Privacy Policy
Last Updated: November 7, 2025
Introduction
Trakyo ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our conversion attribution platform and related services (collectively, the "Service").
YouTube API Services: This application uses YouTube API Services. By using our Service's YouTube integration features, you are also agreeing to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms) and the Google Privacy Policy (http://www.google.com/policies/privacy).
By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not use our Service.
Definitions
- Service: The Trakyo platform, tracking scripts, APIs, and related services
- Customer: Content creators, marketers, or businesses using Trakyo to track conversions
- End User: Individuals who interact with Customer content and are tracked through our Service
- Personal Data: Information that can be used to identify an individual
- Usage Data: Data collected automatically through the Service
- Tracking Technologies: Cookies, browser fingerprinting, and similar technologies
Information We Collect
Information We Do Not Collect
We do not collect or process sensitive information, including:
- Racial or ethnic origin
- Political opinions or religious beliefs
- Trade union membership
- Genetic data
- Biometric data for the purpose of unique identification
- Health information or medical data
- Sexual orientation data
- Precise geolocation data (GPS coordinates)
- Government-issued identifiers (Social Security numbers, driver's license numbers, passport numbers)
- Financial account login credentials (we use third-party payment processors)
We only collect IP addresses for approximate geographic location (city/region level), which is not considered precise geolocation under applicable privacy laws.
For Customers
When you create an account and use our Service, we collect:
- Account Information: Name, email address, company name
- Authentication Data: Login credentials, OAuth tokens for platform integrations (YouTube, Calendly), API keys and webhook secrets for service connections
- Billing Information: Payment details processed through our payment providers
- Platform Integration Data: OAuth connections to YouTube, Calendly, and other integrated services
For End Users (Tracked Visitors)
When End Users interact with Customer tracking links and sites, we automatically collect:
Browser Fingerprinting Data
- Browser fingerprint ID via browser fingerprinting technology
- Browser type and version
- Operating system
- Device type (desktop, mobile, tablet)
- Screen resolution and color depth
- Installed browser plugins
- Timezone and language settings
- IP address (for geographic location and fraud prevention)
Tracking Data
- Cookies: We set a first-party cookie (trakyo_id) that persists for 90 days
- Local Storage: Used as a fallback for visitor ID storage
- UTM Parameters: Campaign source, medium, campaign name, and other attribution data
- Referrer Information: The website or platform that referred the visitor
- Domain Information: The domains visited that have our tracking script installed
Conversion Data
Through our platform integrations, we may receive:
- Email addresses (from form submissions)
- Phone numbers (from form submissions)
- Names (from form submissions)
- Meeting booking information (Calendly)
- Form responses (Typeform, ClickFunnels)
- Email signup data (Kit/ConvertKit)
- Calendar bookings and opt-ins (GoHighLevel)
- Payment verification data (without storing payment details)
How We Use Information
Customer Data
We use Customer data to:
- Provide and maintain your account
- Process transactions and send related information
- Send administrative communications
- Respond to customer service requests
- Monitor and analyze usage trends
- Detect and prevent fraud
End User Data
We use End User tracking data to:
- Generate unique visitor identifiers for attribution tracking
- Track user journeys from content interaction to conversion
- Associate conversions with specific marketing campaigns
- Create aggregated analytics for our Customers
- Deduplicate leads across multiple touchpoints
- Enable cross-domain tracking for our Customers
Data Retention
- Customer Account Data: Retained for as long as your account is active
- End User Tracking Data:
- Cookies persist for 90 days
- Event data retained for 12 months by default
- Customers may configure shorter retention periods
- YouTube API Data:
- Video metadata and analytics: Retained while your YouTube integration is active
- Deleted within 30 days after you disconnect your YouTube account or revoke access
- OAuth tokens: Automatically revoked upon disconnection
- Aggregated Analytics: Retained indefinitely in anonymized form
Data Sharing and Disclosure
We do not sell, trade, or rent Personal Data. We may share information:
With Customer Organizations
- End User interaction and conversion data is shared with the Customer whose content or links were interacted with
- This includes attribution data linking conversions to specific content pieces
With Service Providers
We share data with third-party service providers who assist us in operating our Service:
- Browser fingerprinting service providers
- Content delivery and edge computing providers
- Cloud database infrastructure providers
- Transactional email service providers
- Payment processors for billing
Third-Party Data Processing: We require all service providers to agree to confidentiality obligations and to process personal information only as instructed by us. However, if a service provider processes your personal information in a manner inconsistent with our instructions, we will not be liable unless we are responsible for the event giving rise to the unauthorized processing.
