Skip to content

LEGAL Privacy notice

Privacy notice

What personal data Tracepointer handles, why, and how long it is kept.

Last updated 10 August 2026 Applies to Tracepointer Ltd

Template — not yet reviewed by a solicitor

This document is scaffolding written to match how the platform actually handles data. It is not legal advice and must be reviewed and amended before the site goes live. Remove this notice by setting 'reviewed' => true in config/policies.php.

01

Who is responsible for your data

Tracepointer Ltd is the controller for personal data about our own customers — the people who hold accounts, the details on their invoices, and the messages they send us.

For the visitor and customer data that flows through the platform on behalf of a company, Tracepointer Ltd is a processor. The company that collected it is the controller and decides what is collected, why, and for how long. Our obligations in that role are set out in the data processing addendum.

02

What we collect

As a controller, for account holders:

  • Account details — name, work email address, organisation, and a hashed password.
  • Billing details — company name, billing address, VAT number, and a payment reference held by our payment processor. We do not store card numbers.
  • Product usage — pages viewed in the dashboard, features used, and error diagnostics, so we can find and fix faults.
  • Correspondence — support tickets and emails you send us.
03

What we process on behalf of companies

When a company installs the tracker or connects an integration, the platform receives data about that company's own visitors and customers. By design it is minimised:

  • A first-party identifier stored in a cookie, used to join a visit to a later outcome.
  • Page URLs, referrers, campaign parameters and advertising click identifiers.
  • Approximate location, derived from a hashed or truncated IP address. Raw IP addresses are not retained unless a company explicitly enables it and records a justification.
  • Hashed email addresses and phone numbers, used to match a person across devices and to send conversion signals to advertising platforms. Raw values are stored only where the company enables it and has a lawful basis.
  • Business outcomes supplied by the company — that a lead was created, an appointment was booked, attended, or produced revenue.
04

Lawful basis

For account and billing data we rely on performance of a contract. For product usage and diagnostics we rely on legitimate interests — running a reliable service — balanced against your interests.

For tracking on a company's own websites, the controller is the company. Where consent is required, it must be collected before the tracker records anything. The platform captures consent state alongside every event and will not export a conversion for a visitor who has not consented to marketing.

05

How long it is kept

Raw event data is retained for a period each company sets, defaulting to 26 months. A nightly job deletes anything past that horizon. Aggregated reporting totals are kept beyond it, because they contain no personal data.

Account and billing records are kept for seven years after an account closes, to meet UK company and tax record-keeping requirements.

06

Who else sees it

We do not sell personal data and we do not use it to train models.

Data is shared with the infrastructure and service providers listed in our subprocessors page, each under a written contract. Where a company has enabled a conversion export, hashed identifiers are transmitted to the relevant advertising platform on that company's instruction.

07

International transfers

Application data is stored in the United Kingdom and the European Economic Area. Where a subprocessor operates outside those regions, transfers are covered by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.

08

Your rights

You may request access to your personal data, correction of it, erasure, restriction or objection to processing, and portability. Write to the address below and we will respond within one month.

If the data concerns your activity on a customer's website rather than your relationship with us, we will pass the request to that customer, who is the controller, and support them in answering it.

You can complain to the Information Commissioner's Office at ico.org.uk.

09

Contact

Privacy enquiries: privacy@tracepointer.com.

Tracepointer Ltd, London, United Kingdom.

Questions about this document? Write to privacy@tracepointer.com.