1. Overview
This Privacy Policy explains what personal data TrackerHub ("we," "us," "our") collects when you use trackerhub.site and the TrackerHub dashboard (together, the "Service"), why we collect it, and the choices you have. We built TrackerHub to collect as little as we need to run the product — no analytics scripts, no tracking pixels, and no ad trackers run on this site.
2. Information We Collect
Account information
- Email address — used to identify your account, send login links, and deliver email alerts.
- Password — if you set one, stored only as a salted PBKDF2 hash; we never store or have access to your plain-text password.
- Plan & subscription status — which plan you're on and whether it's active.
Tracker data
- The targets you configure (URLs, accounts, or sources to watch), what to watch for, your chosen notification channel, and the destination for alerts (email address, phone, webhook URL, or chat handle you provide).
- A history of checks performed and whether a change was detected, kept to power your dashboard and for troubleshooting.
- To check most targets, we request the public page or a public embed/syndication feed on your behalf, rather than using each source's official API — check frequency varies by target type and may change over time. See our Terms of Service for detail on how this affects monitoring speed and reliability.
Payment information
Subscription payments are handled entirely by Stripe. We never see or store your card number — Stripe passes us only your subscription status and a Stripe customer reference ID.
Login & security data
When you log in we record device and network details for security and sharing-detection purposes. We do not store IP addresses. This is set out in full in section 7.
Communications
If you email us or use the contact form, we keep that correspondence so we can respond and maintain a record of support requests.
3. How We Use Information
- To operate your trackers and deliver alerts through the channel you chose;
- To authenticate you (login links and password login) and secure your account;
- To process payments and manage your subscription;
- To respond to support requests;
- To maintain and improve the reliability of the Service.
We do not sell your personal data, and we do not use it for advertising.
4. Who We Share Information With
We share data only with the service providers ("subprocessors") that make TrackerHub work, and only the data each one needs to do its job:
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing | Email, billing/subscription details |
| Resend | Transactional email delivery | Email address, alert/login-link content |
| Telegram Bot API | Telegram alert delivery | Telegram handle/chat ID you provide, alert content |
| Cloudflare | Hosting (Workers, database, edge network) | All data listed above, as our infrastructure provider |
We may also disclose information if required by law, or to protect the rights, safety, or property of TrackerHub or our users.
5. Data Retention
Tracker check history is retained according to your plan: 7 days on the Demo plan, 30 days on Solo and Team plans. Account information is retained for as long as your account is active. If you'd like your account and associated data deleted, email info@trackerhub.site and we'll process the request.
6. Data Security
Login links are single-use and expire in 10 minutes, each device gets its own session that can be revoked on its own, passwords are hashed and never stored in plain text, and all traffic to the Service is encrypted in transit (HTTPS). Repeated failed logins are rate-limited, and we check new passwords against public breach datasets so a password already known to attackers cannot be set. No system is perfectly secure, but we take reasonable measures to protect your data.
7. Login & Security Data
To keep your account secure, to let you see and revoke your own sessions, and to detect account sharing (for example, a login link forwarded to someone else), we record a small amount of technical information when you log in or use the dashboard.
We do not store your IP address. Like every website, our servers receive one with each request — that is how the reply finds you — but we do not keep it. What we save instead is a one-way, salted fingerprint of it, which lets us answer “is this the same network as last time?” without the address itself ever being written down or recoverable from our records.
What we do keep:
- A device identifier — a random ID generated by your browser and stored there. It is first-party and identifies your browser to us only; it is not shared with anyone and cannot follow you to other sites.
- Basic device details — the browser, operating system, device type, language and time zone your browser reports on its own with every request.
- Network — the salted fingerprint described above, plus your internet provider’s network identifier and name, and whether the connection comes from a VPN or hosting provider.
- Approximate location — the country, region, city and city-level coordinates our infrastructure provider (Cloudflare) derives from the connection. This is accurate to a city at best. We never collect GPS or precise device location.
- Login events — a log of login-link requests, logins, logouts and rejected attempts, with the above attached.
Why we may use it: to prevent unauthorised access and credential sharing, and to show you your own active sessions. Under the GDPR our lawful basis is our legitimate interest in preventing fraud and abuse (Recital 47). We use this data for nothing else — no advertising, no sale, no profiling beyond the security purpose described here.
What we deliberately don’t do: no canvas or audio fingerprinting, no third-party tracking scripts, no cross-site identifiers, and no stored IP addresses.
How long we keep it:
| Data | Kept for |
|---|---|
| City, region and approximate coordinates | 30 days, then erased (country and network are retained) |
| Login event log | 90 days, then deleted |
| Unused login links | Deleted within a day of expiring |
| Device and session records | While your account is active |
These deletions run automatically every day, not on request. All of it is deleted when your account is deleted, and included if you ask us for an export of your data.
8. Cookies & Local Storage
The dashboard stores your login token in your browser's local storage so you stay signed in, alongside the random device identifier described in section 7, which is used only to secure your login and detect account sharing. Both are functional, not tracking, storage. We don't run analytics cookies, third-party ad trackers, or tracking pixels on this site.
9. Your Choices
You can review and delete your trackers at any time from the dashboard. For anything not self-serve — exporting your data, correcting your email, or deleting your account entirely — contact us and we'll take care of it.
10. Children's Privacy
The Service isn't directed at children, and we don't knowingly collect personal data from anyone under 18.
11. International Users
TrackerHub's infrastructure runs on Cloudflare's global network. If you're accessing the Service from outside the United States, your data may be processed in other countries as part of that infrastructure.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected in the "Last updated" date above.
13. Contact
Questions about this policy or your data? Email info@trackerhub.site.