Security

How we protect customer data, and what we do not claim.

Last updated: 7 October 2026

This page describes the technical and organisational measures we apply to customer data. It forms Annex II to our Data Processing Addendum.

Where data lives

Core data is stored in the European Union: the database in Ireland, the analytics event store in Germany, and application hosting in the Netherlands. The full list of providers and locations is on our Subprocessors page. EU storage is a fact about where data sits, not a certification.

Encryption

  • Data is encrypted in transit: all traffic to SourceTrack uses HTTPS.
  • Integration credentials, such as the access tokens you authorise, are encrypted at rest.
  • Card numbers are handled by Stripe only. We never see or store them.

Access control and workspace separation

  • Each workspace can only read its own data. This is enforced in the database and again in our application code.
  • The public site key in your tracking snippet can only send events. Reading data always requires a signed-in user who belongs to the workspace.
  • Our staff do not read customer workspace data except when a customer asks for support, to investigate a security or abuse issue, or when the law requires it. Staff access is limited.

Integrations

  • Google and Meta connections use OAuth, and you can revoke access at any time from the provider’s own settings as well as from SourceTrack. Search Console access is read-only.
  • Payment webhooks from Stripe and Shopify are verified before any data is used, and webhooks we send to you are signed so your endpoint can check who sent them.
  • Disconnecting an integration deletes its stored credentials straight away.

Monitoring and abuse protection

  • We monitor the service for errors and abuse.
  • Routes that accept data are rate limited, known automated traffic is filtered, and addresses you give us for webhooks are checked so they cannot be used to reach internal systems.

Privacy controls built in

  • The tracking script stops when it sees Do Not Track or Global Privacy Control.
  • Sensitive values such as email addresses, phone numbers and tokens are removed from page URLs when events arrive.
  • We provide tools to erase a single visitor, to answer a data access request, and to delete a whole workspace.

Incident response

If we become aware of a personal data breach, we notify affected customers without undue delay so they can meet their own obligations. For data we control, we notify the data protection authority within 72 hours where the law requires it, and affected people where the law requires it.

What we do not claim

We do not currently hold SOC 2 or ISO 27001 certification, and we do not claim either. We do not claim to be “GDPR certified”, because no such certificate exists. What we can tell you is written on this page, our Privacy Policy and our Data Processing Addendum.

Reporting a vulnerability

Email support@sourcetrack.ai with the subject “Security”. Please give us reasonable time to fix an issue before you disclose it publicly, and do not access other customers’ data while testing.