What we store, and what we never do
A plain description of how the platform handles shopper data. It describes how the software works; your legal agreement with us governs.
Roles
Merchants are the controllers of their shoppers' data. Trakero processes it on their behalf, only to deliver the events they configure.
Contact details are hashed on arrival
Email, phone, name and street address are normalized and SHA-256 hashed inside our ingestion service before anything is queued, stored or logged. The original values are discarded. City, region, postal code and country are also kept in plain form, because Google requires them that way for matching.
What else is stored
Event name and time, page URL, order value and items, visitor and session identifiers, ad click identifiers, IP address and user agent. IP address and user agent are needed by Meta and Google for matching, and are deleted with the event when its retention period ends.
Consent is enforced
Each event carries the shopper's consent. With advertising consent denied, the browser SDK sets no ad cookies and ad destinations receive nothing. Merchants choose whether unknown consent counts as allowed or not.
Retention
Merchants set how long raw events are kept (1 to 730 days, within their plan). Expired events are deleted automatically.
Credentials
Destination tokens are encrypted with AES-256-GCM, bound to the store, and never shown again after saving, including to our own staff.
Logs
Request bodies, tokens and credentials are never written to logs.
Cookies on your store
The SDK sets first-party cookies on the merchant's own domain only: a visitor id, a 30-minute session id, ad click ids and first/last touch, plus Meta's _fbp and _fbc when advertising consent is not denied.
Our own site
This website sets a session cookie only when you sign in to the dashboard. It does not load third-party trackers.