How TrackVerity handles store and customer data

A plain-language summary of data collection, encryption, retention, and merchant responsibilities.

Roles

For visitor and order data from a connected store, the merchant is the controller and TrackVerity is the processor. For TrackVerity account and support data, TrackVerity acts as controller.

Data collected

  • A random first-party _tvid identifier, advertising click IDs, and UTM parameters.
  • Order ID, value, currency, and permitted order details.
  • Buyer email and phone normalized and SHA-256 hashed in memory. Plain email and phone are not written to the tracking database or logs.
  • IP address and browser user agent in raw form because Meta and TikTok require them for server-side matching.
  • Account email and, when you choose Google sign-in, the basic profile details returned by Google.
  • Name, email, and message content that you choose to send through support chat.

Security controls

  • Platform credentials are encrypted at rest with AES-256-GCM.
  • Data is sent over TLS.
  • Row-level security isolates each merchant organization's data.
  • Store webhooks are authenticated with platform-specific HMAC verification.

Retention and location

  • Raw click records containing IP address and user agent are automatically deleted after 90 days.
  • The first-party _tvid cookie can remain on the storefront for up to 400 days.
  • Core application and database processing are configured in Frankfurt, EU regions.
  • Authentication, email, payments, support, and merchant-selected ad platforms can process data in other regions under their own terms and safeguards.

Merchant responsibilities

The merchant is responsible for the legality of collection on the storefront, including required consent banners, cookie notices, and regional consent settings. Credentials remain owned by the merchant and can be revoked at the source platform.

Requests and DPA

A DPA template is available at trackverity.com/dpa. Ask support for a signable copy or help with an access, export, or deletion request. The Privacy Policy and DPA are the controlling documents if this summary differs from them.