Data we collect
- Account data: your email address, the secure (hashed) form of your password, and the organizations you belong to along with your roles.
- Captured request data: the requests that reach your endpoints — headers, body, metadata, and the rules/responses you configure. You decide what this content is; take care not to send sensitive data.
- Usage and technical data: the request counter, tracking of plan limits, and the basic logs required for the service to operate (e.g. IP, browser type, error traces).
How we use data
We process data only to provide the service, manage your account, enforce plan limits, handle billing, ensure security and improve the service. We do not use the request data you capture for advertising purposes, and we do not sell it.
Service providers (processors)
To provide the service we work with a limited number of trusted service providers. Each accesses data only for its own function:
- Whop — payment and subscription management. Your payment details are processed by Whop; we do not store card data.
- mila — delivery of transactional emails (e.g. account and payment notifications).
- Paraşüt — invoice documentation and accounting processes.
- Cloudflare and our hosting providers — infrastructure, content delivery and security (e.g. abuse/DDoS protection).
- Sentry — error and performance monitoring (client and server side). Runs only when configured; collects technical error data and is not used for advertising.
International users and cross-border transfers
SoliTrace serves users worldwide. Some of the service providers above (Whop = payments, Cloudflare = hosting/CDN, Sentry = error monitoring) are located outside Türkiye; therefore some data is processed and stored abroad. We carry out transfers only to provide the service, within the safeguards required by applicable law. Detailed cross-border transfer and KVKK information for users in Türkiye is set out in the KVKK Disclosure Notice.
Rights for European Union (GDPR) users
If you are in the European Economic Area (EEA), you have additional rights under the GDPR. The legal bases we rely on when processing your data are: performance of a contract (your account and subscription), legitimate interest (security and service improvement), legal obligation (invoice records) and, where necessary, your consent.
- Access your data and request a copy (including portability).
- Request rectification of inaccurate/incomplete data.
- Request erasure of your data (right to be forgotten).
- Restrict processing and object to processing.
- Withdraw your consent at any time for consent-based processing.
- Lodge a complaint with the competent data protection authority.
To exercise these rights, simply write to [email protected]. For our use of cookies, see the Cookie Policy.
Retention periods
We retain captured request data according to your plan:
- Free plan: captured data is deleted automatically after 3 days.
- Paid plan: captured data is deleted automatically after 30 days.
We retain your account data for as long as your account is open. When you delete your account, your personal orgs and the captured data attached to them are permanently deleted; from orgs you co-own, only your membership is removed. We may need to keep certain data for the period required by applicable law due to legal obligations (e.g. invoice records).
Your rights
You have the right to access, rectify, erase and export your personal data. You can delete your account yourself via the "Danger zone" in the billing settings. To export your data or for other requests, reach us at [email protected].
Security
We apply reasonable technical and administrative measures to protect data: encryption in transit, access restrictions and regular updates. No system is entirely without risk; for this reason we recommend that you do not send unnecessary sensitive data to your endpoints.
Contact
For privacy-related questions you can use the Contact page or write directly to [email protected].