Legal document

Privacy Policy

Last updated: June 30, 2026

This Privacy Policy describes how TheOne Tracker ("TheOne Tracker," "we," "us," "our") collects, uses, shares, and protects personal data when operating the attribution and campaign management platform available at www.theonetracker.com and www.app.theonetracker.com (the "Service"). By using the Service, you agree to the practices described here.

01 Who we are

The Service is operated by TheOne Tracker, a technology company providing campaign attribution and management software to advertisers, affiliates, and agencies. Full legal entity name, state of incorporation, registered address, and tax identification number are published in the entity's Terms of Use header and will be finalized upon completion of incorporation; this Policy will be updated to reflect that information before the Service is made available for production use with the Google, Meta, and TikTok APIs. For any privacy or data protection matter, contact us at [email protected].

02 Who this applies to

This Policy applies to anyone who creates an account, connects an advertising account, or otherwise uses the Service, as well as anyone who contacts us. For most processing activities, the TheOne Tracker customer is the controller (or "business," under U.S. state privacy law terminology) of the data from their own campaigns and advertising accounts, and TheOne Tracker acts as a processor (or "service provider"), processing that data on the customer's behalf and instructions, under a Data Processing Addendum incorporated into the Terms of Use. With respect to the customer's own account, registration, and billing data, TheOne Tracker acts as controller.

03 Data we process

3.1. Account and registration data

Name, email address, company name, and authentication data necessary to create and maintain your account.

3.2. Connected advertising account data

When you connect a Google Ads, Meta, or TikTok account through the official authorization flow (OAuth), we access data from those accounts according to the permissions you grant — such as account identifiers, campaigns, ad sets/groups, ads, pixels/conversion actions, and performance metrics. Access credentials (tokens) are handled securely and are never displayed to you.

3.3. Attribution and tracking data

To link the ad click to the sale, we process click identifiers (click_id), campaign parameters (UTMs), conversion events received via postback from your checkouts, and fraud risk scoring and event deduplication identifiers.

3.4. Billing and payment data

Data necessary to manage plans, subscriptions, and billing, such as plan tier, billing history, and tax information. Payments are processed by a third-party payment processor; we do not store your full card details — we only receive limited information necessary to manage the subscription (for example, payment status and the card's last four digits).

3.5. Communications and support data

Messages you send us (including through the website's contact form, which collects your name, email, and message content) and the history of our support interactions.

3.6. Technical data

IP address, device/browser identifiers, access logs, and data collected by cookies essential to the operation and security of the Service.

04 How we use data

We process personal data for the following purposes:

  • operating, maintaining, and providing the Service;
  • managing campaigns on your own advertising accounts (create, edit, pause, activate, and remove);
  • performing click-to-conversion attribution and generating reports;
  • identifying and mitigating fraud and abusive activity, including through automated risk scoring;
  • processing payments and managing plans and subscriptions;
  • providing support and communicating with you;
  • ensuring the security, integrity, and operation of the Service;
  • complying with legal and regulatory obligations.

We do not sell personal data and we do not use it to serve you targeted advertising.

05 Legal bases

We process personal data based on, as applicable, the performance of a contract and pre-contractual steps taken at your request, compliance with a legal obligation, our legitimate interest (for example, security and fraud prevention), and consent where applicable, under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and other applicable U.S. state privacy laws, the EU/UK General Data Protection Regulation (GDPR) where applicable, and, with respect to data subjects in Brazil, Law No. 13,709/2018 (LGPD) — see Section 10 below for jurisdiction-specific rights.

06 Data received from third-party APIs

TheOne Tracker integrates with the official Google Ads, Meta, and TikTok APIs exclusively to manage campaigns on the advertising accounts you connect and authorize. We request only the minimum set of permissions (scopes) necessary for those purposes and we use data received from those APIs only to provide and improve the Service's features for you.

Limited Use — Google API Services. TheOne Tracker's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data obtained through Google APIs: (i) is not used or transferred to serve advertisements, including remarketing, personalized, or interest-based advertising; (ii) is not used to determine creditworthiness or for lending purposes; (iii) is not sold; and (iv) is not transferred to third parties, except when strictly necessary to operate or improve the Service for you, to comply with applicable law, or as part of a merger or acquisition, always under the terms of that policy.

Similarly, our processing of data obtained from the Meta and TikTok APIs observes each platform's developer policies and terms and is limited to managing your own campaigns, attribution, and reporting.

