Privacy Policy
Last updated 19 August 2026
This policy explains what Trakt does with personal data. It covers two different things, and the difference matters throughout: the data we hold about our own customers, and the data our customers collect from their website visitors using Trakt.
For the first we are the controller. For the second our customer is the controller and we are their processor — we hold that data on their instructions and do not decide what it is used for.
Who we are
Trakt is operated by confirm: legal entity name and registered address. For any privacy question, or to exercise a right described in section 8, contact confirm: privacy contact address.
Data we hold about our customers
When you create an account or use the app, we hold:
- Account details — your email address, your name, your role, the plan you are on, and the workspace you belong to.
- Authentication data — handled by Supabase Auth. We never see or store your password.
- Billing data — handled by Stripe. We store the identifiers Stripe gives us and your subscription status. We do not receive or store card numbers.
- Team data — workspace and property memberships, and invitations you send or receive.
- Email records — a log of the transactional emails we have sent you, so support can tell whether a message was delivered.
We use this to provide the service, bill you, notify you about leads and account activity, and answer support requests. We do not sell it, and we do not use it to train models.
Data our customers collect through us
Trakt’s purpose is to tell a business where its enquiries came from. When a customer installs our script on their own website, we collect the following on their behalf, about their visitors:
- Page views — the page address, the referring address, campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content, utm_id), advertising click identifiers (Google gclid, Meta fbclid, TikTok ttclid, Snapchat scid), time spent on the page, and a consent flag. No IP address and no browser user-agent is stored on a page view.
- Form submissions — the values a visitor typed into a form, excluding password fields, together with the page address, the first page they landed on, the ordered list of pages they visited in that session, the campaign parameters and click identifiers above plus Microsoft msclkid, the browser user-agent, and a one-way hash of the IP address.
- Leads — where a customer qualifies a submission into their pipeline: name, email address, phone number, company, location, an estimated deal value, pipeline stage, and any notes their team adds.
- Link clicks — clicks on tracking links and QR codes a customer has generated.
- Site scans — when a customer asks us to scan their own website to find its forms, we fetch and store the results of that scan.
A visitor is identified by two first-party identifiers: a persistent visitor_id and a session-scoped session_id. These are set on our customer’s own domain, not ours. We do not operate an advertising network, we do not build cross-site profiles, and we do not combine one customer’s visitor data with another’s.
IP addresses
Our tracking pipeline does not store raw IP addresses. An IP is hashed with SHA-256 using a salt unique to the website, and only a truncated prefix of that hash is kept — enough to distinguish visitors for analytics, not enough to recover the address.
There is one exception, and we would rather state it than bury it. Submissions made through forms built inside Traktitself currently store the visitor’s raw IP address alongside the answers. confirm: whether this is intended, or is a defect to fix before launch
Consent, and whose job it is
We record whether consent was given for each page view and submission, and whether it was granted, denied, or unknown. We provide that mechanism; we do not operate it.
Obtaining a lawful basis for tracking visitors, presenting a cookie or consent notice where one is required, and publishing a privacy notice describing this collection are the responsibility of the customer whose website the script is installed on. If you are a visitor to a customer’s website and want your data removed, contact that business first — they control it. If you cannot reach them, contact us and we will help.
Who else processes the data
We use the following sub-processors. Each receives only what it needs:
- Supabase — database, authentication and file storage. Region: confirm: hosting region
- Vercel — application and website hosting.
- Stripe — subscription payments. Stripe receives your billing details directly.
- Resend, or an SMTP provider configured by us — transactional email such as invitations and lead alerts.
- Google — only where a customer connects their own Google account. See section 7.
confirm: whether any sub-processor transfers data outside your customers’ region, and the transfer mechanism relied on
Integrations you choose to connect
Nothing is connected unless a customer authorises it. Where a customer connects Google, we request only these scopes:
- Read-only access to contacts, so a lead can be matched to someone already known.
- Read-only access to calendar events.
- Access to spreadsheets, for exporting pipeline data.
- Basic profile and email address, to identify the connected account.
Customers may also connect messaging tools to receive lead alerts, and third-party form providers so submissions reach Trakt. A connection can be revoked at any time in the app, and revoking it stops further access immediately.
Your rights
Depending on where you live you may have the right to access, correct, export, or delete your personal data, to object to processing, and to complain to a supervisory authority.
To exercise any of these, contact us at the address in section 1. Where we act as a processor for one of our customers, we will pass your request to that customer and support them in answering it.
We should be straight about the current state: deletion and export are handled manually on request rather than by a self-service tool, and we have not yet set an automatic retention period after which visitor data is discarded. confirm: retention period, and whether it will be enforced automatically at launch
Security
Data is encrypted in transit. Access is scoped per workspace so one customer cannot read another’s data. Passwords are never stored by us, and password fields are excluded from captured form data.
This website
Our marketing website runs Google Analytics 4 to count visits and see which pages are read. It sets Google’s own _ga cookies in your browser to tell one visit from another, and reports aggregate usage to Google as a processor on our behalf. We do not use it for advertising, we set no advertising cookies, and we run no other third-party trackers. The only value the site itself stores is your light or dark theme preference. confirm: whether a consent banner is required before this runs for EU and UK visitors, and whether Google Consent Mode should gate it — analytics cookies are not strictly-necessary cookies, and §6 already lists a consent notice as outstanding
Changes
If we change this policy we will update the date at the top. For a change that materially affects how we handle personal data, we will tell account holders directly rather than relying on you to notice.