework, or an equivalent valid transfer mechanism under Chapter V of the GDPR. If you do not accept analytics cookies, no data about your visit is sent to Google at all.
7. Your rights under the GDPR
You have the following rights, exercisable at any time:
- Right of access (Art. 15): download a copy of all personal data we hold on you via /account/data.json (logged-in users) or by emailing the DPO.
- Right to data portability (Art. 20): your data is provided in machine-readable JSON and CSV (/account/usage.csv) suitable for transfer to another service.
- Right to rectification (Art. 16): edit your details at any time from your account page.
- Right to erasure / "right to be forgotten" (Art. 17): request deletion from your account page (30-day grace period; permanent thereafter).
- Right to restrict processing (Art. 18): deactivate your account from your account page.
- Right to object (Art. 21): contact dpo (at) thirdtrail.life.
- Right to withdraw consent: where processing is based on consent, you can withdraw it without affecting the lawfulness of past processing. For analytics, use the Cookie settings link in the footer of any page — it stops the collection and deletes the cookies immediately.
- Right to lodge a complaint with your supervisory authority. In Ireland that is the Data Protection Commission; for other EU/EEA countries, see the EDPB members list.
8. Security
We protect your data with: encrypted-at-rest databases, encryption-in-transit (TLS 1.2+) for all traffic, SHA-256 hashing of secrets (passwords, API keys), AWS Systems Manager Parameter Store for application secrets, and standard production-hardened access controls. We do not, however, claim that any system is invulnerable.
If we become aware of a personal-data breach affecting your data, we will notify you and our supervisory authority in accordance with Art. 33 and 34 GDPR (without undue delay and, where feasible, within 72 hours).
9. Cookies and similar technologies
We set no advertising cookies and run no cross-site tracking. Cookies fall into two groups, and only the second one asks your permission.
9.1 Strictly necessary — no consent required
These are exempt from the consent requirement under Reg. 5(5) of S.I. 336/2011 because the Service cannot be provided without them. Refusing analytics does not remove them.
| Name | Purpose | Expires |
|---|---|---|
sessionid | Keeps you logged in. | When you log out, or after two weeks |
csrftoken | Protects form submissions against cross-site request forgery. | 1 year |
tt-consent | Remembers your answer to the analytics question, so
we do not ask again on every page. Contains only a version number and the words
granted or denied. | 6 months |
We also use your browser's local storage for one key, tt-theme, which records whether you chose the
light, dark or automatic appearance. It never leaves your device and is not sent to us.
9.2 Analytics — off until you accept
We use Google Analytics 4 to count visits and see which pages are read. It is the only non-essential technology on this site.
| Name | Purpose | Expires |
|---|---|---|
_ga | Distinguishes one browser from another using a randomly generated identifier. | 2 years |
_ga_EG54QP4B07 | Holds the session state for this site's Analytics property. | 2 years |
Until you press Accept, none of this happens: the Google script is never downloaded, no cookie is written, and no request — not even an anonymous one — is made to Google. That is a deliberate design choice, not merely a setting; the tag is loaded by our own code after your answer rather than shipped in the page. Google Consent Mode is additionally set to deny advertising and analytics storage by default.
You can change your mind at any time using the Cookie settings link in the footer of every page. Choosing Reject there stops the collection and deletes the two cookies above. Refusing costs you nothing: no feature is withheld, and you are not asked again for six months.
What Google receives, and what it does with it, is described in
Google's Privacy & Terms for business and
Google Analytics' own cookie documentation.
Google Signals is disabled on our property, so your analytics data is never joined to your
Google account and never used to build a cross-device profile. Independently of that setting, advertising storage
(ad_storage, ad_user_data, ad_personalization) is set to denied
for every visitor and is never raised, including when you press Accept — the consent we ask you for covers
measurement and nothing else. We run no advertising and no remarketing, and we do not ask you to consent to any.
You can also opt out of Google Analytics on every site you visit with Google's
browser add-on.
10. Children
The Service is intended for adults: you must be at least 18, or the age of majority in your jurisdiction if it is higher (see the Terms). We do not knowingly collect personal data from children. If you believe we have inadvertently collected personal data from a child, contact the DPO and we will delete it promptly.
11. Changes to this Policy
We will update this Policy when our processing changes. Material changes will be notified by email and/or in-product banner. The "Last updated" date at the top reflects the most recent revision.
12. Contact
Data-protection enquiries: dpo (at) thirdtrail.life
Postal address: Third Trail Limited, Innisfree, Coolmona, Donoughmore, Co. Cork, P32 Y718, Ireland