Privacy Policy and Personal Data Processing at TrendOrFlat
1. Who processes the data
The personal-data controller is Olga Igorevna Ilina, a self-employed individual under the Russian "Professional Income Tax" (NPD) regime, Tax ID (INN) 501803615021, data-related email [email protected], phone +7 910 423 29 21 (the "Operator").
This Policy applies to the website https://trendorflat.com, the account, subscription, support, Telegram integration, and related TrendOrFlat features.
2. What data may be processed
Depending on how the Service is used:
- email, account identifier, and authentication service data;
- Telegram ID, name/username, language, and related authorization identifiers, if Telegram sign-in is used;
- plan, subscription status and period, and selected instruments;
- payment ID, amount, currency, status, and receipt data; full card details are processed by the payment provider YooKassa and are not passed to the Operator;
- notification, integration, and webhook settings, and hashed API tokens;
- support requests, messages, attachments, and diagnostic materials the User sends voluntarily;
- technical data: IP address in infrastructure logs, browser type, device, request time, security events, and errors;
- analytics and cookie data after the User's required choice;
- the version, date, and method of acceptance of legal documents.
The Service is not intended to process special categories of personal data, biometrics, health data, or data about minors. Please do not send such information through support.
Trade files uploaded to the public Simulator are processed locally in the User's browser and are never sent to TrendOrFlat servers.
3. Purposes and legal bases
- Account creation and sign-in (email, Telegram/OAuth ID, auth events) — conclusion and performance of the contract, necessary pre-contractual steps.
- Providing the subscription (plan, status, settings) — performance of the contract.
- Payments and accounting (payment ID, amount, currency, receipt) — performance of the contract and legal obligation.
- Notifications and integrations (Telegram ID, webhook, pairs, settings) — performance of the contract and the User's request.
- Support (contact, messages, attachments) — performance of the contract and legitimate interest; consent for optional attachments.
- Security and abuse prevention (technical logs, auth events) — legitimate interest and legal obligation.
- Product analytics (cookie ID, usage events) — consent, where required by applicable law.
- Marketing (email, ad events) — separate voluntary consent.
- Evidence of document acceptance (user ID, version, hash, time) — performance of the contract, legitimate interest, legal obligation.
Consent is not used as a universal basis for processing that is necessary to perform the contract.
4. Sources of data
Data comes directly from the User; from OAuth and Telegram sign-in providers; from the payment provider; automatically from the browser, app, and infrastructure; and from support requests and bug reports.
5. Recipients and processors
The Operator engages the following actually connected providers:
- Supabase — database, authentication, and storage of core account data;
- Cloudflare — CDN, DNS, attack protection, and infrastructure web analytics;
- YooKassa — card payment processing;
- Telegram — account sign-in and notifications, if the User enables that feature;
- Sentry — technical error diagnostics;
- Google Analytics 4 and Yandex Metrica — product analytics, loaded only after the User's explicit consent in cookie settings and only if the owner has enabled the relevant counter.
No other providers, including any payment systems not listed above, are used. This list may be updated as the Service evolves; the current version of this Policy is published at /privacy. Data may also be disclosed to authorized authorities, auditors, and professional advisers where required by law.
6. International transfer and place of storage
The primary hosting and processing regions, and the applicable cross-border transfer mechanisms, are being confirmed as part of an infrastructure review of the providers used (Supabase, Cloudflare) and will be published in an updated revision of this Policy.
7. Retention periods
The Operator retains data no longer than necessary for the processing purpose, contract performance, dispute resolution, and mandatory reporting. Exact retention periods for each data category (account, payments, support, technical logs, analytics, legal acceptances, backups) are being finalized in an internal policy and will be published in an updated revision of this Policy. After the retention period ends, data is deleted or anonymized, except where the law requires longer retention (for example, payment records).
8. Cookies and analytics
8.1. Strictly necessary cookies are used for sign-in, security, language selection, and Service operation.
8.2. Optional analytics does not run before the User consents. Declining does not block the core Service.
8.3. The User can change their choice in the "Cookie settings" panel in the site footer. Withdrawing consent is as easy as giving it.
8.4. Analytics never receives email, Telegram ID, payment data, tokens, support content, file names, or trade data. Form fields and the Simulator are excluded from session recording.
9. Security
The Operator applies access control, encryption in transit, secret hashing, event auditing, backups, and component updates. Absolute security is not guaranteed.
Suspected incidents can be reported to [email protected]. Users and regulators are notified in the cases and within the timeframes established by applicable law.
10. User rights
Depending on applicable law, the User may: obtain information and a copy of their data; correct inaccurate data; request deletion or restriction of processing; object to processing; receive data in a portable format; withdraw consent for the future; file a complaint with a competent supervisory authority; opt out of marketing messages.
Requests are sent to [email protected]. The Operator may verify identity to protect the account. The Operator aims to respond within 30 calendar days of receipt, unless a shorter period is set by applicable law.
Deleting an account does not always mean immediate deletion of payment records, contract evidence, or security logs where their retention is mandatory or necessary for legal claims.
11. Children
The Service is intended for people aged 18 and over. The Operator does not knowingly collect children's data. If such an account is discovered, please contact [email protected].
12. Changes to this Policy
12.1. A new revision gets a separate version, publication date, and effective date. Archived revisions are kept at permanent links such as /legal/archive/privacy/{version}.
12.2. The Operator notifies material changes in the Service and, where a channel is available, by email or Telegram before they take effect.
12.3. If a change requires new consent under applicable law, the Service requests a separate explicit action. Continuing to use routine sign-in is not treated as automatic consent to new optional purposes.
13. Contacts
- Operator: Olga Igorevna Ilina, self-employed, NPD taxpayer;
- Tax ID (INN): 501803615021;
- privacy email: [email protected];
- phone: +7 910 423 29 21;
- a separate Data Protection Officer (DPO) has not been appointed: applicable law does not require one for individual operators in self-employed status; data-processing inquiries are handled directly by the Operator;
- competent supervisory authority in the Russian Federation: the Federal Service for Supervision of Communications, Information Technology, and Mass Media (Roskomnadzor).