We limit the personal information provided to service providers to only what is reasonably necessary for them to perform their functions.
For Legal Requirements
We may disclose information if required to:
- Comply with legal obligations
- Protect our rights and property
- Prevent fraud or abuse
- Protect the safety of any person
Third-Party Integrations
Our Service integrates with various third-party platforms at the Customer's direction:
- Content Platforms: YouTube
- Booking Platforms: Calendly, GoHighLevel
- Form Platforms: Typeform, ClickFunnels
- Email Marketing: Kit (ConvertKit)
- Payment Platforms: Stripe, Teachable, Whop, Fanbasis
Each integration is subject to that platform's own privacy policy. We only access data necessary for attribution tracking.
YouTube API Services
Trakyo uses YouTube API Services to enable attribution tracking for YouTube content. When you connect your YouTube account to Trakyo:
- We access video metadata (titles, IDs, publication dates, view counts) to associate conversions with specific videos
- We may access channel information and basic video analytics data to provide attribution insights
- We use this data solely for the purpose of providing conversion attribution features to our Customers
- Your use of YouTube integration features is governed by the YouTube Terms of Service (https://www.youtube.com/t/terms)
- Google's privacy practices are described in the Google Privacy Policy (http://www.google.com/policies/privacy)
We do not use YouTube data for any purpose other than providing our Service. We do not share YouTube data with third parties except as necessary to provide our Service to you.
Cookies and Tracking
Technologies
First-Party Cookies
We use first-party cookies exclusively (no third-party cookies):
- trakyo_id: Persistent cookie (90 days) for visitor identification
Browser Fingerprinting
We use browser fingerprinting technology to generate browser fingerprints, which creates a unique identifier based on:
- Browser configuration
- Device characteristics
- System settings
This technology creates a unique identifier while respecting privacy by not accessing personal files or data.
Browser fingerprinting technology may enable identification across different browsers or devices belonging to the same user.
Local Storage
Used as a fallback mechanism when cookies are not available, storing the same visitor identifier.
Data Processing and Location
Your data is processed and stored through the following infrastructure:
- Global Processing: Data is processed through a global edge network for optimal performance
- Primary Storage: Core data is stored in US-East region data centers
- Edge Locations: Your data may be temporarily processed in multiple geographic regions for performance optimization
By using our Service, you consent to the processing of your information in these locations.
Lawful Basis for Processing
For Customer Data
We process Customer data based on:
- Contract: To provide the Service you've requested
- Consent: For marketing communications (where applicable)
- Legitimate Interests: For service improvements and fraud prevention
For End User Data
We process End User data based on:
- Legitimate Interests: Our Customers have a legitimate interest in understanding their marketing effectiveness and attribution
- Customer Responsibility: Customers must establish their own lawful basis for collecting End User data and ensure appropriate consent where required
Trakyo acts as a data processor on behalf of our Customers for End User data.
GDPR Legal Basis by Data Category
For users in the European Union, UK, or Switzerland, the following table describes our legal basis for processing each category of personal information:
Category of Personal Information Legal Basis for Processing
Customer account information (name, email, company)
Performance of a contract; Legitimate interests (account administration)
Customer payment information
Performance of a contract; Legal obligation (tax/financial recordkeeping)
Customer authentication data (passwords, API keys)
Performance of a contract; Legitimate interests (security)
Platform integration tokens (OAuth)
Performance of a contract; Consent (when connecting platforms)
End User browser fingerprints and cookies
Legitimate interests (attribution tracking on behalf of Customers); Customer's legal basis
End User IP addresses
Legitimate interests (fraud prevention, approximate geolocation)
End User UTM parameters and referrer data
Legitimate interests (marketing attribution)
End User conversion data (email, phone from forms)
Customer's legal basis; Processed on behalf of Customer
Usage data and analytics
Legitimate interests (service improvement, security)
Legitimate Interests: Where we rely on legitimate interests, our interests include: providing attribution services to Customers, preventing fraud and abuse, improving our Service, and ensuring security. We have assessed that these interests are not overridden by your data protection rights.
