← TrackVerity

Privacy Policy

Effective date: 22 July 2026

TrackVerity provides server-side ad tracking for Shopify and WooCommerce merchants. We match ad clicks to orders and send verified purchase events to the ad platforms the merchant has connected. This policy explains what data flows through us, why, how long we keep it and who else touches it. We wrote it to be read, so we kept it short and specific.

1. Who does what with your data

When you visit or buy from a store that runs TrackVerity, the merchant is the data controller and we are their processor. We process the data described below on the merchant's instructions, under a data processing agreement. For our own website and merchant accounts (for example the email you give us when you sign up or join the waitlist), we act as the controller.

2. What we collect on merchant stores

  • A first-party visitor cookie, _tvid.A random identifier we set on the store's own domain so an order can be attributed to an earlier ad click. It is strictly necessary for the order attribution the merchant installed us to perform. It lives for up to 400 days.
  • Ad click IDs and UTM parameters. Values such as fbclid, ttclid, gclid and utm_source that the ad platforms append to the URL when you click an ad.
  • IP address and browser user agent. We store these in raw form for up to 90 days, then delete them automatically. Meta and TikTok require both fields unhashed for server-side event matching; a hashed IP fails their validation and matches nothing, so hashing here would break the service.
  • Buyer email and phone number, hashed only. When an order webhook arrives, we hash the email address and phone number with SHA-256 in memory, at receipt. The plain values are never written to our database or logs.
  • Order data. Order ID, totals, currency and line items. Buyer names, billing addresses and shipping addresses are never stored.

3. What we collect from TrackVerity users

  • Account data. Your email address and organization details. If you choose Google sign-in, Google provides the basic profile and email data covered by the openid, email and profile scopes. We do not request access to Gmail, Drive, contacts or advertising accounts for sign-in.
  • Billing data. Plan, subscription, invoice and payment-status data. Stripe handles the full card details; TrackVerity does not store them.
  • Support data. The name, email address, messages and technical context you choose to send through chat or email. Commslayer stores the conversation and its AI features can process it to answer from our published support material. A human can take over when the answer is uncertain or the request is sensitive.
  • Email delivery telemetry. To diagnose missing authentication emails, we store the Resend message and event IDs, event type, recipient provider domain, timestamps and a SHA-256 hash of the normalized recipient address. We do not store the email subject, message content, raw recipient address or full webhook payload in this telemetry log.

Do not send passwords, access tokens, private keys, webhook secrets, one-time codes, buyer personal data or special-category data through support chat.

4. Where we store it

Core tracking data is stored on Supabase in eu-central-1 (Frankfurt), and the core application runs on Vercel in fra1 (Frankfurt). Authentication, email, payments, support and merchant-selected ad platforms can use other regions. Where personal data leaves the EEA, we rely on an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism provided by the relevant service.

5. Where it goes

On the merchant's instruction, we transmit matched purchase events to Meta (Conversions API), TikTok (Events API) and, when connected, Google Ads (Data Manager API). Meta and TikTok events can contain the click ID, hashed email and phone, raw IP and user agent, order ID, value and currency. The current Google Ads path sends the gclid, transaction ID, timestamp, value and currency, without hashed buyer contact data. These platforms receive data as independent controllers under their own terms with the merchant. We sell data to no one.

6. Service providers and destinations

  • Supabase (database and authentication)
  • Vercel (application hosting)
  • Resend (service and authentication email delivery)
  • Stripe (subscriptions, payments and invoices)
  • Commslayer, operated by Actuals Oy (support conversations and AI-assisted replies)
  • Google (optional account sign-in and, when the merchant connects it, Google Ads event delivery)
  • Meta (ad event delivery, independent controller)
  • TikTok (ad event delivery, independent controller)

A signable data processing agreement covering TrackVerity's processor obligations is available on request at support@trackverity.com. A template is published at trackverity.com/dpa.

7. How long we keep it

  • Raw IP and user agent: up to 90 days, deleted automatically.
  • Click IDs, UTMs and the _tvid identifier: for the life of the merchant account.
  • Hashed email and phone, order totals: for the life of the merchant account.
  • Email delivery telemetry: up to 90 days, deleted automatically.
  • Merchant account data: until the account closes, then deleted.
  • Support conversations: while the request is active and normally for up to 24 months after resolution, unless a shorter deletion request or a legal obligation applies.

8. Your rights

You can request access to or deletion of your data at any time. If you bought from a store that uses TrackVerity, the fastest route is the store itself, since the merchant is the controller; we act on their deletion instructions without delay. You can also write to us directly at support@trackverity.com and we will handle or forward the request. EU residents hold the full set of GDPR rights: access, rectification, erasure, restriction, portability and objection, plus the right to complain to a supervisory authority.

9. Automated support

The support assistant answers from our help articles and training examples. It is not authorized to change billing, issue refunds, delete data or reveal private account information. Its replies do not make decisions that produce legal or similarly significant effects. You can ask for a human at any time.

10. Changes

When we change this policy we update the effective date above. For material changes we notify merchants by email before the change takes effect.

11. Contact

Questions about this policy: support@trackverity.com.

TrackVerity

Attribution you can trust.

Product

PricingHow it worksFeaturesIntegrationsBook a demoContact

Company

AffiliatesHelp center

Integrations

ShopifyWooCommerceMeta AdsTikTok AdsKlaviyoSnapchat AdsGoogle AdsPinterest AdsAll Integrations
© 2026 TrackVerity. All rights reserved.
Privacy policyTermsDPA