Privacy Policy

Last updated: June 2026

This policy explains how Track40 (“we”, “us”) collects, uses, stores and protects personal data in connection with the Track40 service, and the rights and choices you have over your information. By using Track40, you agree to the handling of data described below.

Data we collect

Account data (name, email), team content you create (pipes, cards, comments, attachments), and operational logs needed to run and secure the service.

How we use it

To provide and maintain the service, authenticate you, process billing, send transactional email, and investigate abuse or security incidents. We do not sell personal data.

Retention

Team content is retained for the life of your account. Operational and audit logs are retained per your plan’s retention window. You can request deletion at any time.

Your rights

You may request access to, correction of, or deletion of your personal data. Contact legal@track40.com.

Track40 Sync browser extension

The optional Track40 Sync browser extension imports your Pipefy boards into Track40. It is enabled only after you explicitly turn it on, and you can pause or remove it at any time.

What it reads. Using your own existing Pipefy login session in the browser, and only for the boards an administrator of your team has chosen to sync, it reads those boards’ structure and card data — including field values, comments, attachments, phase history, and the names/emails of the people who created or moved cards. This content can include personal information that lives in your Pipefy cards. The extension does not read your other browser tabs, does not read any Pipefy data outside the chosen boards, and observes only the request headers it needs (a CSRF token) to call Pipefy on your behalf — it never inspects unrelated page content.

Where it goes. The data it reads is sent to Track40’s servers to recreate the equivalent pipes, cards, comments and files inside your Track40 team, and is then handled under the rest of this policy. The extension does not store your Pipefy password and does not transmit your data anywhere other than Track40.

Authentication. The extension connects to Track40 with a narrowly-scoped, time-limited token that authorises only sync; it is stored locally in the browser and removed when you sign out or remove the extension. We use the information it handles solely to provide the sync feature — it is not sold, and not used for advertising or any unrelated purpose.

Changes to this policy

We may update this policy from time to time. The “last updated” date above reflects the current version, and material changes will be communicated where appropriate. Continued use of the service after an update takes effect constitutes acceptance of the revised policy.

Contact

Privacy questions: legal@track40.com. Security disclosures: security@track40.com.