Data Minimization
We follow data minimization principles:
- We only collect information necessary for attribution tracking and service provision
- We do not collect sensitive personal information beyond what's required
- We regularly review our data collection practices to ensure they remain necessary
Customer Responsibilities
Customers who implement our tracking script on their websites are responsible for:
- Obtaining appropriate consent from End Users for cookie usage and fingerprinting in accordance with applicable laws
- Providing their own privacy policy that discloses the use of Trakyo tracking
- Managing cookie consent banners and compliance with GDPR, CCPA, and other privacy regulations
- Ensuring lawful basis for data collection in their jurisdiction
Trakyo provides the tracking technology, but Customers must ensure they have proper legal basis and consent mechanisms for tracking their website visitors.
Data Breach Notification
In the event of a data breach that affects Personal Data:
- We will notify affected Customers promptly after becoming aware of the breach
- Our notification will include the nature of the breach, categories of data affected, and measures taken
- Customers are responsible for any required End User notifications per applicable law
- We will cooperate with Customers to meet their regulatory obligations
Data Security
We implement appropriate technical and organizational measures to protect Personal Data:
We implement appropriate technical and organizational measures to protect Personal Data, including:
- Encryption of data in transit and at rest
- Multi-tenant data isolation
- Secure authentication systems
- Access controls and monitoring
- Regular security assessments
International Data Transfers
Your information may be transferred to and maintained on servers located outside of your country. We ensure appropriate safeguards are in place for such transfers.
Your Privacy Rights
For Customers
You have the right to:
- Access your account information
- Update or correct your information
- Delete your account
- Export your data
- Opt-out of marketing communications
For End Users
Depending on your location, you may have certain rights regarding your data:
GDPR Rights (European Union)
- Access: Request a copy of your data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data
- Portability: Receive your data in a machine-readable format
- Object: Object to certain processing activities
- Restrict: Request restricted processing
CCPA Rights (California)
- Know: What personal information we collect and how it's used
- Delete: Request deletion of your personal information
- Opt-Out: We do not sell personal information
- Non-Discrimination: Equal service regardless of privacy choices
Exercising Your Rights
To exercise these rights, contact us at privacy@trakyo.io with:
- Your specific request
- Information to verify your identity
- Any relevant tracking IDs or domains
We will respond to verified requests within 30 days.
Revoking YouTube Data Access
If you have connected your YouTube account to Trakyo and wish to revoke our access to your YouTube data, you have several options:
Option 1: Revoke Access Through Trakyo
- Log in to your Trakyo account
- Navigate to Settings > Integrations
- Click "Disconnect" or "Revoke Access" next to the YouTube integration
- Confirm the disconnection
Option 2: Revoke Access Through Google
- Visit the Google security settings page: https://myaccount.google.com/connections?filters=3,4&hl=en
- Find "Trakyo" in the list of connected apps
- Click on Trakyo and select "Remove Access"
Option 3: Request Deletion via Email
- Contact us at privacy@trakyo.io
- Include "YouTube Data Deletion Request" in the subject line
- Provide your account email and YouTube channel information
- We will process your request within 30 days
What Happens When You Revoke Access:
- We will immediately stop accessing new YouTube data from your account
- Existing YouTube data in our system will be deleted within 30 days of revocation
- All OAuth credentials will be cleared from our database
- Attribution data that references your YouTube videos will be anonymized
- You can reconnect your YouTube account at any time
Important Note About Disconnection Detection:
- If you disconnect through Trakyo (Options 1 or 3 above), we immediately revoke access and begin data deletion
- If you disconnect directly through Google (Option 2), we cannot detect the disconnection immediately
- For Google-initiated disconnections, our system will detect the revoked access within 30 days when token refresh attempts fail
- Data deletion will begin automatically once the disconnection is detected
- We run automated SQL scripts to completely wipe all Google/YouTube-related data upon disconnection
For Immediate Data Deletion: We strongly recommend disconnecting through Trakyo (Option 1) rather than directly through Google to ensure immediate data deletion.
