Legal

Privacy Policy

Trekport runs locally on your machine. Your database credentials, source schemas, PL/SQL, and any extracted data never leave your environment. This policy explains what we do collect, the limited circumstances under which we collect it, and the rights you have over that information.

Last updated · May 20, 2026

1. Data controller

For the purposes of the EU General Data Protection Regulation (GDPR) and other applicable data protection laws, the data controller is:

Trekport
Email: privacy@trekport.sh

2. Information we collect

2.1 Website contact information

When you submit a form on trekport.sh (contact, waitlist, sales inquiry, or trial request), we collect:

  • Name and email address.
  • Company name and role, where you choose to provide them.
  • Free-form message content.
  • The form route and timestamp of submission.

2.2 License validation

When you activate a Trekport license, the desktop application and CLI send the following to our license server:

  • License key.
  • Machine identifier (a non-reversible hash of hardware characteristics, used to enforce seat counts).
  • Trekport product version.

We do not transmit your database credentials, source schemas, PL/SQL code, conversion output, or any extracted data as part of license validation.

2.3 Opt-in crash reports

If you opt in during installation or in the Settings panel, the desktop application may send crash reports containing:

  • Stack trace and error type.
  • Trekport version, operating system, and machine architecture.
  • Anonymized session identifier.

Crash reports are sanitized in-process before transmission. SQL statements, identifiers, file paths, and any customer-supplied strings are stripped or replaced with type-only placeholders before the report leaves your machine.

2.4 Payment information

If you purchase a Trekport license, payment details are collected and processed by Stripe, our payment processor. We do not store your full credit-card number or bank account on our servers. Stripe provides us with a tokenized reference and transaction metadata (amount, currency, date, status, billing country for tax calculation).

2.5 Technical and usage data (website only)

We automatically collect limited technical information when you visit trekport.sh, including:

  • Browser type, operating system, and device class.
  • IP address and approximate geographic location (country or region).
  • Pages visited, referral URLs, and aggregate usage patterns.
  • Error reports and performance metrics for the website.

This data is collected from the website only. The desktop application and CLI do not send any usage telemetry beyond the license validation and opt-in crash reports described above.

3. How we use your information

We use the information we collect for the following purposes:

  • Providing, operating, and maintaining the Services.
  • Issuing and validating licenses and managing your account.
  • Processing payments and managing subscriptions and renewals.
  • Sending transactional emails such as receipts, license keys, download links, and security notices.
  • Responding to inquiries, support requests, and sales conversations.
  • Improving the desktop application, CLI, and website by analyzing aggregated crash reports and website usage.
  • Detecting and preventing fraud, license abuse, and security incidents.
  • Complying with applicable legal obligations.

4. Legal bases for processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR:

  • Contract performance. Processing your account, license, and payment data is necessary to provide the Services you signed up for.
  • Legitimate interests. We process limited technical and website usage data to improve the Services, ensure security, and prevent license abuse, where those interests are not overridden by your rights.
  • Consent. We rely on your explicit consent for opt-in crash reports, analytics cookies, and any marketing communications. You may withdraw consent at any time.
  • Legal obligation. We retain certain payment and tax records to comply with financial reporting requirements.

5. Third-party service providers

We share information with the following third-party processors, each of which processes data only as necessary to perform services on our behalf:

  • Vercel — website hosting and edge delivery. Processes IP addresses, request metadata, and server-side rendering payloads for trekport.sh.
  • Stripe — payment processing. Processes payment card details, billing address, sales tax and VAT, and transaction records. Stripe acts as a separate data controller for fraud-prevention purposes.
  • Resend — transactional email delivery. Processes your email address and the body of receipt, license, and security notification emails.
  • Cloudflare — Turnstile bot protection and DDoS mitigation on website forms. Processes IP addresses and browser fingerprints to score form submissions.
  • PostHog — privacy-respecting product analytics for the website only, with your consent. Processes anonymized page-view events. Session replay and autocapture are disabled.
  • Sentry — error monitoring for the website and, opt-in, for the desktop application. Processes error reports, stack traces, and browser or runtime metadata.

We do not sell your personal information to any third party. We may disclose information if required by law or in response to valid legal process from a court of competent jurisdiction.

