Trakzy
Legal

Privacy policy

Last updated · 18 September 2026

Who we are

Trakzy is attribution software for YouTube creators. This policy covers two kinds of data: information about you as a Trakzy account holder, and information the Trakzy snippet collects on our customers' websites on their behalf.

Your account

When you sign up we collect your name, email address and billing details. Payments are handled by our payment provider; we never store full card numbers. We also keep basic usage records of the dashboard so we can support you and improve the product.

What the snippet collects

When a customer installs the Trakzy snippet on their site, it records click IDs from tracked links, referrer and UTM parameters, the pages a visitor lands on, and the lead and conversion events the customer has set up (which can include a visitor's name and email from a form). Trakzy processes this data on behalf of the customer whose site it is; they control it. If you are a visitor to one of those sites, contact the site owner about your data.

Google and YouTube data

Trakzy uses YouTube API Services to pull video and channel statistics for the channels you connect. By connecting a channel you also agree to the YouTube Terms of Service. Google's handling of this data is described in the Google Privacy Policy.

With your consent we request read-only scopes only. We never request permission to post, edit or delete anything on your channel. Specifically we receive:

  • your Google account name, email address and profile picture (openid, email, profile), so we can show which account a channel is connected through;
  • your channel and video metadata — titles, IDs, descriptions, thumbnails, durations, public view counts (youtube.readonly);
  • your YouTube Analytics reports — views, watch time, traffic sources and audience-retention curves (yt-analytics.readonly);
  • your estimated revenue and RPM/CPM figures (yt-analytics-monetary.readonly), which we treat as sensitive data and protect as described below. This scope is optional to your use of Trakzy: if your Google account does not grant it, every other feature still works.

We use this data for one purpose: to show you, in your own dashboard, how your videos perform and which of them produced leads and sales. We do not use Google user data for advertising, we do not sell it, and we do not use it to build profiles of anyone or to train machine-learning models.

Trakzy's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke Trakzy's access to your channel at any time from your Google account permissions page; our stored tokens stop working the moment you do. To also have the data we already pulled erased, email hello@trakzy.io and we will delete it within 30 days. Deleting your Trakzy account removes it as well.

Who we share Google user data with

We do not sell, rent or trade Google user data, and we do not share it with advertisers, ad networks, data brokers or information resellers. We do not disclose it to other Trakzy customers. The only parties who ever handle it are the infrastructure providers we use to run the product, and each of them processes it under a contract that limits them to providing their service to us:

  • Vercel Inc. — application hosting and serving (United States).
  • Neon Inc. — the managed PostgreSQL database where channel, video and analytics records are stored (United States).
  • Clerk Inc. — Trakzy account authentication and session management. Clerk holds your name and email address, not your YouTube analytics.
  • Stripe Inc. — subscription billing. Stripe holds your billing details, not Google user data.
  • Functional Software, Inc. (Sentry) — error monitoring. Sentry may incidentally receive an identifier such as a channel or video ID inside an error report; it never receives OAuth tokens or revenue figures.
  • Anthropic PBC — when you run a video analysis, the text of that video's publicly available caption track is sent to Anthropic's API so calls-to-action in the script can be located. No Google account details, tokens, analytics or revenue data are sent. Anthropic does not train models on data submitted through its API.

Beyond those providers, we disclose Google user data only in two cases: when you explicitly ask us to (for example, when you export a report), and when we are legally required to — a valid court order, subpoena or equivalent legal process. If Trakzy is ever involved in a merger, acquisition or sale of assets, we will give you notice before your data becomes subject to a different privacy policy, and you will be able to delete your data first.

How we protect your data

We treat OAuth tokens, YouTube revenue figures and lead contact details as sensitive data, and protect them with the following measures:

  • Encryption in transit. Trakzy is served over HTTPS only, and every call we make to Google's APIs or to any provider listed above runs over HTTPS with TLS 1.2 or higher. Plain HTTP requests are redirected to HTTPS.
  • Encryption at rest. Google OAuth access and refresh tokens are encrypted with AES-256-GCM before they are written to the database, using a key held in our server environment and never stored alongside the data it protects. The database itself is additionally encrypted at rest by our hosting provider.
  • Least privilege. We request read-only Google scopes, and the monetary scope only where you grant it. Tokens are used server-side only and are never exposed to the browser or to any client-side script.
  • Access control and tenant isolation. Every query is scoped to the workspace that owns the data, so one customer cannot read another's. Administrative access to production systems is limited to authorised personnel who need it to operate or support the service, requires multi-factor authentication, and is used only for troubleshooting and abuse prevention.
  • Deletion. Revoking access in your Google account invalidates our stored tokens immediately. Deleting your Trakzy account, or emailing us to ask, removes your Google user data from our systems, and it is purged from backups on their normal rotation, within 30 days.

No system is perfectly secure, but if we ever become aware of a breach affecting your data we will notify you and the relevant authorities as required by law. Security questions and reports can be sent to hello@trakzy.io.

Cookies

We use first-party cookies to keep you signed in to the dashboard. On customers' sites, the snippet sets a first-party identifier so a click can be matched to a later lead or purchase. We do not run third-party advertising cookies.

Where data lives

Your channel, video and analytics records are stored in the European Union (Frankfurt), and the application that serves them runs there too. Some of the providers named above are US-incorporated and may process data in the United States in the course of providing their service; where they do, the transfer relies on the Standard Contractual Clauses in our contracts with them. We do not sell your data.

Retention and your rights

We keep account and tracking data while your account is active. You can request a copy of your data, ask us to correct it, or ask us to delete it by emailing hello@trakzy.io. Deleting your account removes the tracking data stored for your projects.