How TraceLog protects access to your data
TraceLog collects only what its figures need, keeps each customer’s data apart and keeps raw events for thirty days.
Current controls
Account and project separation
Queries on a project’s data carry its identifier, and access paths are tested against reading another customer’s data. A client contact sees one project.
Credentials and temporary links
Passwords and server keys are stored so they cannot be read back. Secrets are shown once; temporary links are hashed and expire.
Network boundaries
Browser ingestion checks the project's allowed origins. Authentication, ingestion and sensitive query endpoints apply request limits.
Retention and operational access
Raw events are kept for thirty days. Every operator read of an account records who and why.
What TraceLog collects
The declared conversion path, and the acquisition context its figures need.
What TraceLog needs
The sessions, declared steps and conversions it receives.
Acquisition context needed for supported segment comparisons.
Daily counts and the evidence behind alerts and findings.
What it leaves out
No session replay, screen recording, keystrokes or mouse movement.
No stored IP addresses or visitor advertising identifiers.
No analytics or advertising account credentials.
No secrets, credentials or raw payloads in application logs.
For the complete data and contractual detail, read Privacy and data and the Data Processing Agreement.