Privacy Policy
Track21 Touring Limited (“Track21”, “we”, “us”, “our”) is committed to protecting your privacy. This policy explains how we collect, use and store your personal data when you use the Track21 International Travel Calculator (ITC) app and website.
Track21 Touring Limited is the data controller for the purposes of UK GDPR and the Data Protection Act 2018.
1. What Information We Collect
We may collect and process:
Account Information
-
Name
-
Email address
-
Subscription status
Claim & Travel Data
-
Travel dates
-
Countries and cities
-
HMRC-matched data
-
Duration types
-
Calculated subsistence values
-
Manually entered location data (including latitude and longitude where required)
Google API Services
Track21 ITC only accesses calendar data when the user explicitly chooses to connect their Google account. Track21 ITC may request permission to access a user’s Google Calendar through Google’s OAuth authentication system. This access is used solely to allow users to import travel events from their Google Calendar into the Track21 ITC application for the purpose of calculating international travel subsistence claims in accordance with HMRC overseas scale rate guidance.
The application only requests read-only access to calendar events and does not create, modify, or delete any calendar data within a user’s Google account.
Imported calendar event information may include event titles, dates, and locations. This information is used only to populate the user’s claim records within the application.
Track21 Touring Limited does not share Google user data with third parties and does not use this information for advertising or marketing purposes.
​
Users may revoke access to their Google account at any time through their Google account permissions settings.
​
We do not access or store unrelated Google data.
​
Track21 Touring Limited’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
​
Authentication tokens provided by Google during the sign-in process may be stored securely in the application’s database to allow the service to access calendar data on behalf of the user. These tokens are encrypted and used solely for the purpose of retrieving calendar event data requested by the user.
Payment Information
Payments are processed securely by Wix Payments and/or Stripe.
We do not store card details.
Usage & Technical Data
-
Basic usage logs
-
Wix Analytics data
-
Device and session information
2. Lawful Basis for Processing
We process personal data under the following lawful bases:
-
Contract – to provide subscription services.
-
Legitimate Interest – to maintain security and improve performance.
-
Consent – for marketing communications.
3. How We Use Your Information
We use your data to:
-
Provide the ITC calculation tool
-
Import and organise travel claims
-
Match locations to HMRC rates
-
Manage subscriptions
-
Provide customer support
-
Improve service functionality
We do not sell personal data.
4. Data Sharing
We may share data with trusted service providers including:
-
Wix (hosting and infrastructure)
-
Supabase (database hosting)
-
Stripe and Wix Payments (payment processing)
-
Google (OAuth authentication)
These providers act as data processors and process data under contractual safeguards.
5. Data Retention
-
Data is retained while your subscription is active.
-
If you cancel, your data will be retained for up to 90 days, after which it is permanently deleted.
-
Server logs are retained for up to 60 days.
-
Users are responsible for exporting and retaining their own tax records.
6. Location Data
Where users enter non-listed locations, latitude and longitude may be processed solely for subsistence rate matching.
Track21 does not use location data for tracking or profiling.
7. Marketing Communications
If you opt in, we may send service updates and promotional communications.
You may unsubscribe at any time using the link in our emails.
8. Your Rights
Under UK GDPR, you have the right to:
-
Access your data
-
Correct inaccurate data
-
Request deletion
-
Restrict or object to processing
-
Data portability
-
Lodge a complaint with the Information Commissioner’s Office (ICO)
Requests can be sent to:
9. Security
We implement appropriate technical and organisational measures to protect your data.
OAuth tokens are stored securely and may be revoked by the user at any time.
10. Changes to This Policy
We may update this policy periodically. Continued use of the service indicates acceptance of any updates.
​
Track21 provides a calculation and organisational tool only. Users remain fully responsible for verifying and submitting their own claims in accordance with UK tax law.