CloseTrace

Privacy

Privacy policy

A plain-language description of the data CloseTrace handles and the controls available to customers and visitors.

Effective August 11, 2026

Scope and our role

This policy covers the CloseTrace website, dashboard, hosted API, tracker, replay, heatmaps, lead recovery, and chat features. For account, billing, support, and our own website data, CloseTrace decides why the data is used. For visitor data collected from a customer's site, that customer controls the tracking purpose and CloseTrace processes the data on its behalf.

Customers are responsible for giving their visitors appropriate notice, collecting any consent their use case requires, and avoiding capture of data they are not permitted to process.

Data we collect

  • Account details such as name, email, workspace membership, role, and authentication records.
  • Site configuration, public tracker keys, privacy settings, notification preferences, and support messages.
  • Visitor identifiers stored in browser local/session storage, session timestamps, page URLs, referrers, device/browser data, IP address, and approximate location.
  • Interaction events such as page views, clicks, scroll depth, form friction, replay events, heatmap snapshots, and chat messages.
  • When an approved workspace capture policy is active, Lead Recovery can collect supported lead fields such as name, email, phone, company, budget, and message unless the field is excluded.

Input masking and Lead Recovery

CloseTrace applies the active workspace privacy policy before replay or form-draft data leaves the visitor's browser. Password, payment, authentication, SSN, date-of-birth, bank-account, and similar sensitive fields remain excluded.

While values are withheld, CloseTrace can retain form and field names/types plus fill, timing, submission, and abandonment metrics without retaining what the visitor typed. Where approved value capture is active, a customer can add data-private (or a supported mask/block marker) to a field or container to exclude it from replay text and form-draft capture. Static heatmap snapshots remove hidden inputs and all form values before upload.

How we use data

We use data to provide and secure the service, attribute sessions to the correct customer site, render analytics and replay, recover leads, deliver requested chat and notifications, troubleshoot incidents, respond to support and privacy requests, prevent abuse, and improve product reliability. We do not sell customer session data or use it to build advertising profiles.

Service providers and external AI

We may use infrastructure/database hosting, email delivery, push notification, and IP geolocation providers only to operate requested features. They receive the minimum data needed for their function and are subject to their own contractual and security terms.

External AI processing is disabled unless it is configured for the deployment. When an enabled AI analysis runs—automatically under platform-managed limits or when a workspace administrator requests an individual analysis—CloseTrace sends privacy-safe behavioral metadata such as event types, timestamps, interaction counts, field timing, submission state, and aggregate click/scroll measurements. Typed field values, direct contact details, raw replay HTML, and full page content are not included in external AI prompts. The dashboard identifies metadata-only analysis and distinguishes cached or limited-evidence results.

Storage, retention, and deletion

Data is retained according to the active plan, deployment configuration, customer instructions, and legitimate security/operational needs. Workspace administrators can use the dashboard's Data Control workflow for tracking-data or workspace deletion requests. You may also email privacy@closetrace.com. We may retain limited records when required for security, fraud prevention, dispute resolution, or legal compliance.

Security and choices

We use access controls, tenant-scoped queries, encrypted transport, secret hashing, input filtering, and abuse controls designed to protect the service. No internet service can promise absolute security.

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing. Start with the customer whose site collected the session; for CloseTrace account or website data, contact us directly. See the privacy request instructions.

Children, changes, and contact

CloseTrace is a business service and is not directed to children. We may update this policy as the product or providers change; the effective date above will be revised. Questions or privacy requests can be sent to privacy@closetrace.com.