Privacy Policy

What we collect, why, how long we keep it, who receives it, where it is stored, and how to control it.

Last updated: 7 October 2026

At a glance

  • Two roles. We are the controller for data about our own customers and our own website. We are a processor for the data our customers collect about their website visitors, and we handle it only on their instructions under our Data Processing Addendum.
  • First-party only. Visitor identifiers are kept per website (or per group of one customer’s own linked websites) and are never shared between different companies’ websites. We do not track people across sites, and we do not sell personal data.
  • Privacy signals are respected. Do Not Track and Global Privacy Control stop the tracking script before it stores or sends anything.
  • Ad platforms receive data only when a customer connects them. Contact details are hashed before they are sent.
  • Data is stored in the European Union. Our providers are listed on our Subprocessors page.

1. Who we are and our two roles

SourceTrack (www.sourcetrack.ai) is a marketing attribution service. It shows a business which marketing sources lead to sign-ups, leads and revenue on its website. It is operated by Abaid Ur Rehman, a self-employed trader (autónomo) based in Tarragona, Spain, whose full identification details (tax ID and postal address) are in our Legal Notice. You can reach us at support@sourcetrack.ai. We have not appointed a data protection officer. Privacy questions go to the same address.

  • Controller. We decide how data is used for our customers’ accounts, billing and support, for people who contact us, and for visitors to our own website (sections 2 and 3).
  • Processor. When a customer installs our tracking script or connects a data source, the customer is the controller of the data collected about its visitors, leads and buyers. We process that data only to provide the service, on the customer’s instructions, under our Data Processing Addendum (sections 4 to 7). If you are a visitor to a customer’s website, that website’s owner decides how your data is used, and its own privacy notice applies. We help the owner respond to your requests (section 12).

2. Data about you as a customer

CategoryWhat it includesWhy we use itLegal basis (GDPR Art. 6)
Account dataEmail address, name if you give one, sign-in details, workspace and site settings, team members you invite. If you sign in with Google, we receive your name, email address and profile picture from Google.To create and run your accountContract
Billing dataPlan, billing status, invoices and Stripe identifiers. Stripe handles card payments. We never see or store your card number.To charge for the service and keep accounting recordsContract; legal obligation
Integration dataThe connections you authorise (for example Google, Meta, Shopify), their encrypted access tokens, and the data they returnTo provide the features that depend on themContract
CommunicationsMessages you send us; service emails such as sign-in links, reports and usage alertsTo support you and run the serviceContract; legitimate interests
Usage and service logsTechnical logs, request metadata such as IP address and browser, and error diagnosticsTo keep the service secure, prevent abuse and fix errorsLegitimate interests
Marketing emailsYour email address, if you sign up for our newsletterTo send product newsConsent, which you can withdraw at any time

You need to give us an email address to create an account. Everything else is optional, although some features need it. We do not use your account data for advertising on other websites, and we do not sell it.

3. Our own website (www.sourcetrack.ai)

  • Cookie notice. Google Tag Manager (which loads measurement and advertising tags) and our own tracking script load only after you click Accept. Until you choose, and if you click Reject, neither loads. If your browser sends Do Not Track or Global Privacy Control, we treat that as Reject. You can change your choice at any time with “Cookie settings” in the footer. Your choice is stored in your browser’s local storage. The notice does not set a cookie. See our Cookie Policy.
  • Forms. If you use our contact form, newsletter or free audit report, we receive the details you enter (such as your name, email address, phone number and message). We use them only to answer you or send what you asked for, and keep them only for as long as we need them for that.
  • The dashboard (the signed-in app) uses browser storage to keep you signed in and to remember your preferences. It does not load advertising tags.

4. Visitor data we process for customers

When a customer installs our tracking script on its website, or connects a payment, store or form provider, we process the following on the customer’s behalf.

