Privacy Policy
Effective Date: August 25, 2026
This Privacy Policy explains how Tracendra handles personal information in connection with its public website, Tracendra-operated customer and administrator services, commercial licensing, support interactions, and the locally deployed Tracendra product. Tracendra is currently jointly owned and operated by Craig Gebo and Eric Gebo as individuals, without a separate incorporated entity. In this Policy, Tracendra, we, us, or our refers to Craig Gebo and Eric Gebo operating under the Tracendra name.
Contents
- 1. Scope and the Three Data Environments
- 2. Public Marketing Website
- 3. Tracendra-Operated Commercial Services
- 4. Locally Deployed Product and Forensic Data
- 5. Accounts and Authentication
- 6. Licensing and Installation Activation
- 7. Stripe Checkout and Subscription Data
- 8. Cookies and Similar Technologies
- 9. Contact, Support, and Email
- 10. Technical, Security, and Administrative Data
- 11. How We Use Information
- 12. AI Model Training
- 13. Selling or Sharing Personal Information
- 14. Model Providers and Customer-Configured Integrations
- 15. Service Providers
- 16. Data Retention
- 17. Security
- 18. Security Incidents
- 19. International Data Transfers
- 20. Privacy Rights
- 21. U.S. State Privacy
- 22. European and UK Users
- 23. Children’s Privacy
- 24. Legal Requests
- 25. Business Transfers
- 26. Changes to This Policy
- 27. Contact
1. Scope and the Three Data Environments
Tracendra develops software and services for AI-agent security monitoring, forensic analysis, detection, investigation, configurable response, and supported containment. How information is handled depends on which part of Tracendra is involved:
- The public marketing website is a primarily static website used to describe Tracendra and present contact information and preview account interfaces.
- Tracendra-operated commercial services provide customer and administrator accounts, browser sessions, Stripe checkout and subscription synchronization, license issuance and validation, installation activation, and commercial administration.
- The locally deployed Tracendra product processes and stores AI-agent and forensic information in the customer’s own deployment. That local forensic information is not automatically uploaded to Tracendra’s commercial service.
This Policy applies where Tracendra receives or controls personal information. It does not govern independent third parties, customer-selected model providers, or information processed solely inside a customer’s deployment where Tracendra does not receive it.
2. Public Marketing Website
The currently deployed public website has:
- no analytics or advertising tracker;
- no advertising cookies, product telemetry, or crash-reporting integration;
- strictly necessary browser storage for the active Supabase authentication session and the non-authoritative plan/interval selection described in Section 8;
- production account, authentication-email, Stripe-hosted checkout and portal, entitlement synchronization, and licensing integration as described below;
- a direct email contact path to
website@tracendra.net; the website does not collect or submit contact-form fields, and its dormant same-origin PHP endpoint is disabled; and - no externally loaded Google Fonts or other third-party typography request. The site uses fonts available on the visitor’s own device.
A production hosting provider may receive ordinary request information such as IP address, user agent, requested URL, date and time, referring page, and error or security-log information. The public website is hosted through Namecheap. Hosting logs and their availability are governed by the selected Namecheap service and account configuration; Tracendra has not adopted a separate fixed retention period for those provider logs.
These website findings do not describe the separate commercial portal or the locally deployed product.
The public website is connected to a separate production Supabase project, and /account/, signup, signin, and password-recovery routes are deployed. Its production Auth Site URL is https://tracendra.net, and its approved redirect allowlist contains exactly https://tracendra.net/account and https://tracendra.net/account?recovery=1. Supabase provides email/password authentication, account records, organization membership, and commercial metadata. Production custom SMTP submits verification and password-recovery messages through Twilio SendGrid. Server-side Supabase Edge Functions create Stripe-hosted Checkout and Billing Portal sessions, verify signed Stripe webhooks, and synchronize entitlements with Tracendra’s separate licensing authority. Secret credentials are held in server-side configuration and are not included in the browser bundle.
