Legal

Privacy Policy

What personal data we process, why, for how long, and what you can require of us. Written to be read, not to be skipped.

Version 1.0 · in force from 10 August 2026

The short version

Your hand histories, your statistics, your opponents' names and your database never leave your computer. The software has no way to send them anywhere, and we have no copy of them.

What we hold is what is needed to sell you a licence and keep it working: your e-mail address, your subscription status, a licence key, and a hardware fingerprint so that the seat count is honest. Payment card data is handled by Stripe and never reaches us. We run no advertising, no analytics and no cookies on this website.

Contents
  1. Who is the controller
  2. What the software does not send
  3. What we process, and why
  4. Legal bases
  5. How long we keep it
  6. Who else sees it
  7. Transfers outside the EEA
  8. This website and cookies
  9. Your rights
  10. Security
  11. Children
  12. Changes

1Who is the controller

The controller of your personal data, within the meaning of Regulation (EU) 2016/679 (GDPR), is:

Controller
Bartosz Kowalski
Address
Osiedle Widok 27/A4, 66-200 Świebodzin, Poland
Tax ID (NIP)
9271963198
E-mail
bartoszownkowalski@gmail.com

We are not required to appoint a data protection officer and have not appointed one. Write to the address above for any matter concerning your data; it reaches the controller directly.

2What the software does not send

This deserves its own section, because it is the question players ask first.

The application makes exactly one kind of outbound connection: the licence check described below.

3What we process, and why

DataWhere it comes fromWhy
E-mail addressYou, at checkout or when you contact usTo deliver your licence key, send invoices and renewal notices, and answer support requests.
Name and billing address, tax ID if you give oneYou, at checkoutTo issue an invoice and to determine the VAT rate. Required by tax law.
Subscription record — plan, billing period, start and end dates, payment statusCreated by us; payment status from StripeTo perform the contract and to know whether your licence is active.
Licence key and activation recordsCreated by usTo enable the software and to enforce the number of seats included in your plan.
Hardware fingerprint — a one-way hash derived from your computer's hardware identifiersGenerated on your computer by the softwareTo count seats and to detect a shared or resold key. It is not reversible into a serial number and identifies a machine, not a person.
IP address and timestamp of a licence checkAutomatically, when the software verifies the licenceTo operate the service and to detect abuse of a licence. Kept short-term.
Correspondence you send usYouTo answer you and to keep a record of complaints and their handling.
Payment card dataNot processed by us at allEntered by you directly into Stripe's checkout. We receive only the result of the payment, the card brand and the last four digits.

We do not profile you, and no decision that produces legal effects for you is taken by automated means. We do not use your data for advertising and we do not sell or rent it to anyone, ever.

4Legal bases

5How long we keep it

Account and subscription dataFor as long as your subscription is active, then 12 months, in case you come back or a dispute arises.
Invoices and accounting records5 years counted from the end of the calendar year in which the tax became due — a period we are required to observe by Polish tax law.
Licence activations and hardware fingerprintsFor the life of the subscription, then 12 months.
Licence-check connection logs (IP, timestamp)30 days, then deleted automatically.
Support correspondence24 months from the last message, or longer if it concerns a complaint or a claim, until that is finally resolved.
Newsletter subscriptionUntil you unsubscribe.

6Who else sees it

We keep the list of recipients as short as we can. Each of them processes data on our instructions under a written data-processing agreement, or as an independent controller where the law makes them one.

RecipientRoleWhat they receive
Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA)Payment processing; independent controller for payment dataYour name, e-mail, billing country, card data you enter directly, transaction records.
Our hosting providerProcessor — website and licence endpointTechnical connection data; the licence records stored on the server.
Our e-mail providerProcessor — transactional and support e-mailYour e-mail address and the content of messages exchanged.
Our accountantProcessor — bookkeepingInvoice data required by tax law.
Public authoritiesWhere the law requires itOnly what a lawful, specific request obliges us to hand over.

No poker operator receives any personal data from us, and no poker operator has access to your database. If an operator asks us about the software, we answer about the software, not about our customers.

7Transfers outside the EEA

Our own infrastructure is inside the European Economic Area. One recipient, Stripe, may process data in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the recipient is certified, on the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards that apply.

8This website and cookies

evextracker.com is a set of static pages. It sets no cookies, runs no advertising network, and carries no third-party analytics, tag manager, pixel or social plug-in. Nothing on it profiles you.

One exception, and it is visible to you:

Our server keeps standard web-server logs — IP address, time, page requested, user agent — for 30 days, for security and to diagnose faults. The legal basis is our legitimate interest in keeping the site running and safe.

9Your rights

Under the GDPR you may ask us to:

Write to bartoszownkowalski@gmail.com. We answer within one month, and tell you if we need longer and why. There is no charge unless a request is manifestly unfounded or excessive.

You also have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office — Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl. You may also complain to the authority in your own country of residence.

10Security

Licence data is stored on a server inside the EEA, protected by access control and encrypted in transit. Licence keys and tokens are stored in a form that is not readable as plain text. Access is limited to the controller. We do not store card data, which removes the largest category of risk from our side entirely.

If a breach were to occur that is likely to result in a high risk to your rights, we will notify you without undue delay and report it to the supervisory authority within 72 hours, as Articles 33 and 34 require.

11Children

The software is not intended for anyone under 18, and we do not knowingly process the data of minors. Online poker itself is restricted to adults in every jurisdiction we sell into.

12Changes

If we change this policy we publish the new version here with a new date, and, where the change matters to you, we e-mail subscribers before it takes effect. Earlier versions are available on request.

Related documents

Terms of Service — the contract and the licence.
Refund and Withdrawal Policy — the 14-day guarantee and the model withdrawal form.