Privacy Policy

Last updated: August 2026

This policy explains how Track40 (“we”, “us”) collects, uses, stores and protects personal data in connection with theTrack40 service, and the rights and choices you have over your information. By using Track40, you agree to the handling of data described below.

Data we collect

Account data (name, email), team content you create (pipes, cards, comments, attachments), usage logs (IP address, browser metadata and timestamps, kept for 90 days for security and abuse prevention), and billing details for paid plans, which are handled by Stripe. We never see or store your full card number.

How we use it

To provide and maintain the service, authenticate you, process billing, send transactional email, and investigate abuse or security incidents. We do not sell personal data.

Analytics, cookies and session replay

We measure how this website and the Track40 app are used with PostHog, hosted in the United States: pages viewed, actions taken, the referring site, browser type, and an approximate location derived from your IP address. Both surfaces may also capture a session replay showing the screens you saw and where you clicked and scrolled. Anything typed into a form is masked and never recorded; a replay of the app does include the content that was displayed on your screen during the session.

On this website the measurement uses no cookies. A temporary identifier lives in the browser tab for the duration of your visit and is discarded when the tab closes. In the app, an essential session cookie keeps you signed in, PostHog stores its identifier in cookies prefixed ph_, and analytics events are linked to your account name and email so we can understand usage per user. To object to analytics, emaillegal@track40.com or block PostHog with your browser's tracking protection. The session cookie is required for the app to function.

Sub-processors

The third parties that touch personal data on our behalf: hosting in European data centres in Germany (application servers, database and attachment storage), Amazon SES (transactional email), Stripe (payment processing), Sentry (error monitoring, which receives error details and the user id and email tied to the session), and PostHog (analytics and session replay, as described above).

Data residency and security

Your data is stored in European data centres in Germany. Where data is transferred outside the EU/EEA (for example to the United States for analytics), we rely on Standard Contractual Clauses; details are available on request.

Sign-in is passwordless by default (a one-time email link), so there is no password to steal unless you explicitly set one, in which case we store only a salted hash. All public traffic uses HTTPS with HSTS. We are a small team and take security seriously, but we make no claim of SOC 2 or ISO 27001 certification at this stage.

Retention

Team content is retained for the life of your account. Operational and audit logs are retained per your plan’s retention window. You can request deletion at any time.

Your rights

You may request access to, correction of, or deletion of your personal data. Contactlegal@track40.com. Deleting your account removes your personal data from our database and anonymises content you contributed to other teams. Teams you own are deleted with the account, so transfer ownership first if other members should keep access.

Track40 Sync browser extension

The optional Track40 Sync browser extension imports your Pipefy boards into Track40. It is enabled only after you explicitly turn it on, and you can pause or remove it at any time.

What it reads. Using your own existing Pipefy login session in the browser, and only for the boards an administrator of your team has chosen to sync, it reads those boards’ structure and card data: field values, comments, attachments, phase history, and the names and emails of the people who created or moved cards. This content can include personal information that lives in your Pipefy cards. The extension does not read your other browser tabs, does not read any Pipefy data outside the chosen boards, and observes only the request headers it needs (a CSRF token) to call Pipefy on your behalf. It never inspects unrelated page content.

Where it goes. The data it reads is sent to Track40’s servers to recreate the equivalent pipes, cards, comments and files inside your Track40 team, and is then handled under the rest of this policy. The extension does not store your Pipefy password and does not transmit your data anywhere other thanTrack40.

Authentication. The extension connects to Track40 with a narrowly-scoped, time-limited token that authorises only sync; it is stored locally in the browser and removed when you sign out or remove the extension. We use the information it handles solely to provide the sync feature. It is not sold, and not used for advertising or any unrelated purpose.

Changes to this policy

We may update this policy from time to time. The “last updated” date above reflects the current version, and material changes will be communicated where appropriate. Continued use of the service after an update takes effect constitutes acceptance of the revised policy.

Contact

Privacy questions:legal@track40.com. Security disclosures:security@track40.com.