Last updated 16 September 2026
Privacy, plainly stated.
tracing.tools helps organisations understand their website traffic and revenue. This notice explains the data involved, including when you use the product and when a website you visit uses its tracker.
Default tracking
The default tracker does not set an analytics cookie or write an identifier to browser storage.
Your data
Customers choose what their events, traits, and payment metadata contain. Those fields can include personal data.
Questions
Contact us at hello@tracing.tools.
Roles and scope
“tracing.tools”, “we”, “us”, and “our” mean the operator of tracing.tools. For account administration, the tracing.tools website, security, and direct communications, we act as a controller of the data described below.
When an organisation installs tracing.tools on its own website, that organisation decides why and how its visitors’ data is collected. It is normally the controller and tracing.tools acts as its processor. Visitors should read that organisation’s privacy notice for its legal basis, cookie choices, and contact details. This policy does not replace it.
Data we process
What we process depends on the features a customer uses.
- Account data: name, email address, profile image, organisation and membership details, plan, site settings, and API-key records. Authentication is provided by Clerk; tracing.tools does not receive or store a password in its application database.
- Analytics data: page paths and remaining query strings, page titles, referrer URLs and domains, UTM values, timestamps, language, browser, operating system, device category, screen size, approximate country, region, and city, event names, and duration data.
- Customer-supplied data: custom-event properties and identify traits. Customers must not send sensitive data or unnecessary personal data. A field that a customer chooses to send can identify a person even where the standard tracker does not.
- Revenue data: when a customer connects Stripe webhooks or sends revenue, payment amount, currency, status, plan, customer and subscription identifiers, email address when supplied by Stripe, and attribution fields can be stored.
- Ask data: questions, up to six prior chat messages, optional selected text, and the dashboard metrics and breakdowns needed to answer the question. These are sent to the AI provider described below.
How collection works
In the default cookieless mode, the collector uses the request IP address, user-agent, site key, and a salt that rotates every UTC day to calculate a visitor hash. The application database stores that hash, not a raw IP-address column. This lets the product count activity during that day without making the identifier reusable across sites or days. It is still information relating to a person in context and should not be treated as anonymous.
The collector retains support for a first-party cookie identifier for legacy or specifically configured sites. If a site is served in that mode, the tracker creates a browser identifier and can recognise a visitor for longer. That use may require consent or another legal basis under applicable law. The website operator, as controller, is responsible for making that decision and presenting any required notice or choice.
The tracker omits common advertising click IDs from stored query strings, but it can retain other query-string values. Customers should avoid URLs containing email addresses, tokens, account numbers, or other personal data, and should use path exclusions for pages they do not want to collect.
Why we use data
We use account data to provide access, authenticate users, manage sites and members, answer support requests, maintain the service, and prevent misuse. We process service data on a customer’s documented instructions to collect, store, display, export, and analyse the customer’s analytics and revenue information.
We use the Ask feature only to prepare and send the requested answer. We may also process data to meet legal obligations, protect the service and its users, and establish, exercise, or defend legal claims. Where applicable law requires a legal basis, it may be the performance of a contract, compliance with a legal obligation, legitimate interests such as security and service reliability, or consent.
Retention and deletion
Analytics, event properties, traits, and revenue records remain available while a customer keeps them in the service. A customer can reset a site’s collected data from its settings. Deleting a site removes it from normal account access; its records are then subject to the service’s deletion process. We retain account and service data for as long as needed to provide the service, follow customer instructions, resolve disputes, meet legal obligations, and protect the service.
We do not publish a fixed retention period because it depends on the customer’s configuration and the deployed service’s operational requirements. Backups and legally required records may persist after deletion in accordance with the deployed service’s operational policies.
Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection to certain processing, and to withdraw consent where processing relies on it. You may also have the right to complain to your local data protection authority.
For tracing.tools account data, email hello@tracing.tools with your request. For data collected by a customer’s website, contact that website’s operator first; it is best placed to identify the applicable records and instruct us where necessary. We may need to verify a requester’s identity before acting.
Children
tracing.tools is not directed to children. Customers must not use the service to knowingly collect children’s personal data unless they have the legal authority and safeguards required for that use. If you believe children’s data has been sent to tracing.tools, contact us at hello@tracing.tools.
Changes and contact
We may update this policy as the service or applicable law changes. The date above shows when it was last revised. Material changes will be communicated through the service or another appropriate channel where required.
Questions about this policy or a privacy request can be sent to hello@tracing.tools. Product setup and technical details are available at docs.tracing.tools. See also our Terms of Service.