Why this page exists
Email tracking involves personal data belonging to someone who did not consent: the recipient. We take that seriously rather than treating it as a footnote.
Roles
For data about tracked emails, the user who sends the email is the controller and EmailTrackApp is the processor. For account data, EmailTrackApp is the controller.
| Data | Controller | Processor |
|---|---|---|
| Tracked emails and their open events | The user who sent the email | EmailTrackApp |
| Account data | EmailTrackApp | — |
Legal basis
Users are covered by contract — they signed up. For recipients, we keep the data we handle to a minimum and give them real control:
- Recipient IP addresses are stored only as an irreversible keyed hash
- A public opt-out is honoured before any tracker is added
- Email content is never transmitted or stored
- No recipient profiles are built, and nothing is shared across accounts
Data subject rights
Recipients and users may request access, rectification, erasure, restriction, portability, or object to processing. Use privacy@emailtrackapp.com. The fastest route to erasure for a recipient is the opt-out page, which deletes existing records immediately.
International transfers
Data is stored in the Supabase region selected for the project. Confirm the region matches your compliance requirements before relying on this service in the EU.
Guidance for our users
You are the controller. Tracking a business negotiation reads very differently from tracking a personal message. The per-email toggle exists so this is a decision each time rather than a default you forget you set.