Legal

Privacy Policy

Last updated: May 21, 2026  ·  Effective: May 21, 2026

1. Information We Collect

We collect information you provide directly and information generated by your use of the Service:

  • Account information: Your name, email address, and password (bcrypt-hashed, never stored in plaintext). Optionally, your profile photo and business name.
  • Workspace data: Links, slugs, titles, tags, campaigns, goals, and settings you create within the Service.
  • Click analytics: For each click on your links — country, city, device type, operating system, browser name, and referrer URL. IP addresses are immediately hashed and never stored in plaintext.
  • Billing information: Subscription tier and payment history. Card details are handled directly by Paystack or Stripe and are never stored on our servers.
  • Usage data: Feature usage patterns, session duration, and error logs to help us improve the Service.

2. How We Use Your Data

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process your transactions and manage your subscription
  • Send you transactional emails (account confirmation, password reset, billing receipts)
  • Respond to your support requests and communications
  • Monitor and analyse usage patterns to improve product features
  • Detect and prevent fraudulent activity, abuse, and security incidents
  • Send you product updates and announcements (you may opt out at any time)
  • Comply with legal obligations

We do not use your data to serve third-party advertising or sell it to data brokers.

3. How We Protect Your Data

We take security seriously and implement multiple layers of protection:

  • IP addresses are hashed with SHA-256 immediately upon receipt and never stored in plaintext
  • Passwords are hashed with bcrypt (cost factor 12) — they are never logged or stored in any readable form
  • API keys are hashed before storage; only the hash is kept on our servers
  • All data in transit is encrypted via TLS 1.2 or higher
  • Database access is restricted by IP allowlist and requires authenticated connections
  • Infrastructure is hosted on Vercel and Neon, which maintain SOC 2 Type II compliance

Despite these measures, no system is 100% secure. In the event of a data breach affecting your personal information, we will notify you within 72 hours as required by applicable law.

4. Analytics & Click Tracking

When someone clicks a Traqly short link, our redirect infrastructure collects the following data points and associates them with the link owner's account:

  • Country and city derived from IP geolocation (IP is hashed immediately)
  • Device category (desktop, mobile, tablet) and operating system
  • Browser name and version
  • Referrer URL (the page the visitor came from, if available)
  • UTC timestamp of the click
  • Whether the click is unique or a duplicate (based on hashed IP + user-agent fingerprint)

As a link owner, you are a data controller of this click analytics data in relation to your audience. You should ensure your own privacy policy discloses to your audience that clicks on your links are tracked.

5. Data Sharing & Third Parties

We do not sell your personal data. We share data only in the following limited circumstances:

  • Infrastructure providers: Vercel (hosting), Neon (PostgreSQL database), Upstash (Redis caching). These providers process data on our behalf under data processing agreements.
  • Payment processors: Paystack (Nigeria) and Stripe (international) handle billing. They receive only what is necessary to process your payment.
  • Email delivery: We use a transactional email provider to deliver account and billing notifications. They receive your email address for delivery purposes only.
  • Legal obligations: We may disclose information when required by law, court order, or government authority, or to protect the rights and safety of Traqly, our users, or the public.

6. Cookies & Local Storage

Session cookies. We use HTTP-only, secure session cookies for authentication. These are essential to the functioning of the Service and cannot be disabled.

Local storage. We store your theme preference (light/dark mode) and certain UI settings in your browser's local storage. This data stays on your device and is never transmitted to our servers.

What we do NOT use. We do not use advertising cookies, tracking pixels, or third-party analytics scripts (such as Google Analytics) on the authenticated dashboard. Our public landing page may use minimal, privacy-respecting analytics to measure aggregate traffic.

Managing cookies. You can clear cookies and local storage at any time from your browser settings. Note that clearing session cookies will log you out of the Service.

7. Your Rights & Data Requests

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Correct inaccurate or incomplete data — you can update most data directly in Settings
  • Erasure: Request deletion of your account and all associated personal data
  • Data portability: Export your links and analytics data in JSON or CSV format
  • Opt-out of marketing: Unsubscribe from non-essential communications via the link in any email or in Settings

To exercise these rights, email privacy@traqly.io. We will respond within 30 days. You may also delete your account directly from Settings → Account → Delete Account.

8. Data Retention

We retain your data for as long as your account is active. Specific retention periods:

  • Account data: Retained until account deletion, then permanently deleted within 30 days
  • Click analytics: Retained for up to 24 months from the date of each click
  • Billing records: Retained for 7 years to comply with Nigerian financial regulations
  • Security logs: Retained for 90 days to support incident investigation

When you delete your account, all personal data — including your links, analytics, and workspace data — is scheduled for permanent deletion within 30 days. Billing records are retained for the legally required period.

9. Children's Privacy

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without verifiable parental consent, we will take steps to delete that information promptly.

If you believe we have inadvertently collected data from a minor, please contact us at privacy@traqly.io.

10. International Users

Traqly is based in Nigeria and our servers are located in the United States (via Vercel) and the EU (via Neon). If you access the Service from outside Nigeria, your data will be transferred to and processed in these jurisdictions.

By using the Service, you consent to the transfer of your information to countries that may not provide the same level of data protection as your country of residence. We take reasonable steps to ensure your data is treated securely in accordance with this Privacy Policy.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes by email and by updating the "Last updated" date at the top of this page at least 14 days before changes take effect.

Your continued use of the Service after the effective date of the updated Policy constitutes your acceptance of the changes.

12. Contact

For privacy-related questions or data requests:

Privacy requests: privacy@traqly.io

General enquiries: hello@traqly.io

Address: Lagos, Nigeria