Privacy Policy

Last updated: 1 June 2026

This Privacy Policy explains how TrackCrumb (“TrackCrumb”, “we”, “us”) collects, uses, shares, and protects personal data when you visit our website, create an account, or use our product analytics platform (the “Service”). It also describes the choices you have about your data.

TrackCrumb is a business-to-business product. When our customers use the Service to analyse the behaviour of their own end users, the customer is the data controller of that end-user data and TrackCrumb acts as a data processor on their behalf. This policy primarily governs data for which TrackCrumb is the controller (for example, your account and billing data).

1. Who We Are

TrackCrumb is an independent service operated from Thailand as a sole operator. A registered company is expected to assume operation of the Service in due course, at which point this section will be updated to identify that entity. Production data is hosted and processed in Singapore (see Section 6).

As the data controller, we are subject to Thailand's Personal Data Protection Act (PDPA B.E. 2562). Because data processing is carried out in Singapore, that processing is additionally subject to Singapore's Personal Data Protection Act, and we honour the rights of individuals in the EEA, UK, and elsewhere under the GDPR and comparable laws. For any privacy-related question you can reach us at the address in Section 13.

2. Data We Collect

2a. Account and Billing Data

When you register, we collect your name, email address, company name, and the password hash (we never store passwords in plain text). If you sign in with Google, we receive your Google account email and name. For paid plans, our payment processors (see Section 5) collect and tokenize your payment details; TrackCrumb stores only a customer identifier, the plan you are on, and your billing email — never full card numbers.

2b. Product Usage Data

When you instrument your application with our SDK, we collect the analytics events you choose to send (event names, properties, timestamps), pseudonymous user and session identifiers, optional session-replay recordings, feature-flag evaluations, device and browser information, and IP addresses (used for approximate geolocation and abuse prevention). The scope of this data is determined by how our customer configures the SDK.

2c. Support and Communications

If you contact us for support, respond to a survey, or correspond with us by email, we retain that correspondence and any information you provide in it.

2d. Automatically Collected Data

We collect server logs (request metadata, error traces), security and performance metrics, and limited first-party cookies needed to keep you signed in and to operate the Service. See our Cookie Policy for details. We do not use third-party advertising or cross-site tracking cookies.

Where the GDPR, the Thailand or Singapore PDPA, or similar laws apply, we rely on the following legal bases:

4. How We Use Your Data

We use personal data to:

We do not use the analytics or session-replay data our customers send us to train general-purpose machine-learning models. AI features (such as anomaly detection and churn scoring) operate on a customer's own workspace data solely to produce results for that customer.

5. Data Sharing and Sub-processors

We share personal data only with service providers who help us operate the Service, and only to the extent necessary. Our current sub-processors are:

We maintain a current list of sub-processors and will notify customers of material changes as required by our Data Processing Agreement. We may also disclose data where required by law, to enforce our agreements, or to protect the rights, property, or safety of TrackCrumb, our users, or others. If TrackCrumb is involved in a merger, acquisition, or asset sale, data may be transferred subject to this policy.

We do not sell your personal data.

6. International Data Transfers

Production data is hosted and processed in Singapore. Because we operate from Thailand, your personal data is transferred to and stored in Singapore; we rely on appropriate safeguards and the security measures described in Section 9 for that transfer, consistent with the cross-border transfer requirements of the Thailand PDPA. Some sub-processors listed above process data in other countries. Where personal data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), together with supplementary technical measures including encryption in transit and at rest.

7. Data Retention

Product analytics events are retained according to your plan's retention window (typically 30, 90, or 365 days), after which they are deleted or aggregated. Account and billing records are retained for the life of your account and for a limited period afterwards to meet legal, tax, and accounting obligations. Encrypted backups are retained for up to 30 days on a rolling basis. When you delete your account, we delete or anonymise your personal data within a reasonable period, except where retention is required by law.

8. Your Rights

Depending on your location, you may have the right to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Individuals in Thailand and Singapore have these rights under the respective PDPA and may lodge a complaint with the Personal Data Protection Committee (Thailand) or the Personal Data Protection Commission (Singapore). EEA/UK residents may also lodge a complaint with their local supervisory authority, and California residents have rights under the CCPA/CPRA, including the right to know and the right to delete.

To exercise any right, contact us at the address in Section 13. We will respond within the timeframe required by applicable law (generally within 30 days) and may need to verify your identity before acting on a request. Where TrackCrumb processes end-user data on behalf of a customer, we will direct end-user requests to the relevant customer.

9. Security

We apply technical and organisational measures appropriate to the risk, including TLS encryption in transit, encryption of sensitive fields and backups at rest, hashed passwords, optional two-factor authentication, least-privilege access controls, tenant isolation, and continuous monitoring. No method of transmission or storage is completely secure; if we become aware of a personal-data breach, we will notify affected parties and regulators as required by applicable law (for example, within 72 hours under the GDPR).

10. Cookies

For details on cookies and similar technologies, see our Cookie Policy.

11. Children's Privacy

The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Changes to This Policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you by email or in-app notice. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

13. Contact Us

For privacy questions or to exercise your rights, email us at [email protected]. As we currently operate as an individual sole operator, we do not publish a registered postal address; a registered entity and address will be added to this policy once the operating company is incorporated.

← Back to home