1. Introduction
Tracklytix Inc. ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Tracklytix platform ("the Platform"), including our website, applications, and APIs.
By using the Platform, you consent to the data practices described in this policy. If you do not agree with this Privacy Policy, please discontinue use of the Platform.
2. Information We Collect
We collect the following categories of information:
Personal Information
- Name, email address, and account credentials
- Business name and contact information
- Billing and payment information (if applicable)
Financial & Business Data
- Transaction records, invoices, and quotes you create
- Client and contact information you store on the Platform
- Expense categories, mileage logs, and financial reports
- Deal pipeline and CRM data
Usage Data
- IP address, browser type, device information, and operating system
- Pages visited, features used, and time spent on the Platform
- Referring URLs and search terms
- Error logs and performance data
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Platform
- Process transactions and generate invoices, quotes, and reports
- Authenticate users and secure accounts
- Send transactional emails (account verification, password resets, invoices)
- Improve and personalize the Platform experience
- Analyze usage patterns and optimize performance
- Detect, prevent, and address technical issues and fraud
- Comply with legal obligations
4. Data Storage & Security
We take the security of your data seriously and implement industry-standard measures to protect it:
- Authentication: User authentication is handled through Supabase Auth with secure token-based sessions and support for email/password authentication.
- Database: Your data is stored in PostgreSQL databases managed by Supabase with encryption at rest and in transit (TLS/SSL).
- Caching: We use Upstash Redis for rate limiting and temporary data caching. Cached data is encrypted in transit and automatically expires.
- Access Controls: API endpoints are protected with authorization headers, rate limiting, and request validation.
While we strive to use commercially acceptable means to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
5. Third-Party Services & Sharing
We do not sell, trade, or rent your personal information to third parties. We may share data with the following categories of service providers:
- Supabase: Authentication, database hosting, and real-time services
- Upstash: Redis-based caching and rate limiting infrastructure
- Hosting Provider: Application hosting and content delivery
These providers are contractually obligated to protect your data and may only use it to provide services on our behalf. We may also disclose your information if required by law, court order, or governmental authority.
6. Cookies & Tracking Technologies
We use cookies and similar technologies for various purposes. For a detailed breakdown of the cookies we use and how to manage your preferences, please see our Cookie Policy.
- Essential Cookies: Required for authentication, session management, and security. These cannot be disabled.
- Functional Cookies: Remember your preferences such as theme settings and dashboard layout.
- Analytics Cookies: Help us understand how users interact with the Platform to improve performance and user experience.
You can control cookie preferences through your browser settings. Disabling essential cookies may affect Platform functionality.
7. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data ("right to be forgotten").
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Restrict Processing: Request limitation of how we process your data.
- Right to Object: Object to processing of your data for certain purposes.
To exercise any of these rights, contact us at privacy@tracklytix.dev. We will respond within 30 days.
8. California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following rights:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to Delete: Request deletion of personal information we have collected from you.
- Right to Opt-Out: We do not sell personal information. If this changes, you will have the right to opt out of the sale of your personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To make a request, email privacy@tracklytix.dev with the subject line "CCPA Request." We will verify your identity before processing the request.
9. Children's Privacy
The Platform is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected personal data from a child under 16, we will take steps to delete that information promptly.
If you believe a child under 16 has provided us with personal information, please contact us at privacy@tracklytix.dev.
10. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with the Platform. Upon account deletion, we will remove your personal data within 30 days, except where we are required to retain it for legal, regulatory, or legitimate business purposes.
Cached data in Redis is automatically purged based on expiration policies and is not retained beyond its functional purpose.
11. International Data Transfers
Your data may be processed and stored in countries outside your country of residence, including the United States. These countries may have different data protection laws. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a prominent notice on the Platform at least 30 days before the changes take effect. We encourage you to review this policy periodically.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
Tracklytix Inc.
Email: privacy@tracklytix.dev