3. Tracendra-Operated Commercial Services
The audited commercial service is implemented separately from the public website and uses its own commercial SQLite database. Depending on the customer’s activity, it receives and stores:
- internal customer and account identifiers;
- customer and administrator login identifiers, which may be email addresses but are not required by the implementation to be email addresses;
- password hashes, account status, account creation time, last-login time, and whether a temporary password must be reset;
- browser-session records and CSRF security tokens;
- internal checkout identifiers, Stripe Checkout Session identifiers, Stripe customer and subscription identifiers, configured Stripe price identifiers, subscription/payment state, cancellation-at-period-end status, and current subscription-period end;
- license identifiers, HMAC license-secret verifiers, status, edition, capabilities, lifecycle timestamps, and links to the relevant customer, checkout, and subscription;
- installation activation identifiers, product identifier, status, and activation, last-seen, and deactivation times;
- Stripe webhook event identifiers, event types, processing timestamps, and processing outcomes; and
- commercial administrative and audit activity, including safe internal identifiers, actor, event type, outcome, timestamp, and limited non-secret detail.
The commercial database is separate from the product’s forensic database. The commercial implementation does not store full payment-card details, Stripe API secret keys, Stripe webhook signing secrets, complete Stripe webhook bodies, raw browser session tokens, or raw license secrets.
The active production account/billing schema stores an account UUID and email address; optional display name; organization and membership role; Stripe customer, subscription, price and event identifiers; plan, billing interval, subscription status, cancellation and period dates; versioned entitlement assignments and overrides; commercial-license synchronization identifiers/status; and limited billing audit records. Supabase does not receive local product prompts, tool calls, model outputs, incidents, or forensic evidence through this design. Privileged billing writes are restricted to server-side functions and the database service role.
The local/test implementation now includes a server-to-server commercial synchronization interface. After a signature-verified Stripe event, the Supabase server function may send the commercial service an opaque organization identifier, Stripe customer and subscription identifiers, the server-mapped Standard, Pro, or Team plan, subscription/cancellation/period state, catalog version, and idempotency identifier. The commercial service stores a safe account link, canonical entitlement state, safe customer/license identifiers, request fingerprint, outcome, and audit record. Capabilities and limits are mapped inside the commercial license authority; the browser cannot submit them, and Enterprise cannot be self-assigned. The shared service authentication key and request signature are not stored in Supabase tables or browser code.
For first activation, an authenticated organization owner or billing administrator may ask the server to synchronize the already-verified subscription. If a new license is required, its raw key is returned once to that authenticated browser response for the customer to copy into the locally deployed product. The raw key is not written to Supabase or the commercial synchronization ledger; the commercial database retains only its HMAC verifier. A repeated request returns safe state and cannot retrieve the prior raw key.
4. Locally Deployed Product and Forensic Data
The Tracendra product may process and store AI-agent activity in the customer’s own deployment, including agent and session metadata, goals, prompts or event payloads, model responses and output scans, tool calls, alerts, baselines and risk metrics, incidents and findings, containment activity, audit records, runtime information, notification state, and forensic evidence. The product stores this information in its local product database and related customer-controlled files unless the customer configures another destination.
Tracendra does not automatically upload locally stored prompts, tool calls, model outputs, incidents, or forensic evidence to the Tracendra commercial account, billing, or licensing service.
The product does make limited commercial-service requests for license activation, validation, and deactivation as described in Section 6. Those requests are licensing traffic, not uploads of the local forensic database. A customer may separately configure model providers, notification callbacks, backup destinations, support transfers, or other integrations. Those customer-selected transmissions are controlled by the customer’s configuration and the destination’s terms.
Customers operating a local deployment are responsible for its access controls, infrastructure, backups, integrations, and retention settings.
5. Accounts and Authentication
The commercial service implements separate customer and administrator account and session systems for its full browser mode; those accounts are created by an operator or administrator. The active public account application separately uses Supabase Auth for self-registration, email verification, signin, password recovery, refresh, and logout. New users receive their own profile and organization membership through the reviewed database trigger, and RLS policies limit browser access to the authenticated user’s permitted organization records.
Passwords are not stored in plaintext. The implementation stores salted password hashes using PBKDF2-HMAC-SHA256 with 600,000 iterations and a random 16-byte salt. Temporary passwords can be generated for account creation or administrator-driven reset, are displayed once, and are not stored in retrievable form. Resetting a customer password revokes that customer’s existing sessions.
At login, the service creates a random browser session token. The raw token is held in the browser’s HttpOnly cookie and presented with requests; only its SHA-256 digest is stored in the commercial database. Session records include account linkage, a CSRF token, creation, last-seen, absolute-expiration and revocation times, and, for administrator sessions, a reauthentication timestamp. The current implementation enforces a 12-hour absolute session lifetime, a 30-minute idle timeout, and a maximum of five active sessions per account. The database-retention period for expired or revoked session records remains to be approved.