  • Events and pages. Page views, page URLs, page titles, referrers (including referrals from AI assistants, where we see only the referring website), engagement events such as scrolling and outbound clicks, and custom events the website defines. Sensitive values in page URLs, such as email addresses or access tokens, are removed automatically.
  • Campaign and click data. UTM parameters and advertising click identifiers (for example from Google, Meta, Microsoft, TikTok and LinkedIn), and the time of the click.
  • Device, browser and location. Browser, device type and operating system, country derived from the IP address (section 5), and whether the browser reports being automated, which we use only to filter bots.
  • Online identifiers. A random visitor identifier and a session identifier (section 6). Where the website enables it, a device identifier derived from the IP address and browser information. It is kept per website, never shared between different companies’ websites, and never sold or sent to advertising platforms. For visitors in the European Union, the European Economic Area, the United Kingdom or Switzerland, or whose country cannot be determined, it is used only after the visitor gives consent through the website’s consent tool. Elsewhere it is used by default, and the visitor can opt out. Do Not Track, Global Privacy Control, an opt-out or withdrawn consent stops it, and a refusal or withdrawal deletes the stored identifiers.
  • Conversions, orders and revenue. Sign-ups, purchases, bookings and form submissions, with their type, value and currency, and order and subscription details from Stripe, Shopify or other sources the customer connects, or that it sends from its own server.
  • Contact details the website sends. If the website tells us who a visitor is (for example after a sign-up), or a checkout or form provider sends them with a conversion, we store the identifier it gives us and, if sent, the person’s name, email address and phone number. They are linked to that visitor’s activity on that website only. Where the website turns it on, the script can also read the name, email address, phone number and company name entered in a form when it is submitted, never passwords, payment card fields or free-text areas. It does not do this if the visitor has refused consent, and where the website requires consent first, it waits until the visitor gives it.
  • Optional recognition features. Where the website enables them and only after the visitor consents (for device recognition, through a separate consent), a returning device can be recognised on the same website from a small set of general browser settings that are hashed in the browser, and a visitor can be linked to their email address through a hash of it. These are never used across different companies’ websites or sent to advertising platforms.
  • Other data the customer chooses to collect. Post-purchase survey answers, and lead status and notes added by the customer’s team.

We do not build profiles across different companies’ websites. Customers must not send us special categories of data, such as health data, or payment card numbers (see our Terms).

5. IP addresses

When an event arrives, we use the visitor’s IP address to determine the country, to filter bots and abuse, and to derive the identifiers described in sections 4 and 6. We do not store raw IP addresses in our event database. Page view events can also carry a short value derived from the IP address, the website and a random value that we replace every day. We use it only to measure automated traffic. It cannot be turned back into the IP address or matched across days or across different companies’ websites.

There are three exceptions, where the IP address is kept or sent outside our event database:

  • Conversion forwarding. When a customer turns on conversion forwarding to an advertising platform, the conversion sent to that platform can include the visitor’s IP address and browser information, because the platforms use them to match conversions (section 7).
  • Conversions waiting for confirmation. A conversion reported by the browser can be held until the payment provider confirms the order. Held conversions are kept for 72 hours and are deleted within a day after that. They can contain the IP address, browser information and any contact details sent with the conversion.
  • Meta retry. If sending a conversion to Meta fails for a temporary reason, we keep it, encrypted, for up to 24 hours, only to retry the failed delivery. It can contain the IP address. It is deleted as soon as it is delivered, when the error turns out to be permanent, when the visitor’s consent or eligibility no longer allows sending, when the customer disconnects Meta, or after 24 hours. The IP address is kept this way for Meta only.

6. Cookies and browser storage

This section describes the tracking script our customers install. Cookies and storage on our own website and app are in our Cookie Policy.

Our script uses first-party cookies and local and session storage on the customer’s own website, never third-party cookies. It uses them to recognise returning visitors, remember the first marketing source and click identifiers, hold the visitor’s consent or opt-out choice, and retry events that failed to send. Cookies last one year by default, or up to about 13 months (400 days) where a longer lifetime is turned on, and browsers may shorten that. Other stored values last until the visitor clears site data, opts out or withdraws consent.

  • Managed tracking domain. If the customer serves the script from a tracking domain we manage on its own website, that domain also sets a first-party cookie holding the visitor identifier. It is not set in Cookieless Mode, when analytics consent is denied, or when the browser sends Do Not Track or Global Privacy Control.
  • Advertising platform identifiers. When a conversion happens, the script can read identifiers that a platform’s own pixel has already set on the website (for example Meta’s and OpenAI’s). It passes each only to the platform that set it, only if the customer has connected that platform, and not when advertising consent is denied.
  • Links between a customer’s own domains. If the customer links several of its own domains, a short-lived token carrying the visitor identifier is added to links between them so the same visitor is recognised. It is tied to that customer and is removed from the address bar once read.
  • Cookieless Mode (a setting the customer can turn on) sets no cookies and keeps no visitor identifier on the device. Our server instead calculates a visitor identifier that changes every day, so a visitor cannot be followed across days or across different companies’ websites. The script may still keep consent choices and click identifiers in local storage.
  • Consent and privacy signals. If a visitor’s browser sends Do Not Track or Global Privacy Control, the script stops before storing anything or sending any event. A website can configure the script to wait for consent first, and the script honours Google Consent Mode v2 signals. An opt-out or withdrawal of consent deletes the script’s stored identifiers from the browser. Customers are responsible for their own cookie notices and for obtaining consent where the law requires it.
  • Region-based consent (optional). The script asks our server which consent rule applies to the visitor’s country, determined from the IP address. Our server applies the same rule before forwarding conversions to advertising platforms.

