This page is maintained by CardTrack, LLC to answer common security and privacy questions about CardTrack. It reflects our current practices and enabled platform controls.
Trust & Security
CardTrack is designed to keep your credit card tracking data safe and private. Below is a summary of the security measures and practices we follow today.
Authentication
- Password-based accounts require a strong password (minimum score enforced at signup).
- Google OAuth is available as an alternative sign-in method.
- Sessions are managed securely and refreshed automatically.
- Password reset emails are sent via our platform email provider.
Data storage
- Card details, balances, and statement metadata are stored in a managed database with row-level security (RLS) enabled.
- Each user can only access their own card data and statements.
- Uploaded statement PDFs are stored in a private storage bucket with owner-restricted access.
- CardTrack does not ask for bank credentials or connect to financial institutions.
Data collection & use
We collect only what is necessary to run the service: your email address, card details you enter (nickname, last four digits, limit, due day, etc.), balance history, and any statement PDFs you upload. We do not sell personal data. See our Privacy Policy for details.
Retention & deletion
When you delete your account, your card data, balances, and statements are removed immediately. We do not retain personal data after account closure.
Shared responsibility
CardTrack runs on a managed cloud platform that provides infrastructure security, encrypted storage, and automated patches. We are responsible for application-level security, access controls, and data handling practices. You are responsible for keeping your login credentials secure and using a strong password.
Security contact
If you discover a security issue or have a vulnerability to report, please email us at support@getcardtrack.com. We review all reports and respond as quickly as possible.