The CSRF token is stored in the server-side session record and returned to the same-origin browser in login or account responses. Browser code holds it in memory and submits it with state-changing requests. It is not stored in a cookie, local storage, or session storage.
Client IP addresses are used in memory for login and licensing rate limits. Whether production infrastructure additionally retains IP addresses or other request logs depends on the final deployment and hosting configuration.
Supabase Auth manages the public account application’s password hashes, email verification, recovery links, access tokens, and refresh tokens. Tracendra’s browser code does not receive the stored password hash. The browser persists the Supabase authentication session in local storage so that sign-in survives navigation and browser restarts; authenticated requests send the access token only to the configured production Supabase project. Database Row Level Security limits users to their own profile and permitted organizations, with billing mutation reserved to server-side functions. This separate design does not change how the existing commercial portal hashes passwords or stores its cookie sessions.
6. Licensing and Installation Activation
A license consists of a displayable license identifier and a secret. The commercial service stores the license identifier and an HMAC-SHA256 verifier derived from the secret and a server-side pepper. It does not store the raw license secret. A new or rotated raw license key is returned only once to the authorized customer, administrator, or operator.
The locally deployed product stores its raw license key in a customer-controlled local file or process configuration. During activation, validation, and deactivation, the product sends the license key to the configured Tracendra commercial licensing endpoint. In hardened deployments, that endpoint is required to use HTTPS. The request may also contain:
- a stable, random, opaque installation identifier generated and stored locally on first use; and
- a short product identifier, currently
agentforensics, during activation.
On first-run activation, the product sends the submitted license key, installation identifier, and product identifier to the commercial service. If activation succeeds, the product stores the raw key locally and updates its local entitlement state. The commercial service stores an activation record containing an activation identifier, license identifier, installation identifier, product identifier, status, and lifecycle timestamps. It also updates the license’s validation time and records safe licensing/audit events.
The locally deployed product maintains a signed local license cache for bounded offline operation. That cache stores a SHA-256 hash of the license key, the installation identifier, status, edition, capabilities, expiration, displayable license identifier, validation time, and a clock high-water mark. It does not store the raw license key in the cache record. A separate locally generated signing key protects the cache.
License validation responses contain entitlement information such as status, edition, capabilities, expiration, displayable license identifier, and validation time. They do not contain product prompts, tool calls, model outputs, incidents, or forensic evidence.
7. Stripe Checkout and Subscription Data
Tracendra uses Stripe for the implemented commercial checkout and subscription flow. Checkout occurs on a Stripe-hosted page.
When Tracendra creates a checkout, it sends Stripe:
- the server-configured recurring Stripe price identifier and quantity;
- Tracendra’s checkout success and cancellation URLs;
- an opaque internal purchase identifier as Stripe’s client reference and metadata; and
- a Stripe idempotency key derived from that purchase identifier.
The audited code does not send local forensic content to Stripe and does not include a customer email address in its Checkout Session creation parameters. A customer may provide contact, billing, and payment information directly to Stripe on Stripe’s hosted page. That information is processed by Stripe under Stripe’s terms and privacy practices; it does not pass through the public Tracendra website.
Through Stripe APIs and signature-verified webhooks, Tracendra receives and retains limited commercial state needed to fulfill and administer the subscription, including Stripe Checkout Session, customer, subscription and event identifiers; event type and outcome; configured price identifier; checkout and subscription/payment status; cancellation-at-period-end status; current-period end; and related timestamps. Invoice events are used to resynchronize the current subscription state, but complete webhook bodies and full card details are not retained in the commercial database.
In the active account/billing integration, Tracendra also sends Stripe the authenticated user’s email address when creating the organization’s Stripe customer, plus an opaque organization identifier and canonical plan/version metadata. Stripe returns hosted Checkout and Customer Portal URLs and the commercial identifiers/status listed above. The browser supplies only a canonical plan and billing interval; server-side code selects the configured Stripe Price. A signature-verified webhook, rather than the browser redirect, is authoritative for billing state. Full webhook bodies are processed transiently and are not designed to be retained in Supabase.
