Privacy Policy
Creative Data Engineers LLC (“Company,” “we,” “us,” or “our”) operates the website trakr.studio and the Trakr application at app.trakr.studio (collectively, the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit trakr.studio or use Trakr.
1. Who We Are
Creative Data Engineers LLC is a U.S.-registered company operating globally. We comply with applicable U.S. privacy regulations and, where applicable, the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
Contact for data protection inquiries:
E-Mail: turan@creative-data-engineers.com
2. Data We Collect
2.1. Information You Provide
When you join the Trakr waitlist or sign up for product updates, we collect:
- First name
- Email address
When you create a Trakr account and use the application, we collect and process:
- Account details: your email address and display name. If you sign in with Google or Microsoft, these come from that provider (see Section 3).
- Account credentials, managed via Supabase Auth. If you register with an email and password, the password is stored only as a salted hash by Supabase; we never see it.
- Payment information, processed via Stripe. We do not store card details.
- Workspace, team, and configuration data you create.
- Campaign URLs and campaign data you generate within the application.
2.2. Information Collected Automatically
When you visit trakr.studio, we collect usage analytics via a self-hosted event tracking system (Supabase). This includes:
- Pages visited and navigation patterns
- Clicks on interactive elements (buttons, links, form submissions)
- Browser type and viewport size
- Referrer URL
- Approximate timestamp of each event
We do NOT use Google Analytics or any third-party tracking pixels on trakr.studio. All analytics events are sent to our own Supabase database instance hosted by Supabase, Inc.
We do NOT set tracking cookies. Our analytics system uses server-side event logging, not browser cookies.
2.3. Email Interaction Data
When we send you emails via our email service provider (Resend), standard email metadata may be processed, including delivery status and bounce information.
3. Google and Microsoft Sign-In (OAuth)
Trakr offers “Sign in with Google” and “Sign in with Microsoft” as optional ways to create and access your account. You can also register with an email and password instead. This section describes exactly how Trakr interacts with Google user data, and applies equally to Microsoft sign-in.
3.1. Data we access
When you choose to sign in with Google, we use Google’s OpenID Connect service with the scopes openid, email, and profile. Through these scopes, Google shares with us:
- Your email address and its verification status
- Your name. The profile scope also returns your profile picture, which Trakr receives but does not currently display.
- Your unique Google account identifier (the OpenID “sub” value), used to recognize your account on return visits
Trakr does NOT request, access, or receive any other Google user data. We do not access Gmail, Google Drive, Google Calendar, Google Contacts, Google Photos, Google Analytics, Google Ads, or any other Google product or API. Microsoft sign-in uses the equivalent scopes (openid, email, profile) and returns the same basic profile fields from your Microsoft account.
3.2. How we use it
We use the data from Google or Microsoft sign-in solely to:
- Create your Trakr account and authenticate you when you sign in
- Recognize your account across sessions and devices
- Display your name and email inside the application
- Secure your account and communicate essential service information
We do NOT use this data for advertising, and we do NOT use it to develop, improve, or train generalized artificial intelligence or machine learning models.
3.3. How we share it
We do not sell your Google or Microsoft account data and we do not share it with third parties for their own purposes. It is processed by the infrastructure sub-processors listed in Section 6 (primarily Supabase, which stores your account record) to operate the Service.
Team and workspace visibility. If you join a Trakr team or workspace, your name and email address are visible to other authorized members and administrators of that company or workspace. Your name and email are attached to the campaign links you generate, so teammates can see who created them. If you invite someone to your team, they can see your name and email address. This is a collaboration feature of the Service. We do not sell this data or transfer it to unrelated third parties.
3.4. How we store and protect it
Your account data is stored in our Supabase database. It is encrypted in transit using TLS and encrypted at rest by Supabase. Access is restricted by row-level security policies and by access controls limiting data access to authorized personnel.
3.5. How long we keep it, and how to delete it
We retain your Google or Microsoft account data for as long as your Trakr account is active. You can request deletion of your account and its associated data at any time by emailing turan@creative-data-engineers.com. We action verified deletion requests within 30 days, except where a longer retention period is required by law (for example, tax and accounting records). Signing out of Trakr also ends your session and clears your locally cached configuration and link history from that browser.
