Immutable archive · version 2026-07-v1 · published 2026-07-27T22:21:22Z · effective 2026-07-27T22:21:22Z · SHA-256 7af66518c497b5748cd214290250c3056b1e3c7531a308d628c7f36835a9d8fa
Privacy Policy and Personal Data Processing at TrendOrFlat
1. Who processes the data
The personal-data controller is Olga Igorevna Ilina, a self-employed individual under the Russian "Professional Income Tax" (NPD) regime, Tax ID (INN) 501803615021, data-related email [email protected] (the "Operator").
This Policy applies to the website https://trendorflat.com, the account, subscription, support, Telegram integration, and related TrendOrFlat features.
2. What data may be processed
Depending on how the Service is used:
- email, account identifier, and authentication service data;
- Telegram ID, name/username, language, and related authorization identifiers, if Telegram sign-in is used;
- plan, subscription status and period, and selected instruments;
- payment ID, amount, currency, status, and receipt data; full card details are processed by the payment provider YooKassa and are not passed to the Operator;
- notification, integration, and webhook settings, and hashed API tokens;
- support requests, messages, attachments, and diagnostic materials the User sends voluntarily;
- technical data: IP address in infrastructure logs, browser type, device, request time, security events, and errors;
- analytics and cookie data after the User's required choice;
- the version, date, and method of acceptance of legal documents.
The Service is not intended to process special categories of personal data, biometrics, health data, or data about minors. Please do not send such information through support.
Trade files uploaded to the public Simulator are processed locally in the User's browser and are never sent to TrendOrFlat servers.
3. Purposes and legal bases
- Account creation and sign-in (email, Telegram/OAuth ID, auth events) — conclusion and performance of the contract, necessary pre-contractual steps.
- Providing the subscription (plan, status, settings) — performance of the contract.
- Payments and accounting (payment ID, amount, currency, receipt) — performance of the contract and legal obligation.
- Notifications and integrations (Telegram ID, webhook, pairs, settings) — performance of the contract and the User's request.
- Support (contact, messages, attachments) — performance of the contract and legitimate interest; consent for optional attachments.
- Security and abuse prevention (technical logs, auth events) — legitimate interest and legal obligation.
- Product analytics (cookie ID, usage events) — consent, where required by applicable law.
- Marketing (email, ad events) — separate voluntary consent.
- Evidence of document acceptance (user ID, version, hash, time) — performance of the contract, legitimate interest, legal obligation.
Consent is not used as a universal basis for processing that is necessary to perform the contract.
4. Sources of data
Data comes directly from the User; from OAuth and Telegram sign-in providers; from the payment provider; automatically from the browser, app, and infrastructure; and from support requests and bug reports.
5. Recipients and processors
The Operator engages the following actually connected providers:
- Supabase — database, authentication, and storage of core account data;
- Cloudflare — CDN, DNS, attack protection, and infrastructure web analytics;
- YooKassa — card payment processing;
- Telegram — account sign-in and notifications, if the User enables that feature;
- Sentry — technical error diagnostics;
- Google Analytics 4 and Yandex Metrica — product analytics, loaded only after the User's explicit consent in cookie settings and only if the owner has enabled the relevant counter.
No other providers, including any payment systems not listed above, are used. This list may be updated as the Service evolves; the current version of this Policy is published at /privacy. Data may also be disclosed to authorized authorities, auditors, and professional advisers where required by law.
6. International transfer and place of storage
Primary regions and infrastructure:
- Supabase — database, authentication and core account storage (cloud provider; project region per Supabase configuration, accessed from the Russian Federation over protected channels);
- Cloudflare — CDN, DNS and site protection (global edge network);
- YooKassa — payment processing in the Russian Federation / under the payment provider’s rules;
- Sentry / Google / Yandex — technical and analytics processing in the vendors’ regions, only when the feature is actually used.
For cross-border transfers the Operator relies on the contract with the User, the need to perform the offer, and safeguards (encryption in transit, access control). Where applicable law requires an extra notice or consent for a specific country, the Operator will request it separately or limit the transfer.