7. Advertising and analytics platforms you connect

All integrations are optional. The customer chooses which to connect and can disconnect at any time. When the website connects advertising or analytics platforms such as Meta, Google, Microsoft, TikTok, LinkedIn or OpenAI, we send conversion data to them on the customer’s behalf. This can include the visitor’s IP address, browser information and identifiers, and the order value. Contact details such as email addresses are hashed before they are sent. Our script reports nothing from a browser that sends Do Not Track or Global Privacy Control, and where region-based consent is on, we do not forward conversions from visitors who have not given consent where it is required. Purchases that a store, payment or form provider reports to us directly from its own server do not pass through the visitor’s browser, so a browser signal may not reach them; the website owner decides whether those are forwarded. Each platform handles what it receives under its own terms and privacy policy and is an independent controller of it.

We also read data from the platforms a customer connects, only to provide the features shown in the SourceTrack app: Google Ads accounts you authorise (daily campaign names, cost, clicks, impressions and currency), Google Search Console performance data (read-only; revenue by search query is an estimate, not an exact match of a query to a customer), Google Tag Manager container and tag settings (read-only, to check the SourceTrack tag is installed; we never change anything in your account), and advertising spend, orders, refunds and payments from Meta Ads, Shopify and Stripe.

If you set up outbound webhooks, Slack or other alert destinations, scheduled email reports, public report links, the developer API, or an AI assistant connected through our MCP server, we send the data you choose to that destination, where it is handled under that destination’s terms.

How we treat Google user data. We use data received from Google only to provide and improve the user-facing features in SourceTrack that depend on it. We do not sell it, use it for advertising or retargeting, or use it to train AI or machine-learning models. We do not transfer it to others, except to provide the feature you asked for, to keep the service secure or investigate abuse, to comply with law, or as part of a merger or sale after notifying you. Our staff do not read it, except when you ask for support, to investigate security or abuse, or when the law requires it. We encrypt the access and refresh tokens you authorise and store all data in the European Union. SourceTrack’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting. Disconnecting an integration deletes the stored credentials straight away. You can also revoke access from your Google Account permissions page. Data already imported stays in your workspace until you delete it or the workspace; ask us at support@sourcetrack.ai to remove it sooner. If you connect an account you do not own (for example as an agency), you must have the owner’s written permission first (see our Terms).

  • Contract: to provide the service you signed up for (account, workspace, integrations, billing and support).
  • Legitimate interests: to keep the service secure, prevent abuse and fraud, filter bots, fix errors and understand how the product is used. You can object to this processing (section 12).
  • Consent: for marketing emails and for the cookies and tags on our own website. You can withdraw consent at any time, and that does not affect processing that happened before.
  • Legal obligation: for example tax and accounting records, and answering lawful requests from authorities.

For visitor data we process for customers, the customer decides the legal basis and gives visitors the notices the law requires, including any consent needed for browser storage and for sharing with advertising platforms.

9. Who receives data

  • Subprocessors that host and run the service, listed with their location on our Subprocessors page. They act only on our instructions, under written data protection terms.
  • Advertising and analytics platforms a customer chooses to connect (section 7), as independent controllers.
  • Destinations a customer sets up, such as webhooks, alert channels, report recipients and connected AI assistants.
  • Authorities, courts or professional advisers, when the law requires it or to establish or defend legal claims.
  • A buyer or successor, if the service is ever sold or transferred, after we notify you.

We do not sell personal data, and we never share visitor identifiers between different companies’ websites.