6. Your rights under the GDPR

If you are located in the EEA, United Kingdom, or Switzerland, you have the following rights regarding your personal data:

  • Right of access. You may request a copy of the personal data we hold about you.
  • Right to rectification. You may request that we correct inaccurate or incomplete personal data.
  • Right to erasure. You may request that we delete your personal data, subject to legal exceptions such as tax-record retention.
  • Right to data portability. You may request a machine-readable export of the personal data you provided to us.
  • Right to restriction. You may request that we restrict the processing of your personal data while a dispute is being resolved.
  • Right to object. You may object to the processing of your personal data based on our legitimate interests, including direct marketing.
  • Right to withdraw consent. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

How to exercise your rights

To exercise any of these rights, email privacy@trekport.sh. We will verify your identity using the email address on file and respond within 30 days. There is no charge for reasonable requests.

If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

7. Your rights under the CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you additional rights:

  • Right to know. You may request details about the categories and specific pieces of personal information we have collected about you.
  • Right to delete. You may request deletion of your personal information, subject to legal exceptions.
  • Right to correct. You may request correction of inaccurate personal information.
  • Right to opt out of sale or sharing. We do not sell or share your personal information for cross-context behavioral advertising.
  • Right to non-discrimination. We will not discriminate against you for exercising your CCPA rights.

Do Not Sell My Personal Information

Trekport does not sell your personal information and has not sold personal information in the preceding 12 months. We do not use your data for cross-context behavioral advertising. No opt-out action is required, but if you have questions please contact privacy@trekport.sh.

8. Data retention

We retain your information according to the following schedule:

  • Account and license data. Retained for as long as your license is active and for a 12-month grace period after expiry. After that, account data is permanently removed.
  • Payment and transaction records. Retained for seven years after the transaction date, as required by applicable tax and financial reporting laws.
  • Website analytics. Anonymized after 24 months. Once anonymized, the data can no longer be linked to you and is used only in aggregate.
  • Operational and error logs. Automatically purged after 90 days.
  • Crash reports. Retained for 180 days, then aggregated into anonymized release-quality metrics and the individual reports are deleted.

9. International data transfers

Personal information collected through the website is primarily processed in the United States and the European Union (Vercel edge regions). If you are located outside these regions, your data may be transferred to and processed in either. We protect your data during transfer by:

  • Using service providers that participate in recognized data transfer frameworks such as the EU-US Data Privacy Framework.
  • Entering into Standard Contractual Clauses (SCCs) approved by the European Commission where required.
  • Implementing supplementary safeguards including encryption in transit (TLS 1.2+) and at rest.

10. Cookie policy

We use cookies and similar technologies on the website only. The desktop application and CLI do not use cookies.

Necessary cookies

Required for the website to function. Includes CSRF tokens, cookie-consent preferences, and the dark-mode toggle. These cannot be disabled.

Analytics cookies

Set by PostHog only with your explicit consent. They help us understand which pages and documentation sections are most useful. You can opt in or out at any time through the cookie banner.

Marketing cookies

We do not use marketing or advertising cookies. If we introduce them in the future, they will require your explicit consent before being set.

11. Security

We take reasonable administrative, technical, and organizational measures to protect your information, including:

  • TLS 1.2 or newer for all data in transit, including license validation.
  • Encryption at rest for database fields containing personal data.
  • Regular security reviews, dependency audits, and SAST scans.
  • Principle-of-least-privilege access controls for personnel.
  • DDoS protection and bot mitigation via Cloudflare on website forms.
  • In-process sanitization of crash reports so sensitive customer SQL and identifiers never reach our servers.

See our Security Policy for the complete program. No method of internet transmission or electronic storage is completely secure; we are committed to protecting your data to the best of our ability and to notifying affected customers without undue delay if a breach occurs.

12. Children’s privacy

The Services are not directed at children under the age of 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe that a child under the applicable age has provided us with personal information, please contact privacy@trekport.sh and we will take steps to delete such information promptly.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Any changes will be reflected by updating the “Last updated” date at the top of this page. If we make material changes, we will notify you by email or by posting a prominent notice on the website prior to the change becoming effective. Your continued use of the Services after the updated policy is posted constitutes acceptance of the changes.

14. Contact information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us:

Trekport
Email: privacy@trekport.sh

For data protection inquiries from the EEA, you may contact our data protection point of contact at the same email address. We aim to respond to all legitimate requests within 30 days.