Privacy Notice

Last updated: October 7, 2026

WE ARE COMMITTED TO SAFEGUARDING YOUR PRIVACY AND WILL NEVER MISUSE YOUR DATA.

This document describes how we collect and process users' data through openserver.digital and app.openserver.digital (the "Website"). The terms "we", "us", "our" refer to Open Tracked, the operator of this Service.

Contact: [email protected]

Table of Contents

1. Information We Collect

1.1. Account Registration

To use the Service, you register an account using only your email address. Additional profile information (name) is optional and provided voluntarily. We use account information to:

We store your account data for as long as your account is active. Inactive accounts are anonymized within 12 months of your last session.

1.2. Service Usage

When using the Website, we collect and process:

1.3. Payments

We do not collect or store your financial information. Payments are processed by Paddle (our authorized payment provider), which collects and stores your payment data according to their own privacy policy. We retain only payment confirmation records to comply with applicable accounting laws.

1.4. Website Analytics

We collect standard web analytics data (pages visited, traffic sources, device type) to improve our service. This data is anonymized and aggregated. Log files including IP addresses are retained for a maximum of 12 months.

1.5. Google Sign-In

If you choose to sign in using Google, we receive your email address and name from Google. Your use of Google Sign-In is governed by Google's privacy policy.

2. Third-Party Services

We use trusted third-party providers to operate the Service, including:

All providers process data only according to our instructions and applicable data protection agreements.

3. Your Rights

You have the right to:

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

4. Security

We implement appropriate technical and organizational measures to protect your data against unauthorized access, modification, or disclosure. Access to personal data is restricted to authorized personnel only, who are bound by confidentiality obligations.

5. Open Tracked Analytics — Data We Process for Our Customers

When a customer installs the Open Tracked tracking pixel on their website, that customer decides why and how visitor data is used (the "controller"), and Open Tracked processes it only on the customer's behalf and instructions (the "processor"). This section describes what the pixel does. If you are a visitor to a website that uses Open Tracked, please contact that website's owner about your data.

What the pixel collects

Cookies and browser storage

The pixel sets first-party identifiers only: _os_vid (visitor, up to 365 days), _os_sid (session, 30 minutes of inactivity), plus browser storage entries used to remember the most recent traffic source (for the attribution window the customer chose, at most 90 days). Where the website already uses Google Analytics, the pixel also reads that browser id (the _ga cookie) so that a later sale or lead status can be tied back to the same visit in the customer's Google Analytics; it does not set that cookie itself. It does not use third-party cookies and does not follow visitors across other websites.

What we do not store

Opt-out and consent

The pixel does not run for browsers that send the Global Privacy Control signal, and a website can offer its visitors an opt-out by calling opentracked('optout'), for example from a cookie banner. Customers are responsible for providing the notices and obtaining the consent that the law requires for their own visitors.

Retention, location and service providers

Raw events are deleted automatically after 425 days (about 14 months). Order records and ad spend entries are kept while the customer's account is active. Our servers are located in the United States. We use Google Cloud (hosting) and Cloudflare (network and security) to provide the service, and Paddle to take payment for our own fees.

6. CRM and Automation — Contacts and Deals We Store for Our Customers

If a customer uses the CRM features, we store, on the customer's behalf, the contacts and deals that the customer (or their website forms, orders or API) sends to Open Tracked: name, email address, phone number, company, deal title and value, notes, custom fields the customer defines, the traffic source the contact first arrived from, and the advertising click identifier (such as gclid or fbclid) captured when the contact submitted a form or placed an order. Unlike the analytics data in Section 5, CRM contacts keep the email address and phone number in readable form, because the customer needs to contact the person. The customer is the data controller for this data; Open Tracked is the processor.

Automations that send data onward

Only when a customer switches on an automation, we can send deal data out of Open Tracked: (a) to Meta's Conversions API, where email, phone, name and identifiers are first normalised and hashed with SHA-256 and sent together with the deal value and click identifier, using the Pixel ID and access token the customer provides; and (b) to a webhook URL the customer chooses, as a JSON message signed with a secret only the customer holds; (c) as a short text message to a Slack or Discord channel through an incoming-webhook address the customer provides; (d) as an event to the customer's own Google Analytics 4 property, using a Measurement ID and API secret the customer provides; and (e) for stores that switch on "Incomplete orders" in the WordPress plugin, the email address, phone number and name a visitor typed into the checkout before leaving it, with the cart and the names of the required fields left empty (kept for up to 60 days and removed when the person orders or the customer erases them); (e2) when the customer uses the AI assistant, a summary of the workspace (key metrics, top channels and campaigns, CRM stage totals, but no customer names or emails) and the customer's questions, sent to the AI provider the customer chose (Anthropic, OpenAI or Google) with the customer's own API key; and (f) as a line in a downloadable file of Google Ads offline conversions (the Google click id, the conversion name, time and value) that the customer uploads to their own Google Ads account. Webhook addresses must be public HTTPS addresses. A workflow can also pause a deal for up to 30 days before its next step; while it waits we keep the deal's place in the workflow and its step-by-step log, and we delete that log with the oldest runs (we keep the newest 200 per workflow). The customer's Meta access token and webhook secret are stored encrypted and are never shown again after saving.

Access, correction and deletion

Customers can edit deals and delete deals together with their history, in the dashboard. To have a contact record erased, or all CRM data removed when an account is closed, the customer can ask us and we will delete it. People whose details were collected by a customer should contact that customer to exercise their rights; we will help the customer respond. CRM records are kept while the customer's account is active.

7. Changes to This Notice

We may update this Privacy Notice from time to time. We will notify you of significant changes by posting a notice on the Website or by email. Continued use of the Service after changes are posted constitutes your acceptance of the updated notice.