Privacy Policy
Last updated: 10 October 2026 (the German version is legally binding)
This privacy policy has two parts:
- Part A explains how personal data is processed when you visit trackd.one and use a customer account. For this, we are the controller.
- Part B informs visitors of websites and users of apps that use trackd.one as an analytics service. There we process data on behalf of the respective website or app operator, who is the controller.
Part A — trackd.one (website and customer account)
In this part we are the controller within the meaning of Art. 4(7) GDPR.
Controller
Eduard Ditler, trading as Mignuti Media, Pfarrer-Mengesstr. 5, 56112 Lahnstein, Germany
Email: trackdone@mignuti.com
Further details can be found in the imprint.
Data protection officer
No data protection officer has been appointed, as the legal requirements for this (Art. 37 GDPR, Section 38 BDSG) are not met. For privacy questions please contact trackdone@mignuti.com.
Visiting the website and hosting
The trackd.one website and dashboard are delivered via the infrastructure of Cloudflare, Inc. (Cloudflare Workers, Workers Assets, Cloudflare D1 database). When you visit, technically necessary data is processed: IP address, date and time, requested URL, HTTP status code, amount of data transferred, referrer, and browser and operating system information (user agent).
Purposes: delivering the website, security (e.g. defending against attacks and abuse) and error analysis. For rate limiting, the IP address is processed only transiently in memory within windows of at most 60 seconds and is not stored.
Technical logs (Cloudflare Workers Logs) are kept for at most 7 days and then deleted automatically. Our own log output does not contain email addresses, URLs or response bodies.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable and error-free provision of our service.
We do not use any analytics, marketing or advertising tools on the trackd.one website itself — not even trackd.one.
Customer account and performance of the contract
When you create an account and use trackd.one, we process:
- email address and password (stored only as a PBKDF2 hash)
- language setting, selected plan and usage counters (e.g. events per month)
- time and version of your acceptance of the Terms and the data processing agreement
- time of the last sign-in and active sign-in sessions
- API keys (stored only as a hash)
- websites and apps you create and their settings
- team and organisation memberships, invitations and roles
- credits and settings such as the weekly report
- for paid plans: Stripe customer and subscription ID
The purpose is to provide the account and perform the contract. The legal basis is Art. 6(1)(b) GDPR. Acceptance of the Terms/DPA is additionally stored as proof of the conclusion of the contract (Art. 6(1)(f) GDPR) and to meet the documentation requirement under Art. 28 GDPR (Art. 6(1)(c) GDPR).
We store your account data until you delete your account. You can trigger deletion at any time in the settings; it is completed asynchronously in daily clean-up runs. Statutory retention obligations (see "Payment processing") remain unaffected.
Payment processing (Stripe)
Paid plans are billed via Stripe. The provider is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. When you book a plan, you are redirected to Stripe's checkout. Stripe collects payment details (e.g. card or bank details) directly; we do not receive them. We receive a customer and subscription ID, the subscription status and invoice information from Stripe.
Stripe processes payment data as an independent controller (among other things for fraud prevention and to meet its own legal obligations). Data may be transferred to Stripe, Inc. in the USA; Stripe, Inc. is certified under the EU-U.S. Data Privacy Framework. More information: https://stripe.com/privacy
Legal bases: Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(c) GDPR (tax and commercial retention obligations). We keep invoices and accounting records for the statutory periods (in particular Section 147 AO, Section 257 HGB; generally 8 or 10 years).
Cancellations, withdrawals and order declarations
If you cancel or withdraw via "Cancel contracts here" (/cancel) or by email, we process your name, your email address, the plan concerned, the type of notice (ordinary or extraordinary cancellation, withdrawal), any reason and requested date you give, the time of receipt, the effective date and — if available — the link to your account. We use this to end the subscription with Stripe and to send you a confirmation of receipt by email. Your IP address is only used transiently for rate limiting and is not stored.
Before you book a paid plan, we store your express request for an early start of the service (time, plan, version of the Terms, account and Stripe Checkout ID) and pass the time and plan to Stripe as metadata. After successful payment we send you a contract confirmation including the withdrawal information by email.
Purposes: performance and termination of the contract, compliance with legal obligations (confirmation of the cancellation under Section 312k BGB, contract confirmation under Section 312f BGB) and evidence (e.g. for compensation under Section 357a BGB). Legal bases: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (legal obligation); for keeping the records as evidence additionally Art. 6(1)(f) GDPR (legitimate interest in establishing and defending legal claims).
Retention: we keep these records as evidence even after the account is deleted, as long as claims under the contract can be asserted — at most 4 years (regular limitation period of 3 years from the end of the year in which the contract ended, Sections 195, 199 BGB) — and then delete them automatically.
