Privacy Policy

Last updated: August 30, 2026

This Privacy Policy explains how Tracebix ("Tracebix," "we," "us," or "our") handles personal information when people visit our public website, use the Tracebix application, or interact with customer experiences instrumented with Tracebix.

Organizations that use Tracebix determine why and how they collect customer signals. For that information, the organization is generally the controller or business and Tracebix processes the data to provide the service. You should also review the privacy notice of the organization whose website, product, or email you are interacting with.

Information we handle

Account and organization information

We handle information used to create and administer an account, such as name, email address, authentication status, organization membership, role, and account preferences.

Customer signals

Depending on an organization's configuration, Tracebix may process browser events, server events, page URLs, referrers, device and session identifiers, tracked-link clicks, email-pixel requests, campaign attribution, conversion activity, and associated timestamps. Organizations may associate those signals with contacts they manage in Tracebix.

Our public browser interfaces do not accept a contact identifier as proof of identity. Email-to-web continuity uses a short-lived opaque token, stores only its hash, and removes the token from the browser URL before the first tracked event.

Billing and communications

We handle subscription status, plan, invoices, and limited billing references. Stripe processes payment-method information. We also process transactional email delivery status for authentication, invitations, and notifications.

Operational information

We process security, request, error, audit, usage, and performance information needed to operate and protect the service. Logging is designed to exclude raw handoff tokens, credentials, customer email payloads, and other unnecessary sensitive values.

Public website

The first release of tracebix.com does not use advertising trackers, analytics cookies, forms, or behavioral personalization. Vercel and network providers may process ordinary request information, including IP address and browser metadata, to host and protect the site. The authenticated application may use strictly necessary browser storage for sign-in, App Check, and product operation.

How we use information

We use information to:

  • provide, secure, and troubleshoot Tracebix;
  • authenticate users and enforce organization, project, and role boundaries;
  • ingest approved events and produce contact timelines, attribution, analytics, notifications, and customer-configured webhooks;
  • administer subscriptions, usage limits, and transactional communications;
  • prevent abuse, investigate incidents, and comply with law; and
  • improve reliability and product behavior using aggregated or de-identified information where appropriate.

Tracebix does not sell personal information or use customer signals for cross-context behavioral advertising.

Service providers and disclosures

We use service providers only for defined operational purposes, including:

  • Google Firebase and Google Cloud for authentication, application hosting, functions, storage, databases, security controls, and monitoring;
  • Stripe for subscriptions, billing, payment processing, and fraud prevention;
  • Resend for approved transactional email;
  • Cloudflare for DNS, network security, and customer tracking hostnames; and
  • Vercel for the public Tracebix website.

We may also disclose information to a customer-configured webhook destination, professional adviser, corporate successor, or authority when instructed, required by law, or reasonably necessary to protect rights and safety. Providers may process information in countries other than your own under their contractual and legal transfer mechanisms.

Retention and deletion

We retain information for the time needed to provide the service, meet contractual or legal obligations, resolve disputes, and protect the platform. Specific continuity safeguards include:

  • an unredeemed email-to-web handoff expires ten minutes after issuance;
  • a redeemed browser identity binding expires after 30 days;
  • same-session campaign attribution expires after 30 minutes; and
  • requesting contact privacy deletion invalidates future continuity and deletes or anonymizes associated artifacts according to the product's deletion workflow.

Backups and security records may remain for a limited period before aging out under the applicable retention schedule. An organization administrator can request deletion of tenant information subject to legal, security, billing, and backup requirements.

Security

Tracebix uses tenant isolation, server-side authorization, scoped credentials, encryption in transit, provider-managed encryption at rest, short-lived tokens, audit records, backups, monitoring, and release controls. No system is completely secure, and we cannot guarantee absolute security.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, or to appeal a privacy decision. If the information was collected by an organization using Tracebix, contact that organization first. We support customers in responding to verified requests.

For information tied directly to a Tracebix account or the public website, email app@tracebix.com. We may need to verify your identity and authority before acting.

Children

Tracebix is a business service and is not directed to children. Customers must not intentionally use Tracebix to collect children's personal information without appropriate legal authority and safeguards.

Changes

We may update this policy as the service or law changes. We will post the revised policy here and change the "Last updated" date. Material changes may also be communicated through the service or by email.

Contact

Questions or privacy requests can be sent to app@tracebix.com.