Privacy Policy
What personal data we process, why, for how long, and what you can require of us. Written to be read, not to be skipped.
Version 1.0 · in force from 10 August 2026
The short version
Your hand histories, your statistics, your opponents' names and your database never leave your computer. The software has no way to send them anywhere, and we have no copy of them.
What we hold is what is needed to sell you a licence and keep it working: your e-mail address, your subscription status, a licence key, and a hardware fingerprint so that the seat count is honest. Payment card data is handled by Stripe and never reaches us. We run no advertising, no analytics and no cookies on this website.
1Who is the controller
The controller of your personal data, within the meaning of Regulation (EU) 2016/679 (GDPR), is:
- Controller
- Bartosz Kowalski
- Address
- Osiedle Widok 27/A4, 66-200 Świebodzin, Poland
- Tax ID (NIP)
- 9271963198
- bartoszownkowalski@gmail.com
We are not required to appoint a data protection officer and have not appointed one. Write to the address above for any matter concerning your data; it reaches the controller directly.
2What the software does not send
This deserves its own section, because it is the question players ask first.
- Hand histories are never transmitted. The application reads the files your poker client wrote to your own disk, opens them read-only, and stores what it parses in a local database file on the same computer.
- Statistics are never transmitted. Everything you see on screen is computed on your machine from that local database.
- Opponent names are never transmitted. There is no shared pool, no central database, no synchronisation between users and no way to publish, sell or exchange a database from inside the application.
- Your notes and colour marks are never transmitted. They live in the same local file.
- We hold no backup of your database. If your disk fails, we cannot restore your hands, because we never had them. Keep your own backup of the original hand-history files.
The application makes exactly one kind of outbound connection: the licence check described below.
3What we process, and why
| Data | Where it comes from | Why |
|---|---|---|
| E-mail address | You, at checkout or when you contact us | To deliver your licence key, send invoices and renewal notices, and answer support requests. |
| Name and billing address, tax ID if you give one | You, at checkout | To issue an invoice and to determine the VAT rate. Required by tax law. |
| Subscription record — plan, billing period, start and end dates, payment status | Created by us; payment status from Stripe | To perform the contract and to know whether your licence is active. |
| Licence key and activation records | Created by us | To enable the software and to enforce the number of seats included in your plan. |
| Hardware fingerprint — a one-way hash derived from your computer's hardware identifiers | Generated on your computer by the software | To count seats and to detect a shared or resold key. It is not reversible into a serial number and identifies a machine, not a person. |
| IP address and timestamp of a licence check | Automatically, when the software verifies the licence | To operate the service and to detect abuse of a licence. Kept short-term. |
| Correspondence you send us | You | To answer you and to keep a record of complaints and their handling. |
| Payment card data | Not processed by us at all | Entered by you directly into Stripe's checkout. We receive only the result of the payment, the card brand and the last four digits. |
We do not profile you, and no decision that produces legal effects for you is taken by automated means. We do not use your data for advertising and we do not sell or rent it to anyone, ever.
4Legal bases
- Performance of a contract — Article 6(1)(b) GDPR: delivering the licence, running the licence check, support, renewal notices.
- Legal obligation — Article 6(1)(c): issuing and keeping invoices and accounting records, VAT reporting, handling complaints.
- Legitimate interests — Article 6(1)(f): protecting the licence against sharing and resale, security of the service, establishing or defending legal claims. We have weighed these against your rights and use the least intrusive means we could find — a hashed fingerprint rather than a hardware serial, and short retention of connection logs.
- Consent — Article 6(1)(a): only if you subscribe to an optional product-news e-mail. You can withdraw it at any time with one click, and withdrawing it never affects your licence.
5How long we keep it
| Account and subscription data | For as long as your subscription is active, then 12 months, in case you come back or a dispute arises. |
| Invoices and accounting records | 5 years counted from the end of the calendar year in which the tax became due — a period we are required to observe by Polish tax law. |
| Licence activations and hardware fingerprints | For the life of the subscription, then 12 months. |
| Licence-check connection logs (IP, timestamp) | 30 days, then deleted automatically. |
| Support correspondence | 24 months from the last message, or longer if it concerns a complaint or a claim, until that is finally resolved. |
| Newsletter subscription | Until you unsubscribe. |
6Who else sees it
We keep the list of recipients as short as we can. Each of them processes data on our instructions under a written data-processing agreement, or as an independent controller where the law makes them one.
| Recipient | Role | What they receive |
|---|---|---|
| Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA) | Payment processing; independent controller for payment data | Your name, e-mail, billing country, card data you enter directly, transaction records. |
| Our hosting provider | Processor — website and licence endpoint | Technical connection data; the licence records stored on the server. |
| Our e-mail provider | Processor — transactional and support e-mail | Your e-mail address and the content of messages exchanged. |
| Our accountant | Processor — bookkeeping | Invoice data required by tax law. |
| Public authorities | Where the law requires it | Only what a lawful, specific request obliges us to hand over. |
No poker operator receives any personal data from us, and no poker operator has access to your database. If an operator asks us about the software, we answer about the software, not about our customers.
7Transfers outside the EEA
Our own infrastructure is inside the European Economic Area. One recipient, Stripe, may process data in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the recipient is certified, on the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards that apply.
8This website and cookies
evextracker.com is a set of static pages. It sets no cookies, runs no advertising network, and carries no third-party analytics, tag manager, pixel or social plug-in. Nothing on it profiles you.
One exception, and it is visible to you:
- The checkout hands you over to Stripe's own hosted page. From that point Stripe's privacy policy and its strictly necessary cookies apply. We receive the result, not your card.
Our server keeps standard web-server logs — IP address, time, page requested, user agent — for 30 days, for security and to diagnose faults. The legal basis is our legitimate interest in keeping the site running and safe.
9Your rights
Under the GDPR you may ask us to:
- Give you access to your data and a copy of it (Article 15).
- Correct anything inaccurate or incomplete (Article 16).
- Erase your data (Article 17) — we will, except where we must keep invoices for the tax period in section 5.
- Restrict processing while a dispute about accuracy or lawfulness is resolved (Article 18).
- Receive your data in a portable format and have it sent to another controller (Article 20).
- Object to processing based on legitimate interests, on grounds relating to your situation (Article 21).
- Withdraw consent at any time, where processing is based on consent (Article 7(3)).
Write to bartoszownkowalski@gmail.com. We answer within one month, and tell you if we need longer and why. There is no charge unless a request is manifestly unfounded or excessive.
You also have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office — Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl. You may also complain to the authority in your own country of residence.
10Security
Licence data is stored on a server inside the EEA, protected by access control and encrypted in transit. Licence keys and tokens are stored in a form that is not readable as plain text. Access is limited to the controller. We do not store card data, which removes the largest category of risk from our side entirely.
If a breach were to occur that is likely to result in a high risk to your rights, we will notify you without undue delay and report it to the supervisory authority within 72 hours, as Articles 33 and 34 require.
11Children
The software is not intended for anyone under 18, and we do not knowingly process the data of minors. Online poker itself is restricted to adults in every jurisdiction we sell into.
12Changes
If we change this policy we publish the new version here with a new date, and, where the change matters to you, we e-mail subscribers before it takes effect. Earlier versions are available on request.
Related documents
Terms of Service — the contract and the licence.
Refund and Withdrawal Policy — the 14-day guarantee and the model withdrawal form.