1. Overview
This Privacy Policy explains what personal data TrackerHub ("we," "us," "our") collects when you use trackerhub.site and the TrackerHub dashboard (together, the "Service"), why we collect it, and the choices you have. We built TrackerHub to collect as little as we need to run the product — no analytics scripts, no tracking pixels, and no ad trackers run on this site.
2. Information We Collect
Account information
- Email address — used to identify your account, send login links, and deliver email alerts.
- Password — if you set one, stored only as a salted PBKDF2 hash; we never store or have access to your plain-text password.
- Plan & subscription status — which plan you're on and whether it's active.
Tracker data
- The targets you configure (URLs, accounts, or sources to watch), what to watch for, your chosen notification channel, and the destination for alerts (email address, phone, webhook URL, or chat handle you provide). If you turn on push notifications instead, your browser registers a push subscription (a delivery endpoint and encryption keys, not something you type) which we store to deliver alerts to that device.
- A history of checks performed and whether a change was detected, kept to power your dashboard and for troubleshooting.
- To check most targets, we request the public page or a public embed/syndication feed on your behalf, rather than using each source's official API — check frequency varies by target type and may change over time. See our Terms of Service for detail on how this affects monitoring speed and reliability. Trackers watching an X/Twitter account are the exception: we use X's official API, sending it only the account handle you're tracking.
- When you create a tracker, Cloudflare Workers AI reads the target and "watch for" text you enter to help write the plain-English description of what you'll get alerted on. On your dashboard's Insights tab, the same AI reads each alert's content to label it good, bad, or neutral for you. Both stay within Cloudflare's infrastructure — see section 4.
- Shared with other customers by default. New trackers are marked "shared" when you create them, which lists the target (the URL or account you're tracking), a display title, what kind of tracker it is, and how many people watch it in every customer's "Already tracked for you" tab, so someone else can adopt it instead of setting up a duplicate. This never includes your destination (email, phone, webhook URL, or chat ID), your "watch for" text, your account, or anything that identifies you — see section 4 for the exact fields shared. Because a tracked URL itself can still be revealing (a specific job listing, a competitor's page, someone's personal profile), every tracker shows whether it's shared right on your dashboard, and you can turn sharing off for any individual tracker at any time with one click — it's removed from the shared list immediately.
Payment information
Subscription payments are handled entirely by Stripe. We never see or store your card number — Stripe passes us only your subscription status and a Stripe customer reference ID.
Login & security data
When you log in we record device and network details for security and sharing-detection purposes. We do not store IP addresses. This is set out in full in section 7.
Communications
If you email us or use the contact form, we keep that correspondence so we can respond and maintain a record of support requests. Emails sent to our support address are also passed to Cloudflare Workers AI, which drafts an automatic first reply; a person reviews anything it can't resolve. See section 4 for detail.
3. How We Use Information
- To operate your trackers and deliver alerts through the channel you chose;
- To authenticate you (login links and password login) and secure your account;
- To process payments and manage your subscription;
- To respond to support requests;
- To maintain and improve the reliability of the Service.
We do not sell your personal data, and we do not use it for advertising.
4. Who We Share Information With
We share data only with the service providers ("subprocessors") that make TrackerHub work, and only the data each one needs to do its job:
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing | Email, billing/subscription details |
| Resend | Transactional email delivery | Email address, alert/login-link content |
| Postmark | Backup email delivery — used only on the rare send Resend rejects (e.g. its daily volume cap) | Email address, alert/login-link content |
| Telegram Bot API | Telegram alert delivery | Telegram handle/chat ID you provide, alert content |
| Slack, Discord, or a webhook URL you supply | Alert delivery, only if you choose one of these as your tracker's notification channel | Alert content, sent to the destination you configured |
| X (Twitter) API | Real-time delivery for trackers watching an X/Twitter account | The account handle you're tracking — nothing about you personally is sent to X |
| Your browser or device's push service (run by Google, Apple, or Mozilla, depending on your browser) | Delivers Push (Windows) / Push (iPhone) alerts | An encrypted alert payload and your device's push endpoint address; the provider can see that a push was sent and to which device, not its content |
| Cloudflare Workers AI | Drafts the automatic first reply when you email our support address; helps write the plain-English description of what a new tracker will alert you on; labels each alert on your Insights tab as financially good, bad, or neutral | Support email subject/body; the tracker target and "watch for" text you enter when creating a tracker; the alert content shown on your Insights tab (processed within Cloudflare's infrastructure, not sent to a further third party) |
| Cloudflare | Hosting (Workers, database, edge network) | All data listed above, as our infrastructure provider |
| Other TrackerHub customers | "Already tracked for you" — lets a customer adopt a tracker someone else already set up instead of duplicating it | For any tracker marked shared: its target (URL/account), a display title, tracker type, and how many customers watch it. Never your destination, "watch for" text, account email, or any identifier for who's watching. See section 2 for how default sharing works and how to opt out per tracker. |
We may also disclose information if required by law, or to protect the rights, safety, or property of TrackerHub or our users.