3.6. Limited Use
Trakr’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How We Use Your Data
- To manage the waitlist and product-updates list, and to notify you about the product
- To send you email (you can unsubscribe at any time via the link in each email, or at trakr.studio/unsubscribe)
- To create your account, authenticate you, and provide and operate the Trakr application
- To analyze how visitors use trakr.studio so we can improve the product and website
- To process payments via Stripe
- To comply with legal obligations
5. Legal Basis for Processing (GDPR)
For visitors and users in the European Economic Area (EEA):
- Consent: when you submit the waitlist or product-updates form, you consent to receiving product-related emails. You can withdraw consent at any time via the unsubscribe link.
- Performance of a contract: when processing is necessary to create your account and provide the Trakr service, including authentication via Google or Microsoft sign-in.
- Legitimate interests: to operate, secure, analyze, and improve our website and service.
- Legal obligations: to comply with tax, accounting, and regulatory requirements.
6. Data Sharing and Third Parties
We do not sell, rent, or trade your personal data. We share data only with the following service providers, strictly as necessary to operate the Service:
- Supabase, Inc. (database hosting, authentication, analytics event storage). Data may be stored in the United States. Privacy policy: https://supabase.com/privacy
- Resend, Inc. (transactional and product email delivery). Privacy policy: https://resend.com/legal/privacy-policy
- Netlify, Inc. (website hosting, CDN). Netlify processes server logs (IP addresses, access times) as part of standard web hosting. Privacy policy: https://www.netlify.com/privacy/
- Stripe, Inc. (payment processing). Privacy policy: https://stripe.com/privacy
- Contabo GmbH (server hosting for the Trakr MCP connector at mcp.trakr.studio). If you connect Trakr to an MCP client, the Google or Microsoft sign-in exchange for that connector runs on this server. Privacy policy: https://contabo.com/en/legal/privacy-policy/
Identity providers. When you choose to sign in with Google or Microsoft, that provider authenticates you and returns the basic profile data described in Section 3. We do not send your Trakr activity back to Google or Microsoft. Their handling of your data is governed by their own policies: Google Privacy Policy and Microsoft Privacy Statement.
Other members of your team or workspace. If you join a team or workspace, your name and email are visible to other authorized members and administrators of that company or workspace, are attached to the campaign links you generate so teammates can see who created them, and are visible to anyone you invite to your team. See Section 3.3 for how this applies to sign-in data.
Where data is transferred outside the EEA, we ensure appropriate safeguards such as Standard Contractual Clauses (SCCs) are in place.
7. Data Retention
- Waitlist and product-updates data (name, email): retained until you unsubscribe or request deletion, or until the list is no longer active.
- Account data (including Google or Microsoft sign-in data): retained for the duration of your account. You can request deletion at any time (see Section 3.5 and Section 8); we action verified requests within 30 days, plus any legally required retention period.
- Analytics events: retained for up to 24 months, then deleted or anonymized.
- Payment records: retained as required by tax and accounting regulations (typically 7 to 10 years).
8. Your Rights (GDPR)
If you are in the EEA or UK, you have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccuracies
- Erasure: request deletion (“right to be forgotten”)
- Restriction: limit how your data is processed
- Data portability: receive your data in a machine-readable format
- Objection: object to processing based on legitimate interests
- Withdrawal of consent: withdraw consent at any time without affecting prior processing
To exercise any of these rights, including deleting your account and the data obtained through Google or Microsoft sign-in, contact us at turan@creative-data-engineers.com. We respond to verified requests within 30 days.
9. Unsubscribe from Emails
Every marketing email we send includes an unsubscribe link. You can also unsubscribe at any time by visiting: trakr.studio/unsubscribe
Unsubscribing removes you from the product-updates emails. It does not delete your account or waitlist entry. To request full data deletion, contact us at the email above.
10. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- TLS encryption for all data in transit
- Encryption at rest for account and database data
- Row-level security policies in our database
- Access controls limiting data access to authorized personnel
- Regular security reviews
No system can guarantee absolute security. Data transmitted over the internet is at your own risk.
11. Children’s Privacy
Trakr is not directed at children under 18. We do not knowingly collect personal data from minors. If you believe we have collected information from a minor, contact us so we can delete it.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. The latest version will always be available at trakr.studio/legal/privacy-policy.html. The “Last updated” date at the top will be updated accordingly.
13. Contact
Creative Data Engineers LLC
E-Mail: turan@creative-data-engineers.com
Website: https://trakr.studio