7. Retention periods
The Operator stores personal data no longer than required by the processing purposes, the contract and applicable law (Russian Federal Law No. 152-FZ). After the purpose is achieved or consent is withdrawn, data are deleted or anonymised within the statutory period (generally within 30 days), unless a longer retention is required by another federal law or the contract.
Category-specific periods:
| Category | Period | Basis |
|---|---|---|
| Account and profile | While the account is active; after account deletion or consent withdrawal — delete/anonymise within 30 days, except categories below | 152-FZ |
| Payments, receipts, tax calculation records | at least 5 years after the end of the period in which the payment was made | Tax Code of the RF art. 23(1)(8); Accounting Law No. 402-FZ art. 29 |
| Legal acceptances of the offer and consents (contract evidence) | 3 years after the end of the relationship; where payments exist — until the related 5-year tax retention ends | Civil Code art. 196; Tax Code |
| Support tickets and attachments | 3 years after ticket closure | Civil Code art. 196 |
| Technical and security logs | 12 months | security / incident investigation |
| Sentry errors | 90 days, then delete or anonymise | diagnostics |
| GA4 / Yandex Metrica | until cookie consent is revoked, and no longer than the relevant vendor identifier settings (typically up to 14 months) | consent; vendor settings |
| Backups | up to 35 days of rotation on top of source-data periods | continuity |
After the period expires, data are deleted or anonymised unless the law requires longer retention.
8. Cookies and analytics
8.1. Strictly necessary cookies are used for sign-in, security, language selection, and Service operation.
8.2. Optional analytics does not run before the User consents. Declining does not block the core Service.
8.3. The User can change their choice in the "Cookie settings" panel in the site footer. Withdrawing consent is as easy as giving it.
8.4. Analytics never receives email, Telegram ID, payment data, tokens, support content, file names, or trade data. Form fields and the Simulator are excluded from session recording.
8.5. Cloudflare Web Analytics (CDN infrastructure analytics) may be used by the site operator separately from GA4/Metrica; it is listed in this cookie inventory.
9. Security
The Operator applies access control, encryption in transit, secret hashing, event auditing, backups, and component updates. Absolute security is not guaranteed.
Suspected incidents can be reported to [email protected]. Users and regulators are notified in the cases and within the timeframes established by applicable law.
10. User rights
Depending on applicable law, the User may: obtain information and a copy of their data; correct inaccurate data; request deletion or restriction of processing; object to processing; receive data in a portable format; withdraw consent for the future; file a complaint with a competent supervisory authority; opt out of marketing messages.
Requests are sent to [email protected]. The Operator may verify identity to protect the account. The Operator aims to respond within 30 calendar days of receipt, unless a shorter period is set by applicable law.
Deleting an account does not always mean immediate deletion of payment records, contract evidence, or security logs where their retention is mandatory or necessary for legal claims.
11. Children
The Service is intended for people aged 18 and over. The Operator does not knowingly collect children's data. If such an account is discovered, please contact [email protected].
12. Changes to this Policy
12.1. A new revision gets a separate version, publication date, and effective date. Archived revisions are kept at permanent links such as /legal/archive/privacy/{version}.
12.2. The Operator notifies material changes in the Service and, where a channel is available, by email or Telegram before they take effect.
12.3. If a change requires new consent under applicable law, the Service requests a separate explicit action. Continuing to use routine sign-in is not treated as automatic consent to new optional purposes.
13. Contacts
- Operator: Olga Igorevna Ilina, self-employed, NPD taxpayer;
- Tax ID (INN): 501803615021;
- privacy email: [email protected];
- a separate Data Protection Officer (DPO) has not been appointed: applicable law does not require one for individual operators in self-employed status; data-processing inquiries are handled directly by the Operator;
- competent supervisory authority in the Russian Federation: the Federal Service for Supervision of Communications, Information Technology, and Mass Media (Roskomnadzor).