Skip to content
Start free
Menu

Privacy policy

Last updated 2026-09-25

TraceLog captures the conversion record you declare, not the whole website. This page explains what data that involves, where it is stored, how long it is kept, and what you can do with it.

Who processes what

For visitors to tracelog.io, TraceLog is the controller of the limited data this site processes: request logs retained by its hosting provider, your language preference and, if you submit one, your demo request. The site runs no third-party scripts.

When the site measures itself, it does so with its own TraceLog project, under the same rules it offers customers: one session record per visit — referrer, campaign, device, country and landing page — and the steps of its own declared conversion path, and nothing else. TraceLog is the controller of that record too. It is first-party capture served by this site alone, and it is never shared with an advertising or analytics platform.

For events captured on a customer's website, the customer is the controller and TraceLog is the processor. The customer decides what to declare and on what legal basis capture runs; TraceLog processes it under the data processing agreement.

What is processed

TraceLog collects three categories of data from a customer's website. First, one session record per visit with its acquisition context: referrer, campaign parameters, confirmed acquisition channel or AI platform, device class, country, landing page, and start time. Second, the conversion path: each declared conversion with its stable identifier, optional value and currency, and the preceding declared steps with any context the customer chose to send. Third, beside each conversion the browser reports, which GA4, Meta and Google Ads tags the page sent requests to just before and after it: the tag's kind, its ID and, for Meta, the event the request names. The ID is the site's own account, never a visitor's, and nothing else of the request is kept.

Errors are captured only inside the conversion path. An error during checkout belongs to the conversion; one on a blog page does not.

For an account, TraceLog keeps the name, email address, authentication records and organization membership. If you choose Google Sign-In, Google provides the stable account identifier, verified email, name and profile image used for that sign-in. TraceLog does not request access to Gmail, Drive or another Google service. When an account is created with email and password, Cloudflare Turnstile checks that a person is signing up; TraceLog keeps nothing from that check.

If you request a demo, TraceLog is the controller of the site address, email address, relationship to the site, and chosen language that you provide. A person uses them to reply and agree a time for the demo.

What is not processed

  • Page views, clicks, scroll depth, mouse movement, or keystrokes
  • Session replay or any recording of the screen
  • Cross-site or cross-device identity, and any visitor's advertising identifier
  • Stored IP addresses: an address is read once when the event arrives to determine a two-letter country code, then discarded
  • Special-category data, which the product has no field for

Where it lives

In the European Union. Events and account metadata sit in one PostgreSQL database in an EU region, and the runtime is served from EU-region object storage behind a CDN. Residency is a product property, not a configuration option.

How long it is kept

Raw events are retained for thirty days, grouped by the date on which they occurred. They provide the evidence behind the product's findings.

Daily aggregates — events and sessions for each project and day, together with the evidence derived from them that decides each installation's state — are kept for every account, including Free. They require little storage, and deleting them would break the Free plan's promise.

Account and project data is kept while the account exists and deleted with it.

A demo request is deleted ninety days after it was created. Demo requests are never linked to a TraceLog account.

An invitation to join an organization holds the email address it was sent to, the role it offers, and who sent it. It expires after seven days and is deleted thirty days after it is accepted, withdrawn, or expires, whichever comes first. An invitation that is never accepted creates no account.

Cookies

This public site sets one first-party functional cookie, NEXT_LOCALE, for up to twelve months to remember whether you chose English or Spanish. It contains only that language code and is not used for analytics, advertising, or tracking.

When the site measures itself with its own TraceLog project, the capture runtime also keeps a session identifier in your browser's local storage. It is not a cookie, it is read by this site alone, it identifies the visit rather than you, and it expires with the session.

The capture code installed on a customer's site sets no tracking cookie, and no cookie of any kind. After consent is granted, a session identifier is stored in that site's browser storage. Before consent, the code creates no identifier, writes nothing to storage, and sends no network request.

Your rights

You may exercise the GDPR rights of access, correction, deletion, restriction, objection, and portability. A customer can export or delete a project's data from the application. A visitor to a customer's site should contact that customer as the controller; TraceLog will help the customer respond.

You can ask us to delete a demo request before ninety days by emailing info@tracelog.io. Otherwise it will be deleted according to the schedule above.

Email info@tracelog.io and a person from TraceLog will reply.

If you have questions about this page, email info@tracelog.io. A person from TraceLog will reply.