Privacy Policy

Last updated: 1 July 2026

1. Who we are

Tracking Auditor (“we”, “us”, “our”) is the operator of this service. We provide a web-based analytics tracking audit service accessible at trackingauditor.io.

If you have questions about this policy, contact us at: hello@trackingauditor.io

2. What data we access and why

Tracking Auditor connects to your Google account using OAuth 2.0. We request the following permissions and use them solely to generate your tracking audit report:

PermissionWhy we need it
Google account identity (email, profile)To identify your session and display your account email in the interface.
Google Tag Manager (read-only)To fetch your GTM container configuration, tags, triggers, variables, and consent settings, for analysis.
Google Analytics (read-only)To fetch your GA4 property configuration and run data quality checks against your traffic data from the last 30 days.
Google Drive (create files only)To save your audit report to your own Google Drive as a Google Doc and Google Sheet. We only create new files, we cannot read, modify, or delete any existing files.

We access only the minimum data necessary to generate your audit. We do not access, read, or store any other data from your Google account.

3. Google API Services, limited use disclosure

Tracking Auditor’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We use Google API data only to provide the tracking audit service you have requested.
  • We do not sell your Google API data to third parties.
  • We do not use your Google API data for advertising or to build advertising profiles.
  • We do not allow humans to read your Google API data except where required by law, necessary for security, or with your explicit consent for support purposes.
  • We do not transfer your Google API data to other apps or services except as described in section 5 (Anthropic, for AI-generated findings).

4. How your data is used

Data accessed through your Google account is used exclusively to:

  • Analyse your GTM container and GA4 property for tracking quality issues
  • Generate scored findings across consent architecture, data quality, GTM governance, event quality, and conversion integrity
  • Produce a written audit report and action plan exported to your Google Drive

We do not use your data for any other purpose.

5. Third-party services

Tracking Auditor uses the following third-party services to deliver the product:

Anthropic (Claude AI)

We send a structured summary of your audit data to Anthropic’s Claude API to generate the written findings, recommendations, and action plan in your report. This summary contains configuration data and aggregate metrics (such as tag names, event names, and scores) and does not include your visitors’ personal data. Some values, such as transaction reference IDs or page paths, may appear where a specific check requires them.

Anthropic processes this data solely to generate your report. It does not use your data to train its models, and the data is not retained by Anthropic beyond what is required to return the response.

Anthropic’s privacy policy: anthropic.com/privacy

Vercel

This application is hosted on Vercel. Vercel may process request metadata (IP addresses, request logs) as part of hosting infrastructure. Vercel’s privacy policy: vercel.com/legal/privacy-policy

Clerk

We use Clerk to manage user accounts, authentication, and sign-in. Clerk stores your email address and account metadata on our behalf. Clerk’s privacy policy: clerk.com/privacy

Stripe

Payments are processed by Stripe. When you purchase a plan, Stripe collects and stores your payment details. Depending on your location, Stripe may act as merchant of record for your purchase and process your payment data as a controller under its own terms. We do not store card numbers or full payment data. Stripe’s privacy policy: stripe.com/privacy

Neon

Our application database is hosted by Neon. It stores your account record (email address, plan status) and saved audit results as described in section 6. Neon’s privacy policy: neon.tech/privacy-policy

Google APIs

This application uses Google APIs to access your GTM, GA4, and Google Drive data. Use of Google services is subject to Google’s Privacy Policy.

6. Data storage and retention

We store the minimum data necessary to operate the service:

  • Account data: Your email address and plan status are stored to manage your account and entitlements.
  • OAuth tokens: Stored in an encrypted session cookie in your browser for the duration of your session. Tokens are used to make API calls on your behalf and are not retained on our servers beyond the active session.
  • Audit results: If you have an account, completed audit reports are stored so you can revisit them. A stored audit report includes scores, findings text, and the configuration item names (such as GTM tag names and GA4 event names) that were referenced in those findings. Raw source data, including full GTM container exports and complete GA4 traffic data, is not retained after your audit session ends. You can delete your audit history at any time from your account dashboard.
  • Google Drive files: Exported reports are saved to your own Google Drive, we do not retain a server-side copy.

7. Legal bases and international transfers

Where UK GDPR / GDPR applies, we process your personal data on the following bases:

  • Performance of a contract: account management, running audits you request, storing your audit history, and billing.
  • Legitimate interests: securing the service and preventing abuse of usage limits.
  • Consent: analytics cookies (see section 9). You can withdraw consent at any time.

Some of our service providers (including Anthropic, Vercel, Clerk, Stripe, and Neon) are based in, or process data in, the United States. Where personal data is transferred outside the UK or EEA, the transfer is protected by appropriate safeguards such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses entered into by those providers, or an applicable adequacy decision (including the UK/EU–US Data Privacy Framework where the provider is certified).

8. Your rights (UK GDPR / GDPR)

If you are in the UK or European Economic Area, you have the following rights regarding your personal data:

  • Access: Request a copy of the data we hold about you.
  • Rectification: Ask us to correct inaccurate data.
  • Erasure: Request deletion of your account and associated data.
  • Restriction: Ask us to restrict processing while a concern is resolved.
  • Portability: Request your data in a machine-readable format.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Revoke Google account access at any time via myaccount.google.com/permissions.

To exercise any of these rights, contact us at hello@trackingauditor.io. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk) or, in the EEA, your local supervisory authority.

9. Cookies

We use strictly necessary cookies to operate the service. These include:

  • Session cookie (Google OAuth): Stores your Google API access token for the duration of your audit session. HttpOnly and Secure, not accessible to JavaScript.
  • Authentication cookies (Clerk): Set by Clerk to maintain your logged-in state across page loads. Required for the service to function.

With your consent, we also use Google Analytics (GA4) to understand how the site is used and to improve it:

  • Analytics cookies (Google Analytics): Set only after you click “Accept analytics” on our cookie banner. We use Google Consent Mode, so no analytics cookies are set and no analytics data is collected unless you consent. You can decline, and you can clear your choice at any time by clearing this site’s cookies and local storage.

We do not use advertising cookies or any cookies for advertising, retargeting, or profiling purposes.

10. Security

All data transmitted between your browser and our servers is encrypted using HTTPS/TLS. OAuth tokens are stored in secure, HttpOnly cookies. We do not store Google API credentials on our servers.

If you become aware of a security vulnerability, please report it to hello@trackingauditor.io.

11. Changes to this policy

We may update this policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Continued use of the service after changes constitutes acceptance of the updated policy.