← Back to TrackingCoder

Privacy Policy

Last updated: June 2026

TrackingCoder is operated by PunchUp Digital Ltd, a company registered in England and Wales. We take your privacy seriously and are committed to protecting your personal data.

1. Information We Collect

When you create an account, we collect your name, email address, and authentication data through our provider Clerk. When you use the service, we collect the website URLs you scan, the tracking configurations you create, and your credit purchase history.

2. How We Use Your Data

We use your data to provide the TrackingCoder service, process credit purchases via Stripe, generate tracking code tailored to your website, and communicate important service updates. We do not sell your data to third parties.

3. Data Storage

Your data is stored securely on servers provided by Neon (database), Clerk (authentication), and Vercel (hosting). Tracking IDs you store in the ID Vault are encrypted at rest using AES-256-GCM with a key held by us and never sent to your browser. All data is processed within the EU and US regions.

4. Cookies

We use essential cookies for authentication and session management. We use a referral tracking cookie (30-day duration) when you arrive via a referral link. We do not use advertising or analytics cookies on our own site.

5. Third-Party Services (Sub-processors)

We use Clerk (authentication), Stripe (payments), Neon (database), Vercel (hosting) and Resend (email) to operate the service. Each processes data on our behalf under its own privacy policy and a data processing agreement. The current list of sub-processors, with their purpose and region, is maintained in our Data Processing Agreement.

6. Your Rights

Under GDPR, you have the right to access, rectify, or delete your personal data. You can request a data export or account deletion by contacting us at privacy@trackingcoder.com. We will respond within 30 days.

7. Website Scanning

When you scan a website URL, we fetch the publicly available HTML of that page to detect the CMS, plugins, and analytics tools installed. We do not store the full HTML content after analysis. We only retain the detected profile (CMS name, plugin list, etc.).

8. TC Pro Monitoring Data

If you use TC Pro Monitor, the Monitor tag you install sends us a small signal each time one of your tracked events (or a once-per-session install check) fires on your site. For this data, you are the data controller and we act as your processor under our Data Processing Agreement.

We are privacy-first about what we keep. We never store the visitor's raw IP address: it is reduced at the point of ingest to a salted, daily-rotating one-way hash. A denylist strips direct identifiers (such as user IDs, emails, phone numbers and names) and URL query strings before anything is stored, and raw Monitor events are automatically deleted after 90 days. The tracking code we generate supports Google Consent Mode v2, so the tags can respect your cookie banner's consent state.

9. Google Tag Manager Integration

If you choose to connect your Google account to import a container directly into Google Tag Manager, you grant TrackingCoder access to your Google Tag Manager containers through Google's OAuth consent screen. This connection is optional and used only to perform actions you explicitly request.

With your permission we access the tagmanager.edit.containers scope to list your accounts, containers and workspaces so you can choose where to import, and to create the tags, triggers and variables you generated in TrackingCoder in the workspace you select. We do not read, modify or delete any other data in your Google account, and we never publish a container version on your behalf. You review and publish in Google Tag Manager yourself.

TrackingCoder's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use the access only to provide the import feature to you; we do not use it for advertising, do not sell it, and do not allow humans to read it except where you give explicit consent, for security or debugging you have authorised, or where required by law.

Sharing, transfer and disclosure of Google user data. We do not share, transfer, or disclose Google user data to any third party, and we do not sell it. The only exceptions are: (a) to our infrastructure sub-processors solely as necessary to operate the feature for you (our hosting provider, Vercel, and our database provider, Neon, which store the encrypted tokens described below under strict confidentiality obligations, and which are listed in our Data Processing Agreement); (b) if we are required to do so by applicable law, regulation, legal process or enforceable governmental request; (c) as part of a merger, acquisition or sale of assets, in which case we will notify you before your Google user data becomes subject to a different privacy policy; or (d) with your explicit prior consent. No third party receives Google user data for advertising, analytics, profiling, or any purpose of its own, and we do not use Google user data to train machine-learning or AI models.

Your Google access token is short-lived (about one hour); your refresh token is encrypted at rest (AES-256-GCM) using the same standard as our credential vault. You can disconnect at any time from your account settings, which revokes the token with Google and deletes it from our systems. Cancelling a subscription does not automatically disconnect the integration; only you can disconnect it.

10. Contact

For privacy enquiries, contact us at privacy@trackingcoder.com or write to PunchUp Digital Ltd.