Legal

Privacy Policy

Last updated: 13 April 2025  ·  Effective date: 13 April 2025
Controller: Tracely  ·  Contact: privacy@tracely.uk

Contents

  1. Who we are
  2. What data we collect
  3. How we use your data
  4. Legal basis for processing (GDPR)
  5. Chrome extension — specific disclosures
  6. Who we share data with
  7. Data retention
  8. Your rights
  9. Security
  10. International transfers
  11. Children
  12. Changes to this policy
  13. Contact & complaints
Plain-English summary: Tracely collects only what is needed to run your account and capture sessions. We do not sell your data, serve ads, or share your screenshots with third parties. You can delete your account and all associated data at any time.

1. Who we are

Tracely ("Tracely", "we", "us", "our") operates the Tracely web application at app.tracely.uk and the Tracely Click Capture Chrome browser extension (together, the "Service").

For the purposes of the UK GDPR and EU GDPR, Tracely is the data controller responsible for the personal data described in this policy.

Contact: privacy@tracely.uk

2. What data we collect

Account data

Capture session data

Authentication data

Technical and usage data

What we do NOT collect

3. How we use your data

Purpose Data used
Create and manage your account Name, email, password hash
Authenticate you and maintain your session Email, session token
Send account activation and password reset emails Email, name, one-time token
Store and serve your captured documents and screenshots Screenshots, page URLs, step metadata
Generate PDF exports of your documents Document content, screenshots
Operate and improve the Service Server logs, error reports
Respond to support requests Email, account data you share with us

We do not use your data for advertising, profiling, or any purpose unrelated to operating the Service.

5. Chrome extension — specific disclosures

The Tracely Click Capture Chrome extension requests the following permissions. This section explains exactly what each is used for.

Permission Why it is needed What it does NOT do
activeTab Captures a screenshot of the current tab when you click during a capture session. Does not access any tab you have not actively chosen to document.
tabs Detects tab switches so the capture session stays in sync, and opens the Tracely web app for login/review. Does not read tab titles, URLs, or content in the background.
scripting Injects the locally-bundled capture script into the active tab to listen for your clicks during a session. Does not execute any remote or server-provided code. All injected scripts are bundled inside the extension package.
sidePanel Renders the Tracely capture interface in Chrome's built-in side panel. No data collection occurs through this permission.
storage Persists your authentication token and active session locally so you remain logged in across browser restarts. Data stored never leaves your device unless you explicitly save a document to Tracely.
Host permissions (<all_urls>) Required because you may start a capture session on any website. The extension must be able to inject the capture script on whichever site you are documenting. The extension does not read, monitor, or transmit data from any page you have not started a capture session on.

Screenshot capture

Screenshots are taken only when you have explicitly started a capture session and clicked an element on the page. Screenshots are uploaded to Tracely's secure cloud storage (Amazon S3, EU region) solely to populate your document. They are never used for any other purpose.

No background monitoring

The extension does not monitor your browsing, collect data in the background, or transmit anything to Tracely's servers unless you actively save a document.

No remote code execution

The extension does not load or execute any code from remote servers. All logic runs from scripts bundled within the published extension package.

6. Who we share data with

We do not sell, rent, or trade your personal data. We share data only with the following sub-processors, strictly to operate the Service:

Sub-processor Purpose Location
Amazon Web Services (AWS) Cloud hosting (EC2), screenshot file storage (S3) EU (eu-north-1 — Stockholm)
SendGrid (Twilio) Transactional email delivery (activation, password reset) USA (Standard Contractual Clauses apply)
MongoDB Atlas (if applicable) Database hosting EU

We may also disclose data if required by law, court order, or to protect the rights and safety of Tracely or others.

7. Data retention

8. Your rights

Under the GDPR and UK GDPR, you have the following rights regarding your personal data:

Right What it means
Access Request a copy of the personal data we hold about you.
Rectification Ask us to correct inaccurate or incomplete data.
Erasure Request deletion of your personal data ("right to be forgotten").
Restriction Ask us to restrict processing of your data in certain circumstances.
Portability Receive your data in a structured, machine-readable format.
Objection Object to processing based on legitimate interests.
Withdraw consent Where we rely on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, email privacy@tracely.uk. We will respond within 30 days. We may ask you to verify your identity before acting on a request.

9. Security

We implement appropriate technical and organisational measures to protect your data, including:

No method of transmission or storage is 100% secure. If you become aware of a security concern, please contact privacy@tracely.uk immediately.

10. International transfers

Your data is primarily stored and processed within the EU (AWS eu-north-1, Stockholm). Where we use sub-processors outside the EEA (e.g. SendGrid in the USA), we ensure appropriate safeguards are in place, such as the EU Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA).

11. Children

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact privacy@tracely.uk and we will delete it promptly.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top and, where appropriate, notify you by email. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

13. Contact & complaints

For any privacy-related questions or to exercise your rights, contact us at:

Tracely
Email: privacy@tracely.uk

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner's Office (ICO). In the EU, contact the supervisory authority in your member state.