Privacy notice
How Trackshon handles personal data
Last updated 2026-08-27. This notice describes our practices for the hosted product at https://trackshon.com. It is written to align with the EU/UK GDPR and California CCPA/CPRA. It is not legal advice; if you need a formal DPA or transfer mechanism for your organization, contact us.
Who is responsible
The controller for the hosted Trackshon service is raeven-co (operator: Godfrey Lebo). Contact for privacy requests: the contact address shown in Admin → Providers, or our GitHub issues. Self-hosters who run their own install are the controller for that install; this notice still describes what the software is designed to store.
What we collect
Website visitors (not signed in)
- A first-party visitor id cookie (
tk_vid, up to one year) so we can tell repeat visits apart for product follow-up. - A short first-party activity log in our Postgres: path, optional product URL or idea from the public demo, referrer, user agent, and a one-way HMAC of the IP address (not the raw IP). Used to improve the product and to follow up with people who asked for access — not to sell profiles.
- If you join the waitlist or reserve a plan: email, optional product URL, and how you heard about us.
- If you use the floating Support / Feedback chat: email, optional name, message text, and (when present) the visitor id so we can keep one thread. Admin replies stay in that thread for you to read in the same widget.
Customers and workspace members
- Account email, name if provided, password hash (we never store plaintext passwords), role, and session cookie.
- Workspace profile and content you enter: product URL or idea, buyer profile, analyses, conversations, people, recommendations, events, competitor votes, content DNA, and exports you download.
- Billing: plan, subscription status, add-ons, and payment references. Card numbers are handled by Flutterwave or Paystack (whichever is enabled for the install); we do not store full card data.
- Workspace cookie (
tk_ws) remembering which workspace you last used.
People Trackshon finds in public conversations
For a person who posted publicly about a problem a founder solves, we may store: public handle, display name, company, location and bio from that platform’s public profile, a website or X handle they listed there, and an email only if they published it themselves on that profile. LinkedIn, Facebook and Instagram are not scraped — we may show a search link only. We do not buy lists or enrich from data brokers.
Purpose: so a founder can answer a public question in public. Trackshon never posts, emails or DMs anyone on its own; every reply is sent by the founder from their own account.
Why we process it (legal bases)
- Contract — providing the signed-in workspace, scout, drafts, billing and support you asked for.
- Legitimate interests — securing the service, preventing abuse, understanding how the marketing site and demo are used (visitor id + hashed IP), and listing public conversation authors so founders can reply in public. You may object (see rights below).
- Consent — where you voluntarily submit email (waitlist, reserve, support chat) or where local cookie law requires consent for non-essential cookies. You can withdraw by clearing cookies or emailing us.
- Legal obligation — retaining limited billing and security records when required.
Cookies
We do not load third-party analytics or ad pixels. Fonts are served from this site. First-party cookies:
tk_vid— visitor id for marketing/demo follow-up (up to 1 year). Clear site cookies or use a private window to stop it; ask us to unlink your email from a visitor id if you left one.session(signed) — keeps you signed in (about 30 days). Cleared on sign-out.tk_ws— last workspace slug (up to 1 year while signed in).
Support chat also stores your email and thread id in your browser’s localStorage so you can see admin replies on return. Clear site data to remove it.
Processors and sharing
We do not sell personal information and we do not share it for cross-context behavioral advertising. We use service providers who process data on our instructions:
- Hosting and database (for example Vercel and Postgres/Neon for the hosted install).
- AI model and search providers configured for the install or workspace (for example Anthropic or others you assign) — only the text needed for that request (page extract, public thread, your profile). Under typical API terms this is not used to train public models; bring-your-own-key customers control their own vendor contract.
- Payment providers: Flutterwave and/or Paystack when payments are enabled.
- Email delivery if configured for invites, resets and digests.
We may disclose data if required by law or to protect the security of the service or individuals.
International transfers
The hosted product may process data in the United States, the European Economic Area, the United Kingdom, or other regions where our subprocessors operate. Where GDPR applies to a transfer, we rely on appropriate safeguards used by those providers (such as Standard Contractual Clauses) and minimize what is sent.
How long we keep it
- Account and active workspace data — while the account is open, then deleted or anonymized after you ask (usually the same day for workspace content).
- Marketing activity log — kept for product and sales follow-up; older rows may be pruned; ask and we delete or anonymize yours.
- Support / feedback threads — while the conversation is open, then for a limited period for quality and abuse prevention unless you ask us to delete sooner.
- Conversations marked noise or never acted on — deleted after about 60 days; people a founder dismissed — after about 30 days.
- Billing records — as long as needed for accounting and disputes.
Your rights (GDPR / UK GDPR)
If you are in the EEA, UK or a similar jurisdiction, you may request: access, correction, deletion, restriction, portability, and objection to processing based on legitimate interests. Where we rely on consent, you may withdraw it. You may lodge a complaint with your local supervisory authority. Workspace customers can export their data as JSON from Settings anytime.
Your rights (California — CCPA / CPRA)
We collect the categories above (identifiers, commercial/subscription info, internet activity on our site, professional information from public profiles). We do not sell personal information and we do not share it for cross-context behavioral advertising as those terms are defined under California law. California residents may request to know, delete, or correct personal information we hold, and are not discriminated against for exercising those rights. Authorized agents may submit requests with proof of authority. Contact the contact address shown in Admin → Providers, or our GitHub issues with the subject “California privacy request”.
If Trackshon listed you from a public post
Tell us (below) and we blank every field the same day across workspaces we control on the hosted product. Include the URL of the public post or your handle so we can find the rows.
Children
Trackshon is for business users. We do not knowingly collect personal information from children under 16. If you believe we have, contact us and we will delete it.
Security
Passwords are hashed. Provider API keys are encrypted at rest. Sessions are signed. Access to admin tools is limited to the install operator. No method of transmission or storage is perfectly secure; report issues via the contact address shown in Admin → Providers, or our GitHub issues or GitHub.
Changes
We will update this page when practices change and revise the “Last updated” date. Material changes for customers will also be noted in-product or by email when appropriate.
How to reach us
Privacy, deletion, access, or “do not sell/share” requests: the contact address shown in Admin → Providers, or our GitHub issues. You can also open an issue at github.com/raeven-co/trackshon, use the Support widget on this site, or reply to any message from us.
Operator: raeven-co · Godfrey Lebo.