8. Cookies and Similar Technologies
The public account application’s Supabase browser client uses local storage for strictly necessary authentication session persistence. The pricing-to-signup journey also uses session storage for the selected plan and billing interval; that value is a user-interface convenience and is not trusted for billing or authorization. The server revalidates the canonical plan and derives the Stripe Price. Users can clear this browser storage by signing out or through browser controls, subject to Supabase session invalidation behavior. The public site does not use advertising cookies or analytics storage.
The separate commercial customer and administrator portals use strictly necessary session cookies named af_customer_session and af_admin_session. Each cookie contains a random opaque session token and is configured with:
HttpOnly;SameSite=Strict;- a narrow path of
/customeror/admin; - no
Domainattribute; and Securewhen the deployment is configured with an HTTPS external URL.
For loopback development over plain HTTP, the Secure attribute is not set so login can function locally; the other restrictions remain. Logout clears the cookie and revokes the session server-side. The commercial portal does not store its CSRF token or raw license secret in local storage or session storage.
Because the public website uses no analytics or advertising cookies and the commercial portal uses only necessary authentication/security cookies, the current code does not include a general advertising-cookie consent banner. This must be reassessed before adding analytics, marketing, or other non-essential technologies.
9. Contact, Support, and Email
The public website currently provides a direct email link to website@tracendra.net. Clicking the email link opens the visitor’s chosen email application; the website itself does not collect or submit contact fields, and its dormant same-origin PHP contact endpoint is disabled.
Messages sent through the public email link are transmitted by the visitor’s chosen email provider and received through the business-email service configured for website@tracendra.net. Those email services may receive the sender and recipient addresses, subject, message content, attachments, and ordinary delivery and security metadata. Tracendra has not adopted a fixed deletion period for these contact emails. The website hosting provider may separately process ordinary request metadata and operational logs when visitors use the public website.
The separate full commercial browser service has no transactional-email integration; its operator-created temporary credentials are delivered out of band. The active Supabase public account application provides email verification and password recovery through the production transactional-email configuration described below.
The production Supabase account application sends verification and password-recovery emails through Twilio SendGrid using authenticated SMTP submission with TLS. The visible sender is Tracendra Accounts <accounts@tracendra.net>. Tracendra sends SendGrid the recipient address, sender address and name, subject, message body containing the one-time Supabase link, and ordinary delivery metadata needed to deliver, retry, secure, and troubleshoot the message. SendGrid returns delivery and authentication results and related message-event metadata. Global open tracking, click tracking, subscription tracking, and Google Analytics tracking are disabled for these authentication messages. The separate reviewed TEST project uses the same provider architecture with its own environment-specific configuration.
accounts@tracendra.net remains a Google Workspace Group used as the reply destination; it is not a separately paid mailbox and its password is not used for SMTP authentication. The production and TEST configurations use separate SendGrid credentials stored only in their Supabase projects’ encrypted server-side SMTP configuration. No SMTP credential is included in browser code, the public website, or the repository.
Tracendra uses Google Workspace / Gmail for approved Tracendra business email addresses and for receipt of privacy, legal, and other direct messages where applicable, including privacy requests sent to Codinginlua1@gmail.com. This does not establish which business-email provider receives website@tracendra.net; that address is described in provider-neutral terms above. The applicable email provider receives the sender’s address, message content, attachments the sender chooses to include, and ordinary email-delivery metadata.
Users may voluntarily provide support messages, attachments, diagnostics, or forensic records through an approved support channel. Tracendra receives and uses only the material actually provided through that channel.
10. Technical, Security, and Administrative Data
The commercial service uses client IP addresses in memory for rate limiting and processes session, CSRF, account, activation, webhook, and administrative activity to authenticate users, enforce authorization, prevent abuse, operate licensing, and investigate service issues. Its append-only commercial audit records contain safe identifiers and outcomes rather than passwords, payment-card details, raw session tokens, raw license secrets, webhook signatures, or full webhook payloads.
The locally deployed product maintains its own security and forensic audit records in the customer’s environment. Those records are distinct from the centrally operated commercial audit table and are not automatically copied to it.
Production web servers, reverse proxies, infrastructure providers, and security tools may generate additional request or operational logs. Their exact content and retention depend on the active Namecheap hosting and server configuration; Tracendra has not adopted a separate fixed retention period for those records.
