Privacy Policy
Last updated: 1 June 2026
This Privacy Policy explains how TrackCrumb (“TrackCrumb”, “we”, “us”) collects, uses, shares, and protects personal data when you visit our website, create an account, or use our product analytics platform (the “Service”). It also describes the choices you have about your data.
TrackCrumb is a business-to-business product. When our customers use the Service to analyse the behaviour of their own end users, the customer is the data controller of that end-user data and TrackCrumb acts as a data processor on their behalf. This policy primarily governs data for which TrackCrumb is the controller (for example, your account and billing data).
1. Who We Are
TrackCrumb is an independent service operated from Thailand as a sole operator. A registered company is expected to assume operation of the Service in due course, at which point this section will be updated to identify that entity. Production data is hosted and processed in Singapore (see Section 6).
As the data controller, we are subject to Thailand's Personal Data Protection Act (PDPA B.E. 2562). Because data processing is carried out in Singapore, that processing is additionally subject to Singapore's Personal Data Protection Act, and we honour the rights of individuals in the EEA, UK, and elsewhere under the GDPR and comparable laws. For any privacy-related question you can reach us at the address in Section 13.
2. Data We Collect
2a. Account and Billing Data
When you register, we collect your name, email address, company name, and the password hash (we never store passwords in plain text). If you sign in with Google, we receive your Google account email and name. For paid plans, our payment processors (see Section 5) collect and tokenize your payment details; TrackCrumb stores only a customer identifier, the plan you are on, and your billing email — never full card numbers.
2b. Product Usage Data
When you instrument your application with our SDK, we collect the analytics events you choose to send (event names, properties, timestamps), pseudonymous user and session identifiers, optional session-replay recordings, feature-flag evaluations, device and browser information, and IP addresses (used for approximate geolocation and abuse prevention). The scope of this data is determined by how our customer configures the SDK.
2c. Support and Communications
If you contact us for support, respond to a survey, or correspond with us by email, we retain that correspondence and any information you provide in it.
2d. Automatically Collected Data
We collect server logs (request metadata, error traces), security and performance metrics, and limited first-party cookies needed to keep you signed in and to operate the Service. See our Cookie Policy for details. We do not use third-party advertising or cross-site tracking cookies.
3. Legal Basis for Processing
Where the GDPR, the Thailand or Singapore PDPA, or similar laws apply, we rely on the following legal bases:
- Performance of a contract — to create your account, provide the Service, and process payments.
- Legitimate interests — to secure the Service, prevent abuse, improve our product, and communicate operational information. We balance these interests against your rights and freedoms.
- Consent — for optional marketing emails and any non-essential cookies. You may withdraw consent at any time.
- Legal obligation — to comply with tax, accounting, and other applicable laws.
4. How We Use Your Data
We use personal data to:
- provide, maintain, and secure the Service;
- authenticate you and manage your account and workspace;
- process subscriptions, invoices, and payments;
- respond to support requests and send service-related notices;
- monitor for fraud, abuse, and security incidents;
- analyse aggregate, de-identified usage to improve the product; and
- send marketing communications where you have opted in.
We do not use the analytics or session-replay data our customers send us to train general-purpose machine-learning models. AI features (such as anomaly detection and churn scoring) operate on a customer's own workspace data solely to produce results for that customer.
5. Data Sharing and Sub-processors
We share personal data only with service providers who help us operate the Service, and only to the extent necessary. Our current sub-processors are:
- Stripe — payment processing (USA / global).
- LemonSqueezy — merchant of record for EU/UK/AU payments and VAT/GST handling (USA).
- Resend — transactional and notification email delivery (USA / EU).
- Cloudflare — CDN, DDoS protection, and object storage for backups and session-replay assets (global edge).
- Contabo — virtual private server hosting for the application and databases.
- OpenRouter — large-language-model inference for AI features (USA).
We maintain a current list of sub-processors and will notify customers of material changes as required by our Data Processing Agreement. We may also disclose data where required by law, to enforce our agreements, or to protect the rights, property, or safety of TrackCrumb, our users, or others. If TrackCrumb is involved in a merger, acquisition, or asset sale, data may be transferred subject to this policy.
We do not sell your personal data.
6. International Data Transfers
Production data is hosted and processed in Singapore. Because we operate from Thailand, your personal data is transferred to and stored in Singapore; we rely on appropriate safeguards and the security measures described in Section 9 for that transfer, consistent with the cross-border transfer requirements of the Thailand PDPA. Some sub-processors listed above process data in other countries. Where personal data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), together with supplementary technical measures including encryption in transit and at rest.
7. Data Retention
Product analytics events are retained according to your plan's retention window (typically 30, 90, or 365 days), after which they are deleted or aggregated. Account and billing records are retained for the life of your account and for a limited period afterwards to meet legal, tax, and accounting obligations. Encrypted backups are retained for up to 30 days on a rolling basis. When you delete your account, we delete or anonymise your personal data within a reasonable period, except where retention is required by law.
8. Your Rights
Depending on your location, you may have the right to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Individuals in Thailand and Singapore have these rights under the respective PDPA and may lodge a complaint with the Personal Data Protection Committee (Thailand) or the Personal Data Protection Commission (Singapore). EEA/UK residents may also lodge a complaint with their local supervisory authority, and California residents have rights under the CCPA/CPRA, including the right to know and the right to delete.
To exercise any right, contact us at the address in Section 13. We will respond within the timeframe required by applicable law (generally within 30 days) and may need to verify your identity before acting on a request. Where TrackCrumb processes end-user data on behalf of a customer, we will direct end-user requests to the relevant customer.
9. Security
We apply technical and organisational measures appropriate to the risk, including TLS encryption in transit, encryption of sensitive fields and backups at rest, hashed passwords, optional two-factor authentication, least-privilege access controls, tenant isolation, and continuous monitoring. No method of transmission or storage is completely secure; if we become aware of a personal-data breach, we will notify affected parties and regulators as required by applicable law (for example, within 72 hours under the GDPR).
10. Cookies
For details on cookies and similar technologies, see our Cookie Policy.
11. Children's Privacy
The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you by email or in-app notice. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
13. Contact Us
For privacy questions or to exercise your rights, email us at [email protected]. As we currently operate as an individual sole operator, we do not publish a registered postal address; a registered entity and address will be added to this policy once the operating company is incorporated.