5. Data Retention
Tracker check history and notification logs are kept for as long as the tracker exists — we don't currently delete individual history entries after a fixed number of days, and this doesn't vary by plan. Account information is retained for as long as your account is active. Account deletion is self-serve: an authenticated request from your account permanently and immediately erases your trackers, check history, notifications, and account information. If you have an active paid subscription, cancel it first — deletion isn't available while a subscription is still active. If you'd rather we do it for you, email alerts@trackerhub.site and we'll process the request.
6. Data Security
Login links are single-use and expire in 10 minutes, each device gets its own session that can be revoked on its own, passwords are hashed and never stored in plain text, and all traffic to the Service is encrypted in transit (HTTPS). Repeated failed logins are rate-limited, and we check new passwords against public breach datasets so a password already known to attackers cannot be set. No system is perfectly secure, but we take reasonable measures to protect your data.
7. Login & Security Data
To keep your account secure, to let you see and revoke your own sessions, and to detect account sharing (for example, a login link forwarded to someone else), we record a small amount of technical information when you log in or use the dashboard.
We do not store your IP address. Like every website, our servers receive one with each request — that is how the reply finds you — but we do not keep it. What we save instead is a one-way, salted fingerprint of it, which lets us answer “is this the same network as last time?” without the address itself ever being written down or recoverable from our records.
What we do keep:
- A device identifier — a random ID generated by your browser and stored there. It is first-party and identifies your browser to us only; it is not shared with anyone and cannot follow you to other sites.
- Basic device details — the browser, operating system, device type, language and time zone your browser reports on its own with every request.
- Network — the salted fingerprint described above, plus your internet provider’s network identifier and name, and whether the connection comes from a VPN or hosting provider.
- Approximate location — the country, region, city and city-level coordinates our infrastructure provider (Cloudflare) derives from the connection. This is accurate to a city at best. We never collect GPS or precise device location.
- Login events — a log of login-link requests, logins, logouts and rejected attempts, with the above attached.
Why we may use it: to prevent unauthorised access and credential sharing, and to show you your own active sessions. Under the GDPR our lawful basis is our legitimate interest in preventing fraud and abuse (Recital 47). We use this data for nothing else — no advertising, no sale, no profiling beyond the security purpose described here.
What we deliberately don’t do: no canvas or audio fingerprinting, no third-party tracking scripts, no cross-site identifiers, and no stored IP addresses.
How long we keep it:
| Data | Kept for |
|---|---|
| City, region and approximate coordinates | 30 days, then erased (country and network are retained) |
| Login event log | 90 days, then deleted |
| Unused login links | Deleted within a day of expiring |
| Device and session records | While your account is active |
These deletions run automatically every day, not on request. If you delete your account (see section 5) — whether you do it yourself or ask us to — this is deleted along with it. If you'd like an export of this data instead, email us and we'll handle that manually; there's no self-serve export tool.
8. Cookies & Local Storage
The dashboard stores your login token in your browser's local storage so you stay signed in, alongside the random device identifier described in section 7, which is used only to secure your login and detect account sharing. Both are functional, not tracking, storage. We don't run analytics cookies, third-party ad trackers, or tracking pixels on this site.
9. Your Choices
You can review and delete your trackers at any time from the dashboard, and delete your account and its data entirely yourself — see section 5 for how that works. Every tracker's row in your dashboard shows whether it's shared and includes a one-click control to turn sharing off (or back on) for that tracker — see section 2. For anything not self-serve — exporting your data or correcting your email — contact us and we'll take care of it.
10. Children's Privacy
The Service isn't directed at children, and we don't knowingly collect personal data from anyone under 18.
11. International Users
TrackerHub's infrastructure runs on Cloudflare's global network. If you're accessing the Service from outside the United States, your data may be processed in other countries as part of that infrastructure.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected in the "Last updated" date above.
13. Contact
Questions about this policy or your data? Email alerts@trackerhub.site. TrackerHub is operated by Asher Kukuk, trading as Klarge Group.