GDPR and ePrivacy

Last updated 19 August 2026

This document needs review by a qualified lawyer before launch. It accurately describes what the software does — the data flows below were written from the source code — but it has not been reviewed for legal sufficiency in any jurisdiction.

Why this page exists

Email tracking involves personal data belonging to someone who did not consent: the recipient. We take that seriously rather than treating it as a footnote.

Roles

For data about tracked emails, the user who sends the email is the controller and EmailTrackApp is the processor. For account data, EmailTrackApp is the controller.

Legal basis, honestly stated

Users are covered by contract — they signed up. Recipients are the harder question. Several EU regulators, including the CNIL and the German DSK, have taken the position that tracking pixels require prior consent under Article 5(3) of the ePrivacy Directive, rather than legitimate interest. There is no settled EU-wide position, and enforcement so far has focused on bulk marketing rather than one-to-one correspondence.

Our response is to minimise and to give recipients real control:

Data subject rights

Recipients and users may request access, rectification, erasure, restriction, portability, or object to processing. Use privacy@emailtrackapp.com. The fastest route to erasure for a recipient is the opt-out page, which deletes existing records immediately.

International transfers

Data is stored in the Supabase region selected for the project. Confirm the region matches your compliance requirements before relying on this service in the EU.

Guidance for our users

You are the controller. Tracking a business negotiation reads very differently from tracking a personal message. The per-email toggle exists so this is a decision each time rather than a default you forget you set.