Privacy Policy
Last updated September 28, 2026
Who we are
TraceAll is operated by saasbrella LLC, 30 N Gould St STE 4000, Sheridan, WY 82801, United States. Email: hello@traceall.app. This notice explains how we handle information for our analytics service. We determine how account and service-administration data is used. For a merchant’s store and customer data, we act on that merchant’s instructions; the merchant is responsible for its own customer privacy notice.
Information we process
- Account information: email address, a password hash, session and verification tokens, workspace membership, support communications, and security records.
- Connected stores: order identifiers, timestamps, order amounts, discounts and taxes, shipping country, customer purchase sequence, checkout identifiers, referring URLs, landing pages, campaign tags, and customer identifiers used for attribution matching.
- Storefront events: consented page and product views, cart events, checkout starts and purchases, pseudonymous visitor and session identifiers, URLs and referrers, browser information, screen dimensions, and consent settings. Marketing identifiers are used when marketing consent permits.
- Integrations: access credentials and account identifiers, Meta ad and campaign metadata and performance reports, and Drip email campaign, click, order, and revenue information where connected.
- Technical information: request information needed to deliver and secure the service, including IP addresses in security or infrastructure logs. TraceAll does not collect payment-card details through its tracking pixel.
How we use information
We use this information to operate private workspaces, authenticate users, synchronize integrations, match observed visits and marketing touches to orders, produce reports and labeled inferences, deliver account emails, and investigate errors or abuse. Attribution may be incomplete or inferred; it is not a definitive statement about a person’s behavior.
Where data protection law requires a legal basis, account administration relies on performing our agreement; service security and support rely on legitimate interests; legally required records rely on legal obligations. Storefront tracking and marketing processing depend on the merchant’s applicable legal basis and consent settings. You can withdraw consent through the merchant’s consent controls without affecting prior lawful processing.
Cookies and browser storage
The dashboard uses a session cookie to keep you signed in and browser storage for preferences and cached reports. The storefront tracker uses pseudonymous identifiers and Shopify’s privacy signals to collect permitted events. Marketing identifiers and cross-page attribution depend on marketing consent. Clearing browser storage can sign you out or remove local preferences. Merchants must configure their consent tools and tracking installation correctly.
Who receives information
Data is available to authorized workspace members and service providers supporting hosting, security, and communications. We use Hetzner for hosting and Forward Email for email services. Connected Shopify, Meta, and Drip services exchange information as needed for enabled integrations. If a merchant enables conversion delivery, permitted purchase information and matching identifiers may be sent to Meta. That delivery is separate from reading Meta reports.
Anyone with an active chart share link can see the shared chart and its aggregate summaries. Links expire after seven days or can be revoked sooner. We may disclose information where legally required or necessary to protect rights and prevent abuse. We do not sell merchant or customer data. Marketing disclosures a merchant enables may have separate consequences under applicable privacy law.
Storage, security, and international processing
We use access controls, HTTPS, password hashing, and encryption for stored integration credentials. No method of storage or transmission is completely secure. Our company is in the United States, and hosting and integration providers may process data in other countries. Contact us for information about processing locations and any contractual transfer arrangements relevant to your workspace.
Retention
Workspace order and event history is retained to provide reporting while the workspace is in use, unless deletion is requested or another retention requirement applies. Disconnecting an integration does not automatically erase previously synchronized history. Account session and action tokens have limited validity. We consider service needs, security, legal obligations, and backup handling when determining how long to retain or delete information.
Your choices and deletion requests
Email hello@traceall.app to request access, correction, export, account closure, or deletion. Include your account email or store domain, but never send passwords or access tokens. We may need to verify your identity and authority. You can revoke integration access in the connected platform; contact us separately to request deletion of data already imported.
If you are a customer of a merchant using TraceAll, contact that merchant first so it can identify your records and instruct us. Depending on your location, you may also have rights to restrict processing, object, withdraw consent, or complain to a data protection authority. We will handle applicable requests without unlawful discrimination.
Children and policy changes
TraceAll accounts are intended for adults managing businesses. If you believe a child’s information has been provided improperly, contact us. We will update this page when our practices change and provide notice of material changes where required.
Contact
saasbrella LLC, 30 N Gould St STE 4000, Sheridan, WY 82801, United States. Email: hello@traceall.app.