---
title: "Privacy Policy — TraceTail"
description: "What TraceTail collects on this website and through its API, why, who processes it, how long it's kept and how to exercise your rights."
url: https://tracetail.io/privacy-policy
updated: 2026-10-05
---

# Privacy Policy

Last updated October 5, 2026

TraceTail provides a browser fingerprinting API. This policy explains what we collect, why, how long we keep it and what you can do about it. It covers two situations:

- **You visit a website that uses TraceTail.** That website's operator, our customer, decides how your data is used: they are the _controller_, and TraceTail processes the data on their behalf as their _processor_.
- **You use the TraceTail website or have a TraceTail account.** TraceTail decides how that data is used and is the controller.

For any privacy question or request, email <support@tracetail.io>.

## 1. Visitors to websites that use TraceTail

### What is collected

When a website runs TraceTail's browser SDK with an API key, the SDK reads characteristics of your browser and device: the browser and operating system family, language, platform, whether cookies are enabled, screen size and color depth, time zone, number of CPU cores, touch points, device memory, a canvas rendering signature, the WebGL vendor and renderer, which of 24 common fonts are installed, and whether the browser reports itself as automated. It computes a visitor ID from these characteristics and sends the ID and the characteristics to TraceTail. Our servers also record your IP address and your browser's user agent.

The SDK doesn't store anything on your device and doesn't track mouse, keyboard or scrolling. If a website uses the SDK without an API key, the visitor ID is computed in your browser and nothing is sent to TraceTail.

### Why

To give the website operator a visitor ID and a flag for automated browsers, which they typically use to prevent fraud and abuse; to show them requests and visitors in their dashboard; to bill them for usage; and to protect the service from abuse.

### How long it is kept

Your visitor record (the visitor ID, the characteristics, your IP address and user agent) is deleted 180 days after your last visit to that website. Logs of individual API requests are deleted after 90 days.

### Your choices

The website operator is responsible for telling you that they use TraceTail and for asking for any consent the law requires where you live. Because they are the controller, contact them first to access or delete your data; they can erase your visitor record at any time. If you contact us instead, we will pass your request to the operator and help them respond.

## 2. TraceTail customers and website visitors

### Your account

When you create an account we collect your email address and use it to send you sign-in codes and service emails. We also keep a display name derived from your email address, your API keys and the domains you register for them, and how many requests each key makes.

### Billing

If you add a card, Stripe processes your payment details. We don't receive or store your card number; we keep your Stripe customer ID, your subscription status and records of your usage and charges.

### Website analytics (Microsoft Clarity)

With your consent, we use Microsoft Clarity to understand how people use the TraceTail website. Clarity records page views, clicks, scrolling and mouse movement, and sets its own cookies. It loads only after you accept it in the analytics banner, never runs on the sign-in, dashboard or billing pages, and stays off when your browser sends a Global Privacy Control or Do Not Track signal. You can change your choice at any time: .

### Request logs

Like any website, our servers receive your IP address and request details when you visit. Our hosting provider, Cloudflare, processes this data to deliver the site and protect it from attacks. Cloudflare Web Analytics also counts page views and page load times for us; it sets no cookies and stores nothing in your browser.

### Legal bases

Where the GDPR applies, we process account and billing data to perform our contract with you, request data for our legitimate interest in running a secure service, billing records to meet legal obligations, and analytics data only with your consent.

### How long it is kept

We keep account data while your account is open. You can delete your account, with its API keys, visitor data and request history, from Settings at any time. Stripe keeps invoices for as long as tax and accounting law requires.

## 3. Cookies and local storage on tracetail.io

- `__Secure-tracetail_access` and `__Secure-tracetail_refresh`: sign-in cookies shared between tracetail.io and admin.tracetail.io. They are strictly necessary, can't be read by scripts, and expire after 15 minutes and 7 days. Older sign-ins may use `access_token` and `refresh_token`, which are replaced when you next use your account.
- `__Secure-tracetail_session`: a strictly necessary cookie lasting 8 days. It keeps older sign-in cookies from restoring a session after you sign out and can't be read by scripts.
- `tracetail:analytics-consent` (local storage): remembers your analytics choice.
- `tracetail:keyboard-shortcuts` (local storage): set only if you turn off dashboard keyboard shortcuts.
- Microsoft Clarity's cookies: only after you accept analytics.

Our fonts are served from tracetail.io itself, so viewing the site makes no requests to font providers.

## 4. Who processes data for us

| Provider                         | Purpose                                                                     | Data                                        |
| -------------------------------- | --------------------------------------------------------------------------- | ------------------------------------------- |
| Cloudflare                       | Hosting, content delivery, the database and cookieless page-view statistics | All of the data described in this policy    |
| Stripe                           | Payments                                                                    | Billing details of customers who add a card |
| Amazon Web Services (Amazon SES) | Sending email                                                               | Email addresses and message content         |
| Microsoft (Clarity)              | Website analytics, only with your consent                                   | How you use the TraceTail website           |

We don't sell personal information.

## 5. International transfers

Our providers operate worldwide, so your data may be processed outside your country, including in the United States.

## 6. Security

All traffic to TraceTail is encrypted with HTTPS. API keys only work on the domains registered for them, and sign-in cookies can't be read by scripts on the page.

## 7. Your rights

Depending on where you live, you may have the right to access, correct or delete your personal data, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time. To exercise any of these rights, email <support@tracetail.io>. We respond within one month. You also have the right to complain to your local data protection authority.

## 8. Children

TraceTail is a service for businesses and isn't directed at children.

## 9. Changes to this policy

When this policy changes, we update this page and the date at the top. See also our [Terms of Service](https://tracetail.io/terms-and-conditions).