Emails
We only send emails related to your account:
- email address confirmation and password reset
- invitations to websites or organisations
- notifications (alerts), e.g. on unusual traffic or when an uptime monitor goes down
- weekly reports with aggregated statistics (can be turned off in the settings)
The legal basis is Art. 6(1)(b) GDPR. We use Resend (Plus Five Five, Inc., San Francisco, USA) as a processor for sending. Your email address and the content of the email are processed. We do not send newsletters or advertising emails.
Invitations by other customers
If a customer invites a person to a website or organisation by email address, we process this email address to send the invitation. If a verified account already exists, we store the invitation until it is accepted or declined; if no account exists, we only send a notice about the invitation and do not store the address. The legal basis is Art. 6(1)(f) GDPR (legitimate interest of the inviting customer and our interest in providing the team feature). The invited person only gets access after accepting the invitation.
Support, security and admin access
If you contact us, we process your information to handle your request (Art. 6(1)(b) or (f) GDPR).
To handle support requests and analyse errors, expressly authorised administrators can view a customer account in a read-only view for at most 60 minutes ("impersonation"). During this time keys and secrets are hidden and exports are blocked. Every access and other administrative actions (e.g. suspending an account) are recorded in an audit log with time, action and the IDs of the accounts involved; email addresses of affected customers are not stored there. The audit log is kept for 2 years.
The legal basis is Art. 6(1)(b) GDPR (support as part of the service) and Art. 6(1)(f) GDPR (security, abuse prevention and traceability of administrative access).
Recipients and transfers to third countries
We use the following service providers:
- Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA — hosting, database, delivery (CDN), protection against attacks, technical logs (processor). The database (Cloudflare D1) is created with EU jurisdiction; data is stored in the EU. Requests are processed at the nearest location in Cloudflare's global network.
- Resend (Plus Five Five, Inc., USA) — sending emails (processor).
- Stripe Payments Europe, Ltd., Ireland — payment processing (independent controller, see above).
Where data is transferred to the USA, this is based on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework (Art. 45 GDPR) where the recipient is certified, and additionally on standard contractual clauses (Art. 46(2)(c) GDPR).
Beyond this, we only disclose data where we are legally obliged to (e.g. to authorities). We do not sell personal data.
Retention periods
- account data: until the account is deleted (deletion runs asynchronously in daily jobs)
- sign-in sessions: 30 days or until you sign out
- password reset link: 1 hour; email verification link: 48 hours
- support access (impersonation): at most 60 minutes per session
- admin audit log: 2 years
- uptime checks and alert history: 90 days
- technical logs (Workers Logs): at most 7 days
- rate limiting: transient, windows of at most 60 seconds
- database backups (Cloudflare D1 Time Travel): up to 30 days
- cancellations, withdrawals and early-start declarations: up to 4 years as evidence (regular limitation period)
- invoices and accounting records: statutory periods (generally 8 or 10 years)
Analytics data you collect as a customer with trackd.one is deleted according to the periods stated in Part B.
Obligation to provide data
An email address and a password are required to register and use the service; without them we cannot conclude a contract with you. Payment details are only required for paid plans. There is no statutory obligation to provide data.
No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
Your rights
Subject to the legal requirements, you have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). Many of these rights can be exercised directly in the dashboard (e.g. data export, deleting your account). Otherwise, an email to trackdone@mignuti.com is sufficient.
Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims. You can turn off weekly reports at any time in the settings.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence, place of work or place of the alleged infringement. The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, Germany, https://www.datenschutz.rlp.de
Part B — Information for visitors of websites and apps that use trackd.one
Website and app operators ("customers") can integrate trackd.one to analyse the use of their offering statistically. The respective operator is the controller for this processing; we process the data solely on their behalf and according to their instructions (Art. 28 GDPR, data processing agreement). The operator's privacy policy is therefore the primary source of information. The following describes which data trackd.one technically processes.
Roles: operator and trackd.one
The controller is the operator of the website or app you are using. The operator decides whether and how trackd.one is used and informs you in their privacy policy. trackd.one processes the data as a processor solely for this operator's statistics. We do not combine data of different operators, do not build cross-site profiles and do not use the data for our own purposes, advertising or sale.