11. How We Use Information
Tracendra may use information it actually receives to:
- provide, operate, secure, maintain, and support the relevant service;
- authenticate customer and administrator users and administer accounts and sessions;
- create, validate, activate, rotate, revoke, and enforce licenses and entitlements;
- initiate Stripe checkout, synchronize subscriptions, and maintain commercial records;
- respond to inquiries and support requests;
- detect fraud, abuse, account compromise, or attacks against Tracendra-operated services;
- maintain security, webhook, licensing, and administrative audit records;
- communicate service, legal, and security information through an approved channel;
- improve reliability and usability based on information Tracendra lawfully receives; and
- comply with legal obligations and resolve disputes.
12. AI Model Training
Tracendra does not use customer forensic content to train general-purpose AI models.
If Tracendra later adopts a training or model-improvement practice involving customer data, it must be separately disclosed and supported by an appropriate legal basis and agreement.
13. Selling or Sharing Personal Information
The current public website does not contain advertising technology or cross-context behavioral advertising trackers. Tracendra does not sell personal information.
Statutory definitions of sell and share vary by jurisdiction. These disclosures will be reassessed if Tracendra’s providers, practices, ownership structure, or applicable legal thresholds change.
14. Model Providers and Customer-Configured Integrations
When a customer configures the locally deployed product to route or proxy traffic to a model provider or another integration, the product sends the selected traffic to that customer-chosen destination. Those interactions are subject to the customer’s relationship with the provider and the provider’s terms and privacy practices. Tracendra does not control customer-selected providers.
The product also supports an operator-configured notification callback. The default notification adapter does not make a network call. If the operator enables a callback, redacted incident or analysis summary fields may be sent to the operator-selected destination. This is separate from the Tracendra commercial licensing service.
Customers should configure destinations carefully and avoid transmitting information they are not authorized to disclose.
15. Service Providers
Confirmed or selected for launch:
- Stripe: hosted checkout and commercial subscription/payment-state processing as described in Section 7.
- Namecheap: current hosting provider for the public website. Ordinary request, operational, and security-log data may be processed according to the selected hosting service and configuration. The dormant PHP contact endpoint is disabled, and Namecheap does not currently deliver public website form submissions.
- Google Workspace / Gmail: used for approved Tracendra business email addresses and receipt of privacy, legal, and other direct messages where applicable. Tracendra does not claim here that
website@tracendra.netterminates at Google Workspace or Gmail.
Production account and email services:
- Supabase: the production account application, Auth service, reviewed account/billing schema, Row Level Security policies, billing Edge Functions, and server-side commercial configuration described in this Policy.
- Twilio SendGrid: authenticated SMTP delivery of Supabase verification and password-recovery messages from
Tracendra Accounts <accounts@tracendra.net>. SendGrid receives recipient and sender addresses, subject, message content and authentication links, and delivery/security metadata. Tracking features are disabled for these authentication messages.
The public website contact path is direct email, and its dormant same-origin PHP endpoint is disabled. SendGrid is limited to the Supabase authentication-email environments described above; it is not used for marketing email by this integration.
The public account application’s authentication, password hashing, and session issuance are provided by Supabase Auth. The separate commercial browser service retains its own audited customer/admin authentication and CSRF controls, while Tracendra’s authority service implements commercial licensing and activation.
16. Data Retention
The current code enforces a 12-hour absolute commercial-session lifetime and a 30-minute idle timeout. It also maintains timestamps for account, checkout, subscription, license, activation, webhook, and audit activity and a bounded local entitlement cache. These operational time limits do not establish how long database rows, logs, support records, or backups are retained.
Tracendra has not adopted fixed deletion periods for centrally operated account, checkout, subscription, license, activation, webhook, commercial-audit, email, infrastructure-log, or support records. Tracendra retains those records for as long as reasonably necessary to provide and secure the Service, administer accounts, subscriptions and licenses, maintain business and security records, comply with law, and resolve disputes. This standard will be updated if Tracendra adopts category-specific periods. Local forensic retention is controlled by the customer’s deployment, configuration, backup practices, and applicable obligations.
