Privacy Policy

Version: July 29, 2026

1. Introduction

Tracergram ("we", "our", "us") operates the tracergram.com website and SaaS platform. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you visit, register for, or use our Service.

Data controller details:
Tracergram
Responsible contact: Calvin Janson
Schenkeldijk 2, 3221 LG Hellevoetsluis, The Netherlands
Dutch Chamber of Commerce (KvK): 80078346
Email: support@tracergram.com

For account, billing, website, security, and service-administration data, Tracergram generally acts as controller. When a business customer uses Tracergram to process its leads' or contacts' data, that customer generally acts as controller and Tracergram acts as processor under the Data Processing Terms in our Terms of Service.

2. Information We Collect

Account information: When you register, we collect your name, email address, and password (stored as a bcrypt hash).

Payment information: Payment processing is handled by Stripe. We do not store your credit card details. We receive your Stripe customer ID and subscription status.

Customer and conversation data: Depending on the features you configure, we process lead names, email addresses, Telegram IDs and usernames, conversation and email content, voice transcripts, attachments, pipeline status, follow-up history, and custom fields.

AI content: We process the instructions, knowledge, Q&A entries, conversation context, and other data you configure for AI agents, together with generated outputs and operational logs.

Tracking data: When visitors interact with websites using our tracking script, we collect:

Connected-service data: When you connect Telegram, email, Meta, or another supported service, we process account identifiers, authorisation credentials or tokens, and the content needed to perform the actions you request.

3. How We Use Your Information

We use the collected information to:

Where Tracergram acts as controller, our legal bases may include performance of our contract with you, compliance with legal obligations, and our legitimate interests in securing and improving the Service. Where consent is legally required, we or the relevant customer must obtain it. Where Tracergram acts as processor, we process data on the customer's documented instructions.

4. AI Data Processing

When an AI feature is used, relevant conversation content, lead data, instructions, and context may be transmitted to OpenAI for model inference. OpenAI states in its API data-controls documentation that API data is not used to train its models unless the API customer explicitly opts in. Under OpenAI's default API controls, prompts and responses may be retained in abuse-monitoring logs for up to 30 days unless longer retention is legally required or necessary to prevent harm. Different retention may apply if we enable approved retention controls or use API features that store application state.

Do not configure the Service to send passwords, payment-card data, government identifiers, health data, or other sensitive or special-category data to AI features unless you have a valid legal basis and appropriate safeguards. AI output can be inaccurate; customers are responsible for appropriate human oversight and for how they use or send it.

5. Data Sharing and Subprocessors

We do not sell personal information. We disclose data only as necessary to provide, secure, support, or legally operate the Service, including to:

Some connected platforms may act as independent controllers under their own terms and privacy notices. We may also disclose data where required by law, to protect rights and security, or in connection with a properly managed business transfer.

6. Data Security

We implement appropriate security measures including:

7. Data Retention

We retain account and Customer Data while the account is active and as needed to provide the configured Service. Tracking data such as visit logs and conversion events is generally retained for up to 12 months. Following account termination, Customer Data is scheduled for deletion within 30 days unless a longer period is required by law, needed to resolve disputes or security incidents, or contained in limited backups that expire under their normal cycle. Legal-acceptance, billing, and security records may be retained longer where necessary to establish, exercise, or defend legal claims and meet legal obligations.

8. Cookies

We use essential cookies for authentication (session tokens). Our tracking script uses Meta's standard cookie identifiers (fbc, fbp) on your visitors' browsers, which are first-party cookies set by your domain, not ours.

9. Your Rights (GDPR)

If you are located in the European Economic Area, you have the right to:

To exercise these rights for data controlled by Tracergram, contact us at the email below. For lead or contact data controlled by one of our customers, contact that customer first; we will assist the customer as required.

10. International Transfers

Our primary application data is hosted in the European Union (Hetzner, Finland). Data sent to OpenAI, Meta, Stripe, Telegram, or other connected providers may be processed outside the EEA. Where required, we rely on an adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism.

11. Children's Privacy

Our service is not intended for individuals under 16. We do not knowingly collect data from children.

12. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or a notice on our website.

13. Contact

For privacy questions or data-rights requests, contact:

Tracergram, attn. Calvin Janson
Schenkeldijk 2, 3221 LG Hellevoetsluis, The Netherlands
Dutch Chamber of Commerce (KvK): 80078346
Email: support@tracergram.com