Privacy
Privacy policy
A plain-language description of the data CloseTrace handles and the controls available to customers and visitors.
Effective August 6, 2026
Scope and our role
This policy covers the CloseTrace website, dashboard, hosted API, tracker, replay, heatmaps, lead recovery, and chat features. For account, billing, support, and our own website data, CloseTrace decides why the data is used. For visitor data collected from a customer's site, that customer controls the tracking purpose and CloseTrace processes the data on its behalf.
Customers are responsible for giving their visitors appropriate notice, collecting any consent their use case requires, and avoiding capture of data they are not permitted to process.
Data we collect
- Account details such as name, email, workspace membership, role, and authentication records.
- Site configuration, public tracker keys, privacy settings, notification preferences, and support messages.
- Visitor identifiers stored in browser local/session storage, session timestamps, page URLs, referrers, device/browser data, IP address, and approximate location.
- Interaction events such as page views, clicks, scroll depth, form friction, replay events, heatmap snapshots, and chat messages.
- After the CloseTrace platform administrator approves partial capture for a workspace, Lead Recovery can collect supported lead fields such as name, email, phone, company, budget, and message unless the field is excluded.
Input masking and Lead Recovery
Input masking is enabled by default for every workspace. Customer workspace members cannot turn it off; only the CloseTrace platform administrator can approve partial capture for an organization. Until then, replay inputs are masked and raw form-draft values are withheld. Password, payment, authentication, SSN, date-of-birth, bank-account, and similar sensitive fields remain excluded.
While values are withheld, CloseTrace can retain form and field names/types plus fill, timing, submission, and abandonment metrics without retaining what the visitor typed. After partial capture is approved, a customer can add data-private (or a supported mask/block marker) to a field or container to exclude it from replay text and form-draft capture. Static heatmap snapshots remove hidden inputs and all form values before upload.
How we use data
We use data to provide and secure the service, attribute sessions to the correct customer site, render analytics and replay, recover leads, deliver requested chat and notifications, troubleshoot incidents, respond to support and privacy requests, prevent abuse, and improve product reliability. We do not sell customer session data or use it to build advertising profiles.
Service providers and external AI
We may use infrastructure/database hosting, email delivery, push notification, and IP geolocation providers only to operate requested features. They receive the minimum data needed for their function and are subject to their own contractual and security terms.
External AI processing is disabled by default. If the platform operator enables it and a workspace administrator invokes an AI feature, relevant session, lead, or heatmap context may be sent to the configured AI provider. The dashboard identifies responses generated by the offline fallback when no external provider is enabled.
Storage, retention, and deletion
Data is retained according to the active plan, deployment configuration, customer instructions, and legitimate security/operational needs. Workspace administrators can use the dashboard's Data Control workflow for tracking-data or workspace deletion requests. You may also email privacy@closetrace.com. We may retain limited records when required for security, fraud prevention, dispute resolution, or legal compliance.
Security and choices
We use access controls, tenant-scoped queries, encrypted transport, secret hashing, input filtering, and abuse controls designed to protect the service. No internet service can promise absolute security.
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing. Start with the customer whose site collected the session; for CloseTrace account or website data, contact us directly. See the privacy request instructions.
Children, changes, and contact
CloseTrace is a business service and is not directed to children. We may update this policy as the product or providers change; the effective date above will be revised. Questions or privacy requests can be sent to privacy@closetrace.com.