Twilio’s current SendGrid documentation states that email message bodies are retained only as long as necessary for delivery and retry, up to 72 hours; random content samples used for anti-fraud or troubleshooting may be retained for 7 days; most recipient, activity, and message metadata times out after a maximum of 37 days; and pseudonymized email-event data that does not contain message-body content may be retained for up to one year for fraud, abuse, security, and network protection. Twilio’s contractual and legal obligations may require additional handling, and these provider periods may change. Tracendra has not adopted a separate promise that shortens the provider’s documented retention.
No fixed deletion period has been approved for the active Supabase profile, organization, membership, billing, entitlement, commercial-link, Stripe-event, and billing-audit records. Tracendra retains them under the general operational standard in this section until category-specific periods are approved.
17. Security
The audited implementation includes password hashing, random session and CSRF tokens, hashed server-side session-token storage, narrow HttpOnly SameSite cookies, server-side session revocation, HTTPS requirements for hardened licensing connections, HMAC license-secret verification, signed local license caching, webhook signature verification, authorization checks, request-size and rate limits, cache-control protections, and commercial audit records.
The account/billing system additionally uses Supabase email/password authentication, Row Level Security, organization-scoped read policies, server-only environment-specific Stripe secrets and price mapping, Stripe raw-body signature verification, webhook event idempotency and ordering, billing audit records, and an HMAC-authenticated HTTPS entitlement bridge. The reviewed migrations, browser integration, production custom SMTP, billing Edge Functions, server-side LIVE Stripe configuration, and commercial synchronization endpoint are active in the separate production environment. Controlled production and TEST lifecycle verification is maintained separately from this Policy.
These measures are designed to reduce risk but cannot guarantee absolute security. Customers must protect account credentials, administrator access, license materials, local deployment infrastructure, model-provider credentials, backups, and locally stored forensic records.
18. Security Incidents
We will provide legally required notifications concerning qualifying security incidents in accordance with applicable law. This Policy does not create a notification deadline beyond what applicable law or a separate written agreement requires.
19. International Data Transfers
Information received by Tracendra, Namecheap, Google, Stripe, Supabase, or Twilio SendGrid may be processed in jurisdictions different from the user’s own. The reviewed SendGrid account uses the provider’s Global/United States environment, but Tracendra does not make a contractual data-localization commitment or claim that all processing occurs in one country. Any legally required international-transfer safeguards will depend on the user, provider, service configuration, and applicable law.
20. Privacy Rights
Depending on applicable law, individuals may have rights to request access, correction, deletion, portability, restriction, objection, or withdrawal of consent. These rights vary by jurisdiction and may be subject to identity verification and lawful exceptions.
To submit a request, email Codinginlua1@gmail.com and identify the message as a privacy request. Tracendra may need information sufficient to verify the request and identify relevant records. For information controlled solely by a customer in a local deployment, the individual may need to contact that customer directly.
21. U.S. State Privacy
Residents of certain U.S. states may have additional privacy rights under applicable law. Where such laws apply to Tracendra, we will honor applicable verified requests. Statutory applicability and required notices must be evaluated against the final entity, processing activities, and business thresholds.
22. European and UK Users
Where the GDPR, UK GDPR, or similar law applies, Craig Gebo and Eric Gebo, operating under the Tracendra name, are the controllers to the extent they determine why and how personal information is processed. The applicable legal basis, transfer safeguards, and any representative or data-protection-officer requirements depend on the processing activity and applicable law.
This Policy does not claim GDPR or UK GDPR certification.
23. Children’s Privacy
Tracendra is a professional cybersecurity and developer product and is not intended for children. We do not knowingly solicit personal information from children. If you believe a child has provided information to Tracendra, email Codinginlua1@gmail.com and identify the message as a privacy request.
24. Legal Requests
Tracendra may disclose information where reasonably necessary to comply with applicable law or valid legal process, protect rights or security, investigate fraud or abuse, enforce agreements, or address an emergency involving risk of harm.
25. Business Transfers
Information may be transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets. Following such a transaction, customer data and personal information will remain subject to applicable privacy commitments and law.
26. Changes to This Policy
Tracendra may update this Policy. The revised version will be posted with an updated effective date. We will communicate material changes in an appropriate manner and provide any notice required by applicable law or agreement.
27. Contact
Tracendra Privacy
Owners and Operators: Craig Gebo and Eric Gebo
Privacy Contact: Codinginlua1@gmail.com
Mailing Address: Tracendra does not currently maintain a public business mailing address.
