Privacy Policy

Effective August 13, 2026

This policy explains what information TracesOn (“TracesOn,” “we,” “us”) collects when you use our platform, how we use it, and the choices you have. It applies to traceson.com and the TracesOn application.

1. Information we collect

Account information. When you or your organization sign up, we collect your name, work email, organization name, and role.

Evidence and content you upload. TracesOn is built to store compliance evidence your organization uploads — documents, screenshots, policy files, and related metadata. This content belongs to your organization; we process it on your behalf to operate the service.

Usage data. We collect log data such as IP address, browser type, pages visited, and actions taken in the app, to operate, secure, and improve the platform.

Information from integrations. If you connect a third-party tool (for example, Jira), we access the data you authorize — such as issue status and attachments — to keep TracesOn in sync with that tool.

2. How we use information

  • To provide, maintain, and secure the TracesOn platform
  • To authenticate users and enforce organization-level data isolation
  • To send transactional email (evidence requests, dispatch notifications, audit invitations)
  • To respond to support and demo requests you submit to us
  • To monitor for abuse, fraud, and security incidents
  • To improve the product based on aggregated, de-identified usage patterns

3. Subprocessors

We use a small number of vetted subprocessors to operate TracesOn, including our hosting provider (Vercel), database and authentication provider (Supabase), transactional email provider (Resend), background job processor (Inngest), and — for optional AI-assisted evidence review — Anthropic. If you connect Jira, Atlassian processes the data you choose to sync, subject to Atlassian's own terms.

We do not sell your data or your organization's evidence to third parties, and we do not use your evidence content to train AI models outside the scope of the feature you explicitly enable.

4. Data retention and deletion

We retain account and evidence data for as long as your organization maintains an active subscription, plus a reasonable period afterward to allow for account recovery and to meet audit recordkeeping norms. Evidence artifacts that have been accepted as part of a completed audit are retained under a soft-delete model — they are never hard-deleted, consistent with how audit trails are expected to work. You can request deletion of your organization's account and data by contacting us at support@traceson.com.

5. Security

TracesOn is built on a multi-tenant architecture with organization-level data isolation enforced at both the application and database layers. See our Security page for details on how we isolate customer data and protect evidence integrity.

6. Your rights and choices

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to certain processing. Organization administrators can manage most of this directly within TracesOn; for anything else, contact us at support@traceson.com and we will respond within a reasonable timeframe.

7. Cookies

We use essential cookies to keep you signed in and to remember basic preferences. We do not use third-party advertising cookies or cross-site tracking.

8. Children’s privacy

TracesOn is a business product intended for use by working professionals. It is not directed to children, and we do not knowingly collect information from anyone under 16.

9. Changes to this policy

We may update this policy from time to time. If we make material changes, we'll notify organization administrators by email or through the app before the changes take effect.

10. Contact us

Questions about this policy or how we handle your data? Reach us at support@traceson.com.