07 Sharing and sub-processors

We do not sell or rent personal data. We share data only with:

  • Advertising platforms you connect (Google, Meta, TikTok), to the extent necessary to manage your campaigns;
  • Infrastructure and technology providers that support our operation of the Service (hosting and database, transactional email, monitoring), which process data under our instructions and confidentiality and security obligations;
  • Authorities, when required by law or court order.

Current sub-processors:

  • Supabase, Inc. — database and backend infrastructure (United States)
  • Vercel Inc. — application hosting and content delivery (United States)
  • Resend — transactional email delivery (United States)
  • Stripe, Inc. — payment and subscription processing (United States)

This list is reviewed periodically and updated as our infrastructure evolves.

08 Retention

We retain personal data for as long as necessary for the purposes described in this Policy, for as long as your account and the contractual relationship remain active, and afterward for the periods required by law or to exercise legal rights. As a general rule: account and registration data is retained for the life of the account and deleted or anonymized within 90 days of account closure; connected advertising account data (campaigns, metrics) is retained while the connection is active and deleted within 90 days of disconnection; attribution and tracking data (click_id, events, UTMs) is retained for 24 months for reporting purposes and then aggregated or anonymized; access logs are retained for 12 months; billing and tax records are retained for the period required by applicable tax law. Once the purpose has been fulfilled, data is deleted or anonymized.

09 Security

We adopt technical and organizational measures to protect data, including SSL/TLS transmission, per-customer data isolation, access controls verified on every operation, and the principle of least privilege. No system is completely immune to risk; we work continuously to reduce and mitigate these exposures. In the event of a security incident that may pose a meaningful risk to data subjects, we will take appropriate measures and make any notifications required by applicable law.

10 Your rights

CCPA/CPRA (California). If you are a California resident, you may exercise the rights to know, access, correct, and delete your personal information, and the right to opt out of the "sale" or "sharing" of your personal information — noting that TheOne Tracker does not sell or share personal information as those terms are defined under that law — as well as the right to non-discrimination for exercising these rights.

GDPR (EU/UK). If you are subject to the GDPR, you may exercise the rights of access, rectification, erasure, restriction of processing, data portability, and objection, and you may lodge a complaint with the competent supervisory authority.

LGPD (Brazil). If you are located in Brazil, under Law No. 13,709/2018 (LGPD) you may, at any time, request: confirmation of the existence of processing; access to your data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data; data portability; information about data sharing; review of automated decisions (see Section 12); and withdrawal of consent.

To exercise any right, write to [email protected]. We may ask you to verify your identity before fulfilling a request.

11 Data deletion

You may request deletion of your data at any time. There are two paths:

  • Disconnect an account: remove the connection to an advertising account directly within the Service to stop access to that account's data;
  • Deletion request: send an email to [email protected] with the subject line "Data deletion." We will confirm receipt and process the request within the legally applicable timeframes, except where retention is legally required.

If you have connected a Meta account, deletion of the associated data can also be requested through this same channel, and disconnecting the account revokes our access.

12 Automated decisions

The Service uses automated risk scoring to identify and mitigate fraud in attribution (for example, classifying events into risk bands). This processing is intended to protect the integrity of campaigns and reports. You may request information about the criteria used and, to the extent permitted by applicable law, request review of decisions made solely through automated processing, by emailing [email protected].

13 International transfers

The Service and some of our providers may process data on servers located outside your country, including in the United States. When this occurs, we will adopt the appropriate safeguards required by applicable law (for example, standard contractual clauses or another recognized transfer mechanism) to protect transferred data.

14 Cookies

We use cookies and similar technologies essential to the operation and security of the Service, as well as to remember preferences. You can manage cookies in your browser settings; disabling essential cookies may affect the Service's functionality.

15 Children

The Service is intended for professionals and businesses and is not directed to anyone under 18. We do not knowingly collect data from children.

16 Changes to this Policy

We may update this Policy from time to time. The current version will always be available on this page, with the date of the last update shown at the top. Material changes may be communicated through the Service's channels.

17 Contact and Data Protection Officer

For questions, requests, or to exercise rights under this Policy, contact our data protection officer: Privacy Team, TheOne Tracker — [email protected]. The registered business address of the controller is published in the entity's Terms of Use and will be added here upon finalization.