Deleting Stored YouTube Data: If you want us to delete all YouTube-related data we have stored about you, contact privacy@trakyo.io with your request. We will delete all stored YouTube data within 30 days, including:
- Video metadata and analytics
- Channel information
- OAuth tokens and access credentials
- Attribution data linked to your YouTube content
Privacy Controls and Opt-Out Options
Global Privacy Control (GPC)
We honor the Global Privacy Control (GPC) signal. When we detect a valid GPC signal from your browser or device, we will treat it as a request to opt out of the sale or sharing of personal information for targeted advertising purposes, as required by applicable law.
To enable GPC, you may need to use a supporting browser or install a browser extension. Learn more at https://globalprivacycontrol.org/
Do Not Track (DNT)
While our Service does not respond to traditional Do Not Track (DNT) browser signals, you can control tracking through:
- Clearing cookies to reset your visitor ID
- Using private/incognito browsing to avoid persistent tracking
- Blocking JavaScript to prevent tracking script execution
- Enabling Global Privacy Control (GPC) as described above
Children's Privacy
Our Service is not intended for individuals under 16 years of age. We do not knowingly collect Personal Data from children under 16. If we become aware of such collection, we will delete the information immediately.
Changes to This Privacy Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last Updated" date. Continued use of the Service after changes constitutes acceptance of the revised Privacy Policy.
For material changes, we will provide notice through:
- Email to registered Customers
- Prominent notice on our Service
Dispute Resolution
Informal Resolution
If you have a privacy-related complaint or dispute, please first contact us at privacy@trakyo.io. We will attempt to resolve the issue informally within 30 days.
Binding Arbitration
Any dispute or claim arising out of or relating to this Privacy Policy or our processing of your personal information that cannot be resolved informally shall be settled by binding arbitration in accordance with the commercial arbitration rules of the American Arbitration Association.
- Arbitration will be conducted in the State of Delaware, United States, or remotely
- The arbitrator's decision will be final and binding
- Each party will bear its own costs and fees unless otherwise awarded by the arbitrator
- Class action arbitrations are not permitted
Notice: By using our Service, you agree to resolve privacy disputes through binding arbitration and waive your right to a jury trial or to participate in a class action lawsuit.
Exceptions
Either party may seek equitable relief in court for:
- Intellectual property disputes
- Violations of confidentiality obligations
- Enforcement of arbitration awards
This arbitration provision does not affect your statutory rights under GDPR, CCPA, or other applicable privacy laws to lodge complaints with supervisory authorities.
Contact Information
For questions about this Privacy Policy or our privacy practices, contact us at:
Email: privacy@trakyo.io Website: https://trakyo.io Legal Entity: Trakyo (United States)
Data Protection Officer
For privacy-related concerns or to exercise your rights: Email: dpo@trakyo.io
Privacy Disputes
For privacy disputes, please see our Dispute Resolution section above, or contact privacy@trakyo.io to initiate informal resolution.
Additional Information for Specific Jurisdictions
California Residents
Under the California Consumer Privacy Act (CCPA), California residents have additional rights. We do not sell personal information. For more details about categories of information collected and purposes, contact privacy@trakyo.io.
European Union Residents
Under the General Data Protection Regulation (GDPR), EU residents have enhanced rights. Our legal basis for processing includes:
- Consent (for marketing communications)
- Legitimate interests (for analytics and fraud prevention)
- Contract fulfillment (for Customer services)
You may lodge a complaint with your local supervisory authority if you believe your rights have been violated.
This Privacy Policy is effective as of the date stated at the top and supersedes all previous versions.