Data processed on websites
With each page view or event, the tracking script sends the following information to trackd.one:
- page URL: query parameters are removed before storage (except utm_source, utm_medium, utm_campaign); a fragment (#…) is only kept for single-page routes (#/…)
- page title and referrer (only origin and path of the referring page)
- language and device type (desktop/tablet/mobile), derived on the server from the request headers sent by the browser (Accept-Language, User-Agent) — the script itself does not read device properties
- browser and operating system family, derived from the user agent; the user agent string itself is not stored
- country, derived by Cloudflare from the IP address (no city or region)
- events defined by the operator, with the event data the operator sends
- optionally, depending on the operator's settings: revenue data (amount, currency, order ID), Web Vitals loading performance metrics, click positions for heatmaps (position in percent, element type, window width — not linked to a visitor) and A/B test variants
A pseudonymous visitor identifier is derived from the IP address (see "Pseudonymisation"). Sessions are formed from this identifier and a 30-minute time window.
Data processed in apps (SDKs)
In Android, iOS, Flutter and JavaScript apps, the trackd.one SDKs send comparable information: screen name, events with event data defined by the operator, platform, app version, operating system version, device type, screen size and language, and optionally revenue data. The SDKs do not use device identifiers (e.g. no advertising ID, ANDROID_ID or IDFV). A session identifier is generated randomly and kept in memory only; it is discarded when the app is closed and stored server-side only as a hash. Operators are obliged to offer a way to turn off analytics in their app.
Handling of IP addresses and pseudonymisation
The IP address is not stored in the database. It is only used in memory to compute a pseudonymous visitor identifier: SHA-256 of the IP address, a secret key, a random value generated anew each day ("salt") and the website ID. Each day's salt is deleted shortly after midnight (UTC), so it exists for about 24 hours. After that, the identifier can no longer be recomputed from an IP address, not even by us; visits on different days or on different websites cannot be linked. For abuse prevention (rate limiting), the IP address is also processed transiently within windows of at most 60 seconds.
The stored data is pseudonymised. As linking it to a person cannot be ruled out in every case, we treat it as personal data.
No storage on the device
The tracking script does not set cookies and does not store any information on your device (no localStorage, no sessionStorage); it uses no fingerprinting techniques and does not read device properties such as screen size or language settings. It only sends the page address, page title and referrer; language and device type are derived on the server from the request headers. Optionally enabled features (Web Vitals, heatmap) additionally measure loading times or click positions. Whether consent is required under Section 25 TDDDG (German Telecommunications Digital Services Data Protection Act) is assessed by the respective operator.
Legal basis
The legal basis is determined by the respective operator. In particular, the operator's legitimate interest in privacy-friendly audience measurement (Art. 6(1)(f) GDPR) or your consent (Art. 6(1)(a) GDPR, where applicable in conjunction with Section 25(1) TDDDG) come into consideration, if the operator only loads trackd.one after you agree.
Retention periods
- individual records (single page views, events, sessions — the basis for filters, funnels and exports): at most 400 days
- aggregated statistics (daily values): depending on the operator's plan 180 days (Free), 1,095 days (Pro), 1,825 days (Business) or individually up to 3,650 days (Enterprise); after a plan change the previous period still applies for 30 days
- uptime checks and alert history: 90 days
- database backups: up to 30 days
Expired data is deleted automatically every day. The operator can delete data earlier at any time, for example by removing the website or their account.
Recipients
Recipients are the operator and the persons they authorise (e.g. team members). As a sub-processor we use Cloudflare, Inc. (hosting and database; storage in the EU, transfers to the USA safeguarded by the EU-U.S. Data Privacy Framework and standard contractual clauses). If the operator sets up disclosures themselves — e.g. public dashboard links, embedded statistics, Slack or webhook notifications — this happens on their instruction and under their responsibility.
Objection and opt-out
You can prevent collection in your browser by enabling Global Privacy Control (GPC) or "Do Not Track"; the script then sends no data. Operators can additionally turn off collection, e.g. from their consent dialog (window.trackdOptOut = true) or with the data-do-not-track attribute. In apps, the operator offers an opt-out within the app.
Please direct your right to object under Art. 21 GDPR to the operator.
Your rights as a visitor or app user
You can exercise your rights of access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR) as well as your right to lodge a complaint with a supervisory authority (Art. 77 GDPR) against the operator. If you contact us, we forward your request to the operator where we can identify them, and support them in responding.
Please note: as we store neither names nor IP addresses nor persistent identifiers, stored records generally cannot be attributed to a specific person (Art. 11(2) GDPR). Rights under Art. 15 to 20 GDPR then only apply if you provide additional information that enables such attribution.
Part C — Further information
Notice for California residents (CCPA/CPRA)
We do not sell personal data or share it for cross-context behavioural advertising ("sale" or "sharing" within the meaning of the CCPA/CPRA). You have the right to know which data is processed, to request its deletion or correction, and not to be discriminated against for exercising your rights.
Changes to this privacy policy
We update this privacy policy when our service or the legal situation changes. The version published here applies; the date is shown at the top.