TracePoint
FeaturesHow it worksPricingFAQContact
Log inGet started free

Privacy Policy

Last updated: August 8, 2026

1. Overview

TracePoint helps you attribute leads on your own website to marketing channels. This policy covers three kinds of data: data about your website's visitors, collected through our tracking snippet; data about you, our customer, collected when you create and use a TracePoint account; and data about visitors to this marketing website, gettracepoint.com itself.

2. Data collected from your site's visitors

When someone submits a tracked form on your site, our snippet records only marketing attribution metadata:

  • Channel, source, medium, campaign, and landing page (derived from the URL/UTM parameters that brought the visitor to your site)
  • The page URL and referrer at the time of submission
  • A randomly generated lead reference and a timestamp

We deliberately never collect or store names, email addresses, phone numbers, or any other message content from your forms. The snippet only detects that a submission happened — it doesn't read the values of your form's fields.

3. Cookies (on sites running our tracking snippet)

The tracking snippet sets two first-party cookies on your domain, used only to remember attribution across a visitor's session:

  • First-touch attribution cookie — set once, on a visitor's first visit, and never overwritten, so we can credit the channel that originally brought them to your site.
  • Last-touch attribution cookie — updated on every visit, reflecting the most recent channel.

Both cookies expire after 90 days and store only the attribution fields listed above — never form content or other personal information.

4. Analytics on this website

This marketing website (gettracepoint.com) itself uses Firebase Analytics (built on Google Analytics) to understand traffic and which pages visitors find useful — separate from, and unrelated to, the tracking snippet described above, which only runs on customer sites. Firebase Analytics may set its own cookies/identifiers in your browser and can share data with Google per Firebase's privacy documentation. We use it in aggregate only, to see what's working on this site — not to identify individual visitors.

5. Data collected about you (our customer)

When you create a TracePoint account, we store:

  • Your email address (from your login)
  • Your account/business name, once you set one
  • Your plan and a Stripe customer reference, if you subscribe to a paid plan

Payment details (card numbers, etc.) are handled entirely by our payment processor, Stripe — we never see or store your card information. See Stripe's Privacy Policy for how they handle it.

6. How we use this data

  • To show you the attribution dashboard and reports for your own sites
  • To enforce your plan's site and lead limits
  • To bill you for paid plans, via Stripe
  • To deliver leads to your own systems, if you configure a webhook
  • To maintain the security and reliability of the Service (e.g. rate limiting)
  • To understand traffic to this marketing website, via Analytics

7. Who we share data with

We share data only where it's necessary to run the Service:

  • Stripe, for billing and payment processing
  • Google/Firebase, for marketing-website Analytics (see Section 4)
  • Your own configured webhook endpoint, if you set one up — you control where that data goes
  • Infrastructure providers (hosting, database) who process data on our behalf to run the Service, not for their own purposes

We do not sell visitor or customer data to third parties.

8. Data retention

Lead attribution data is retained for as long as your site and account exist. If you delete a site, its leads are no longer accessible through the dashboard. If you request account deletion, our team reviews and processes that request rather than deleting everything instantly — this protects against accidental data loss while an active subscription or records you may still need are involved.

9. Your rights and choices

You can view and export your leads at any time from your dashboard. You can request deletion of your account from your account settings. For any other request — including data access or correction requests — contact us at privacy@gettracepoint.com.

10. Security

Your account and site data is only ever written by our backend services, never directly by a client application — our database access rules deny direct read/write access by default and only your own account's data is exposed back to you.

11. Children's privacy

The Service is intended for business use and is not directed at children. We don't knowingly collect personal information from children.

12. International data transfers

Your data may be processed in countries other than your own by our infrastructure and payment providers. We do not currently commit to a specific data-residency region — if your organization requires one, contact us before relying on the Service.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date above.

14. Contact

Questions about this policy? Contact us at privacy@gettracepoint.com.

TracePoint

Marketing attribution for real leads, not last-click guesswork.

FeaturesPricingFAQContactLog in

© 2026 TracePoint. All rights reserved.

Terms and ConditionsPrivacy PolicyRefund Policy