10. Where data is stored and international transfers

Core data is stored in the European Union: our database in Ireland, our analytics event store in Germany, and application hosting in the Netherlands. Some subprocessors (for example Stripe, our email provider, our error-monitoring provider and content delivery networks) may process limited data outside the European Economic Area. Where they do, we rely on an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) or on the European Commission’s Standard Contractual Clauses. You can ask us for a copy of the relevant safeguards at support@sourcetrack.ai. Advertising platforms that a customer connects may process the data they receive in other countries, under their own terms.

11. How long we keep data

DataRetention
Visitor events (page views, sessions and other events)For the data retention period of the workspace’s plan when the event was recorded (400 days on Free; up to 1,095 days on Starter and Growth, including the trial; up to 1,825 days on Scale), then deleted automatically
Do Not Track and Global Privacy Control counts, and automated traffic and crawler recordsUp to 400 days, with no visitor identifier
Attribution records, identity links, contact details a website sends, survey answers, lead notes, delivery logs and failed webhook deliveriesFor the data retention period chosen in the workspace (from 30 days up to the plan maximum, 365 days on Free, 1,095 days on Starter and Growth, 1,825 days on Scale). Where none has been chosen, they may be kept until they are deleted or the workspace is deleted.
Device identifiers and device-recognition values (where enabled)Up to about 13 months
Conversions held for payment confirmation72 hours, then deleted within a day
Conversions waiting to be resent to an advertising platformUp to 24 hours, encrypted
Integration credentialsUntil you disconnect, or delete the workspace
Account and workspace dataUntil you delete your account or workspace
Billing recordsFor as long as tax and accounting law requires
Service and error logsFor the period our hosting and error-monitoring providers keep logs, then deleted automatically

Deleting a workspace permanently deletes its sites, events, attribution data, identity data and integration credentials. An individual visitor can also be erased at any time (section 12). After an erasure, we block the same visitor’s data from being stored again.

12. Your rights

Under the GDPR and the UK GDPR, you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time. Write to support@sourcetrack.ai. We may need to confirm your identity first. We respond within one month, and we will tell you if we need up to two more months for a complex request.

  • Customers: you can delete your account and workspace in the app, export your workspace data, erase an individual visitor and answer a visitor’s access request through our privacy tools, or by contacting us.
  • Website visitors: to exercise your rights over data collected on a customer’s website, contact that website’s owner, who is the controller. If you contact us, we will pass your request to the owner and help them respond. You can also stop collection straight away with Do Not Track or Global Privacy Control, by refusing or withdrawing consent in the website’s consent tool, or by clearing that website’s data in your browser.
  • Complaints: you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos, or to the authority where you live or work.

US state privacy laws (including California). For visitor data, we act as the customer’s service provider or processor. When a customer turns on conversion forwarding, the disclosure to advertising platforms is made at the customer’s direction, and under some state laws it may count as the customer “sharing” personal information, so the customer is responsible for offering the opt-out. Our script treats Global Privacy Control as an opt-out. We do not sell personal information. On our own website, advertising tags that load after you click Accept may count as “sharing” under some state laws; Reject or Global Privacy Control stops them. Our Do Not Sell or Share page explains more. To exercise your rights over our own customer or website data, email support@sourcetrack.ai with the subject “US privacy request”. We do not discriminate against anyone for exercising these rights.

13. Security

We protect data with encryption in transit and encryption of integration secrets at rest, tenant isolation, signed outbound webhooks, rate limiting, protection against server-side request forgery, and limited staff access. See our Security page. If we become aware of a personal data breach that affects data we control, we will notify the Spanish data protection authority within 72 hours where required, and affected people without undue delay. For customer workspace data, we notify the customer without undue delay.

14. Automated decision-making

We do not make decisions that have legal or similarly significant effects on anyone based solely on automated processing. Attribution reports assign marketing credit to sources using statistical rules, and some matches, such as device identifiers, are labelled as likely rather than certain. These reports are about marketing performance, not decisions about individuals.

15. Children

SourceTrack is a business service and is not directed at children. We do not knowingly collect personal data from children. Customers must not use SourceTrack on websites directed at children under 16 without meeting the legal requirements that apply to them.

16. Changes to this policy

We will post changes here and update the date above. If a change materially affects how we use your data, we will notify customers by email or in the app before it takes effect. We will ask for your consent before using Google user data in a new way.

17. Contact

support@sourcetrack.ai: for privacy questions and to exercise your rights. The operator’s identification details and postal address are in our Legal Notice.