Data controller
Reditus is the controller of the personal data described in this policy.
- Identity used by the service: Reditus.
- Website: https://reditus.app.
- Privacy contact: [email protected].
Data we process
The categories depend on the features you use:
- Account and identity: internal identifier, email address, first and last name, password hash when you use local sign-in, authentication provider, Google identifier, base currency, roles, account status, and creation and last-sign-in dates.
- Portfolio and investments: platforms, assets, tickers, transaction dates and types, quantities, prices, fees, currencies, scheduled transaction rules, imported records, and metrics or snapshots calculated from them.
- Subscription and billing: plan, status and subscription periods, and Stripe customer, subscription, and session identifiers. Reditus does not store full card numbers or complete payment details.
- Communications: name, email, subject, and message submitted through the contact form; also titles, descriptions, replies, and status of feedback submitted from an account.
- Technical and security data: IP address used temporarily for rate limiting, request identifiers, requested method and path, user identifier in authenticated logs, and session data contained in the JWT.
- Browser preferences: language, theme, and a local indication that an authenticated session exists.
Sources of data
We obtain data from the following sources:
- Directly from you when you register, complete your profile, record or import transactions, purchase a plan, or contact support.
- From Google, if you choose that sign-in method, and from Stripe when a subscription starts or changes status.
- From service activity, such as security logs, positions, performance, projections, and other metrics derived from portfolio data.
Purposes and legal bases
We process data only where an applicable legal basis exists:
- Providing the service, authenticating you, maintaining your account, and calculating portfolio views: performance of a contract or pre-contractual steps (GDPR Article 6(1)(b)).
- Managing trials, subscriptions, payments, and the billing portal: performance of a contract (Article 6(1)(b)) and, where applicable, compliance with legal obligations (Article 6(1)(c)).
- Responding to inquiries, recovering passwords, and handling feedback: performance of a contract, pre-contractual steps, or our legitimate interest in supporting users (Articles 6(1)(b) and 6(1)(f)).
- Preventing abuse, enforcing rate limits, protecting sessions, investigating errors, and maintaining backups: our legitimate interest in securing the availability and integrity of the service (Article 6(1)(f)).
- Fixing issues and improving features using technical information and feedback: our legitimate interest in improving Reditus (Article 6(1)(f)), balanced against your rights.
- Meeting legal duties and responding to claims or authority requests: compliance with a legal obligation or our legitimate interest in establishing and defending claims (Articles 6(1)(c) and 6(1)(f)).
International transfers
Google, Stripe, Grafana, or other providers may process data outside the European Economic Area. Their locations and subprocessors may change over time.
Where applicable, we require a valid transfer mechanism, such as an adequacy decision, the EU-US Data Privacy Framework, or Standard Contractual Clauses, together with appropriate supplementary measures. Reditus backups are configured in Cloudflare R2's European jurisdiction.
Retention periods
We retain each category only for as long as needed for its purpose:
- Account and portfolio data remains while the account is active. Account deletion removes associated records from the active database unless a legal duty applies or limited information is needed for legal claims. When you delete your account, Reditus automatically and immediately cancels correlated recurring subscriptions.
- Subscription cancellation does not erase Stripe's billing records. Stripe may retain those records and payment evidence for applicable legal, tax, accounting, or fraud-prevention periods.
- Recovery links expire after 60 minutes by default; tokens are stored as hashes and expired tokens are deleted daily.
- Technical identifiers for processed Stripe events are retained for 45 days to detect resends and prevent duplicate processing.
- Contact messages and feedback are retained as needed to respond, manage the issue, and address potential liabilities.
- Backups are encrypted and subject to automatic lifecycles: daily backups expire after 35 days and monthly backups after 400 days. Deleted data may remain in a backup until that backup expires.
- Technical logs are kept for the operational period needed for security, diagnostics, and incident investigation, with restricted access.
Cookies and local storage
The audited version of Reditus uses only necessary or preference technologies:
- access_token: essential JWT authentication cookie. It is HttpOnly, Secure in production, SameSite=Lax, and limited to the configured session duration.
- authenticated: a technical localStorage hint that helps manage redirects and is removed when you sign out; it does not contain the access token.
- The browser may remember your chosen language and theme to preserve your preferences.
- No advertising cookies or behavioral analytics tools were identified in the audited code. If this changes, we will update this policy and request consent where required.
Your rights
Under the GDPR and applicable law, you may request:
- Access to your data and a copy of the information processed.
- Correction of inaccurate or incomplete data.
- Erasure where the data is no longer needed or another legal ground applies.
- Restriction of processing in the circumstances provided by law.
- Objection to processing based on legitimate interests for reasons related to your particular situation.
- Portability of data you provided where processing is automated and based on contract or consent.
- Withdrawal of consent at any time without affecting the lawfulness of prior processing.
- A complaint to the Spanish Data Protection Agency (aepd.es) or the supervisory authority where you live or work.
You can update some data and delete your account from your profile. For any other request, email the contact listed below. We may request reasonable information to verify your identity.
Security
We apply technical and organizational measures proportionate to risk: BCrypt password hashing, HttpOnly cookies that are secure in production, role-based access control, per-user data isolation, IP rate limiting, webhook signature verification, HTTPS connections, encrypted backups, and production access controls. No system can guarantee absolute security.
Children
Reditus is not directed to anyone under 18 and does not knowingly seek to collect their data. If you believe a child has provided information, contact us to request its review and deletion.
Automated decision-making
Reditus calculates metrics, rankings, and projections from portfolio data, but it does not make solely automated decisions that produce legal or similarly significant effects on you. These features are informational and do not constitute financial advice.
Changes to this policy
We may update this policy to reflect legal, technical, or service changes. We will publish the current version on this page and change the update date; if a change is significant, we will provide a reasonable additional notice.
Contact
To exercise your rights or ask any privacy question, email:
[email protected]