Privacy notice

We keep the monitoring record narrow.

TrackTriage is operated by DEEP Professional Ltd. Questions, access requests and deletion requests can be sent to support@tracktriage.com.

Information we process

We process your account email and identifier, the public storefront URLs you submit, browser-visible audit evidence, monitor settings, incident history, and limited billing identifiers supplied by Stripe. To protect public audit limits, we store a one-way HMAC of the requester's network address rather than the raw address.

Why we process it

We use this information to provide public storefront audits and monitoring, prevent abuse, send the alerts you ask for, support your account, and maintain the security and reliability of the service. Our lawful bases are performance of our contract with you, our legitimate interests in preventing abuse and maintaining a secure service, and compliance with applicable legal obligations.

Service providers and international processing

TrackTriage uses Supabase for account and private application data, Vercel for hosting, Browserless for isolated browser checks, Resend for transactional email, Slack only when you connect your own incoming webhook, and Stripe for subscription billing. Each provider processes only what is needed for its part of the service. Some providers may process data outside the UK; where applicable, they use recognised transfer safeguards described in their own data-processing terms.

Retention and deletion

Anonymous scans are removed after 30 days. Signed-in manual scans and routine monitor evidence are removed after 90 days. The current monitoring baseline is retained while monitoring is active. Confirmed incident and recovery evidence is retained for up to 12 months. You can delete eligible manual scans from your dashboard or request a copy or deletion of other TrackTriage application data at any time. We may retain the minimum records needed for fraud prevention, accounting, and legal obligations. Stripe retains its own payment records under its terms and legal obligations.

Your rights

Depending on applicable law, you can ask to access, correct, erase, restrict, or receive a copy of your personal data, and object to processing based on legitimate interests. Contact us to exercise a right. If you are in the UK, you can also complain to the Information Commissioner's Office.

Security

Monitor configuration and audit records are server-accessible only. Public scans reject private or reserved network targets and run through an isolated browser. No system is risk-free, so do not submit credentials, customer records, or confidential URLs to the public audit.