Privacy Policy
Version: July 29, 2026
1. Introduction
Tracergram ("we", "our", "us") operates the tracergram.com website and SaaS platform. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you visit, register for, or use our Service.
Data controller details:
Tracergram
Responsible contact: Calvin Janson
Schenkeldijk 2, 3221 LG Hellevoetsluis, The Netherlands
Dutch Chamber of Commerce (KvK): 80078346
Email: support@tracergram.com
For account, billing, website, security, and service-administration data, Tracergram generally acts as controller. When a business customer uses Tracergram to process its leads' or contacts' data, that customer generally acts as controller and Tracergram acts as processor under the Data Processing Terms in our Terms of Service.
2. Information We Collect
Account information: When you register, we collect your name, email address, and password (stored as a bcrypt hash).
Payment information: Payment processing is handled by Stripe. We do not store your credit card details. We receive your Stripe customer ID and subscription status.
Customer and conversation data: Depending on the features you configure, we process lead names, email addresses, Telegram IDs and usernames, conversation and email content, voice transcripts, attachments, pipeline status, follow-up history, and custom fields.
AI content: We process the instructions, knowledge, Q&A entries, conversation context, and other data you configure for AI agents, together with generated outputs and operational logs.
Tracking data: When visitors interact with websites using our tracking script, we collect:
- Meta click identifiers (fbclid, fbc, fbp)
- IP address (hashed for privacy)
- User agent string
- Page URL and referrer
- Timestamp of the visit
Connected-service data: When you connect Telegram, email, Meta, or another supported service, we process account identifiers, authorisation credentials or tokens, and the content needed to perform the actions you request.
3. How We Use Your Information
We use the collected information to:
- Provide and maintain our tracking service
- Match website visits to Telegram bot interactions
- Operate CRM pipelines, AI replies, translations, classifications, and automated follow-ups
- Match and extract information from connected email accounts when configured by you
- Send conversion events to Meta via the Conversions API on your behalf
- Process payments and manage subscriptions
- Send service-related emails (account verification, billing)
- Monitor and improve the security and performance of our service
Where Tracergram acts as controller, our legal bases may include performance of our contract with you, compliance with legal obligations, and our legitimate interests in securing and improving the Service. Where consent is legally required, we or the relevant customer must obtain it. Where Tracergram acts as processor, we process data on the customer's documented instructions.
4. AI Data Processing
When an AI feature is used, relevant conversation content, lead data, instructions, and context may be transmitted to OpenAI for model inference. OpenAI states in its API data-controls documentation that API data is not used to train its models unless the API customer explicitly opts in. Under OpenAI's default API controls, prompts and responses may be retained in abuse-monitoring logs for up to 30 days unless longer retention is legally required or necessary to prevent harm. Different retention may apply if we enable approved retention controls or use API features that store application state.
Do not configure the Service to send passwords, payment-card data, government identifiers, health data, or other sensitive or special-category data to AI features unless you have a valid legal basis and appropriate safeguards. AI output can be inaccurate; customers are responsible for appropriate human oversight and for how they use or send it.
5. Data Sharing and Subprocessors
We do not sell personal information. We disclose data only as necessary to provide, secure, support, or legally operate the Service, including to:
- OpenAI: AI inference, translation, classification, and related model processing.
- Hetzner: Infrastructure and hosting in Finland.
- Stripe: Payment processing and subscription administration.
- Telegram: Connected account and bot interactions.
- Meta Platforms: Conversion events and integrations configured by you.
- Email and communications providers: Verification, service email, and customer-configured mailbox connections.
Some connected platforms may act as independent controllers under their own terms and privacy notices. We may also disclose data where required by law, to protect rights and security, or in connection with a properly managed business transfer.
6. Data Security
We implement appropriate security measures including:
- Encryption of sensitive data (API tokens, access keys) at rest
- HTTPS/TLS encryption for all data in transit
- Bcrypt password hashing
- Rate limiting and brute-force protection
- Regular security audits
7. Data Retention
We retain account and Customer Data while the account is active and as needed to provide the configured Service. Tracking data such as visit logs and conversion events is generally retained for up to 12 months. Following account termination, Customer Data is scheduled for deletion within 30 days unless a longer period is required by law, needed to resolve disputes or security incidents, or contained in limited backups that expire under their normal cycle. Legal-acceptance, billing, and security records may be retained longer where necessary to establish, exercise, or defend legal claims and meet legal obligations.
8. Cookies
We use essential cookies for authentication (session tokens). Our tracking script uses Meta's standard cookie identifiers (fbc, fbp) on your visitors' browsers, which are first-party cookies set by your domain, not ours.
9. Your Rights (GDPR)
If you are located in the European Economic Area, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Data portability
- Withdraw consent at any time
- Lodge a complaint with your local supervisory authority
To exercise these rights for data controlled by Tracergram, contact us at the email below. For lead or contact data controlled by one of our customers, contact that customer first; we will assist the customer as required.
10. International Transfers
Our primary application data is hosted in the European Union (Hetzner, Finland). Data sent to OpenAI, Meta, Stripe, Telegram, or other connected providers may be processed outside the EEA. Where required, we rely on an adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism.
11. Children's Privacy
Our service is not intended for individuals under 16. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or a notice on our website.
13. Contact
For privacy questions or data-rights requests, contact:
Tracergram, attn. Calvin Janson
Schenkeldijk 2, 3221 LG Hellevoetsluis, The Netherlands
Dutch Chamber of Commerce (KvK): 80078346
Email: support@tracergram.com