Privacy Policy and Personal Data Processing at TrendOrFlat

1. Who processes the data

The personal-data controller is Olga Igorevna Ilina, a self-employed individual under the Russian "Professional Income Tax" (NPD) regime, Tax ID (INN) 501803615021, data-related email [email protected] (the "Operator").

This Policy applies to the website https://trendorflat.com, the account, subscription, support, Telegram integration, and related TrendOrFlat features.

2. What data may be processed

Depending on how the Service is used:

The Service is not intended to process special categories of personal data, biometrics, health data, or data about minors. Please do not send such information through support.

Trade files uploaded to the public Simulator are processed locally in the User's browser and are never sent to TrendOrFlat servers.

3. Purposes and legal bases

Consent is not used as a universal basis for processing that is necessary to perform the contract.

4. Sources of data

Data comes directly from the User; from OAuth and Telegram sign-in providers; from the payment provider; automatically from the browser, app, and infrastructure; and from support requests and bug reports.

5. Recipients and processors

The Operator engages the following actually connected providers:

No other providers, including any payment systems not listed above, are used. This list may be updated as the Service evolves; the current version of this Policy is published at /privacy. Data may also be disclosed to authorized authorities, auditors, and professional advisers where required by law.

6. International transfer and place of storage

Primary regions and infrastructure:

For cross-border transfers the Operator relies on the contract with the User, the need to perform the offer, and safeguards (encryption in transit, access control). Where applicable law requires an extra notice or consent for a specific country, the Operator will request it separately or limit the transfer.

7. Retention periods

The Operator stores personal data no longer than required by the processing purposes, the contract and applicable law (Russian Federal Law No. 152-FZ). After the purpose is achieved or consent is withdrawn, data are deleted or anonymised within the statutory period (generally within 30 days), unless a longer retention is required by another federal law or the contract.

Category-specific periods:

CategoryPeriodBasis
Account and profileWhile the account is active; after account deletion or consent withdrawal — delete/anonymise within 30 days, except categories below152-FZ
Payments, receipts, tax calculation recordsat least 5 years after the end of the period in which the payment was madeTax Code of the RF art. 23(1)(8); Accounting Law No. 402-FZ art. 29
Legal acceptances of the offer and consents (contract evidence)3 years after the end of the relationship; where payments exist — until the related 5-year tax retention endsCivil Code art. 196; Tax Code
Support tickets and attachments3 years after ticket closureCivil Code art. 196
Technical and security logs12 monthssecurity / incident investigation
Sentry errors90 days, then delete or anonymisediagnostics
GA4 / Yandex Metricauntil cookie consent is revoked, and no longer than the relevant vendor identifier settings (typically up to 14 months)consent; vendor settings
Backupsup to 35 days of rotation on top of source-data periodscontinuity

After the period expires, data are deleted or anonymised unless the law requires longer retention.

8. Cookies and analytics

8.1. Strictly necessary cookies are used for sign-in, security, language selection, and Service operation.

8.2. Optional analytics does not run before the User consents. Declining does not block the core Service.

8.3. The User can change their choice in the "Cookie settings" panel in the site footer. Withdrawing consent is as easy as giving it.

8.4. Analytics never receives email, Telegram ID, payment data, tokens, support content, file names, or trade data. Form fields and the Simulator are excluded from session recording.

8.5. Cloudflare Web Analytics (CDN infrastructure analytics) may be used by the site operator separately from GA4/Metrica; it is listed in this cookie inventory.

9. Security

The Operator applies access control, encryption in transit, secret hashing, event auditing, backups, and component updates. Absolute security is not guaranteed.

Suspected incidents can be reported to [email protected]. Users and regulators are notified in the cases and within the timeframes established by applicable law.

10. User rights

Depending on applicable law, the User may: obtain information and a copy of their data; correct inaccurate data; request deletion or restriction of processing; object to processing; receive data in a portable format; withdraw consent for the future; file a complaint with a competent supervisory authority; opt out of marketing messages.

Requests are sent to [email protected]. The Operator may verify identity to protect the account. The Operator aims to respond within 30 calendar days of receipt, unless a shorter period is set by applicable law.

Deleting an account does not always mean immediate deletion of payment records, contract evidence, or security logs where their retention is mandatory or necessary for legal claims.

11. Children

The Service is intended for people aged 18 and over. The Operator does not knowingly collect children's data. If such an account is discovered, please contact [email protected].

12. Changes to this Policy

12.1. A new revision gets a separate version, publication date, and effective date. Archived revisions are kept at permanent links such as /legal/archive/privacy/{version}.

12.2. The Operator notifies material changes in the Service and, where a channel is available, by email or Telegram before they take effect.

12.3. If a change requires new consent under applicable law, the Service requests a separate explicit action. Continuing to use routine sign-in is not treated as automatic consent to new optional purposes.

13. Contacts