TrackThemTrackThem

Privacy Policy

Last updated: September 1, 2026

TrackThem ("we", "us", "our") is a competitor-monitoring tool for e-commerce merchants. This policy explains what personal data we collect, why, how it's protected, and the rights you have over it. We are the data controller for the data described here.

1. What we collect

2. Cookies

We use only what's strictly necessary to run the service: a session cookie from Supabase Auth to keep you signed in, and a short-lived cookie set only during a Google sign-in to prevent CSRF attacks. We don't use third-party advertising or cross-site tracking cookies. If we later add privacy-respecting product analytics, this section will be updated accordingly.

3. Legal basis for processing (EEA/UK users)

We process account, tracking, and change data under contractual necessity — it's required to deliver the service you signed up for. Billing data is processed under a mix of contractual necessity and legal obligation (invoicing, tax). Connecting your own store is optional and processed on the basis of your explicit action to activate it; you can withdraw that at any time by disconnecting.

4. How we use it

To run the checks you set up, to detect and score changes, to generate the recommended action plans (on paid plans), to deliver your email alerts and digests, to bill your subscription, and to secure the service against abuse. To score a change and write an action plan, the extracted page text and, where relevant, your own connected-store catalog summary are sent to Anthropic's Claude API for that single request. We do not sell your data, and we don't use your data to train third-party AI models beyond generating your own result in that request.

5. Automated processing

Change summaries, impact scores, and action plans are generated by an AI model (Claude, by Anthropic). This is a business analytics tool, not a decision made about you as an individual — it produces no legal or similarly significant effect on a person, so it falls outside GDPR Article 22's automated-decision-making protections. You're always free to disregard or act on the suggestions as you see fit, and every alert links the source page so you can verify it.

6. Who we share it with

Each of these processes data under their own privacy terms as our sub-processors, scoped strictly to the function above. We don't share your data with anyone for their own independent marketing purposes.

7. International data transfers

Our sub-processors operate infrastructure in the United States and/or the EU. Where personal data of EEA/UK users is transferred outside those regions, it's done under those providers' own standard contractual clauses or equivalent safeguards.

8. Data retention

Your change history is kept for the window set by your plan — 7 days on the free tier, 30 days on Starter, 90 days on Growth, and 1 year on Scale. Change events older than your window are permanently deleted by an automated nightly process; there is no hidden copy, and a downgrade shortens the window going forward. If you cancel to the free tier, older history beyond 7 days is removed. Account data and your plan/billing record are kept while your account is active, plus a reasonable period afterward to meet legal/tax obligations. Deleting your account (from Settings) permanently removes your account data, trackers, change history, store connection credential, and usage records, and cancels any active subscription — without a recovery window.

9. Security

Your store-connection credential is encrypted at rest (AES-256-GCM) and is never written to your browser's local storage or sent from your browser to our server — the server resolves it itself, server-side, from the encrypted copy, so it's never in a place a browser-based attack (like XSS) could read. Database access outside your own account uses server-only credentials; your data is never queried directly from a browser. If we become aware of a data breach affecting your personal data, we'll notify you without undue delay as required by applicable law.

10. Your rights

Depending on where you live, you may have the right to access, correct, export, delete, or restrict the processing of your personal data, and to object to or withdraw consent for certain processing. Most of these you can exercise directly from your dashboard settings; for anything else, contact us below and we'll respond within the timeframe required by applicable law.

If you're in the EEA/UK, you also have the right to lodge a complaint with your local data protection authority. If you're a California resident, you have equivalent rights under the CCPA/CPRA, including the right to know what personal information we collect and to request its deletion — we do not sell personal information.

11. Children's privacy

TrackThem is a business tool intended for merchants and is not directed at children. We don't knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we'll delete it.

12. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by updating the date at the top of this page; continued use of TrackThem after a change means you accept the update.

13. Contact

Questions about this policy, or to exercise any of your rights: trackthem.app@gmail.com

This policy describes our actual data practices in plain language. It isn't a substitute for tailored legal advice — if you need a formal GDPR/CCPA compliance opinion for your jurisdiction, have it reviewed by a lawyer.