Legal

Privacy Policy

Effective date: March 8, 2026

1. Overview

TrackToClose (“we,” “us,” or “our”) operates the TrackToClose CRM platform accessible at tracktoclose.io (the “Service”). This Privacy Policy explains what information we collect, how we use it, and your rights with respect to that information.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Information You Provide

  • Account information: your name, email address, phone number, brokerage name, license number, and password when you create an account.
  • CRM data: contact records, deal information, task lists, activity logs, notes, and any other data you enter into the Service.
  • Waitlist information: name, email, phone, role, state, current CRM, and feature priorities collected when you join the waitlist.
  • Communications: support messages, feedback, and correspondence you send us.

2.2 Information Collected Automatically

  • Usage data: pages visited, features used, actions taken, and timestamps.
  • Device and browser information: IP address, browser type, operating system, referring URL.
  • Cookies and similar technologies: session cookies required for authentication. We do not use third-party advertising cookies.
  • Login audit: date, time, IP address, and success/failure status of login attempts, used for security monitoring.

2.3 Third-Party Integrations

If you connect Google Drive, we receive OAuth tokens allowing read-only access to files you explicitly select through the Google Picker. We do not receive access to your entire Drive. You can revoke this access at any time from your Google account settings or from TrackToClose Settings → Integrations.

3. How We Use Your Information

  • To provide, operate, and improve the Service.
  • To authenticate your identity and maintain account security.
  • To send you transactional communications (e.g., password reset, task reminders) you have configured.
  • To send waitlist updates and launch announcements to users who opted in (1–2 emails before launch, as stated at signup).
  • To detect and prevent fraud, abuse, and security incidents.
  • To comply with applicable laws and legal obligations.

We do not sell your personal data to third parties. We do not use your CRM data for advertising or share it with data brokers.

4. Data Storage and Security

All data is stored on Supabase (PostgreSQL hosted on AWS us-east-1) with encryption at rest (AES-256) and in transit (TLS 1.2+). Authentication is handled by Supabase Auth.

We implement row-level security so that your data is only accessible to your account. We support optional two-factor authentication (TOTP) and enforce a 30-minute idle timeout for added protection.

While we take reasonable measures to protect your data, no system is completely secure. We cannot guarantee absolute security.

5. Data Retention

We retain your account data for as long as your account is active. If you cancel your subscription, we retain your data for 30 days to allow reactivation, after which it is permanently deleted. Waitlist records are retained until you request removal or the waitlist closes.

You may request deletion of your account and all associated data at any time by emailing hello@tracktoclose.io.

6. Sharing Your Information

We may share your information with:

  • Service providers: Supabase (database and auth), Vercel (hosting), Resend (transactional email), Twilio (SMS, if applicable). These providers process data only as necessary to deliver the Service.
  • Legal requirements: if required by applicable law, regulation, or valid legal process.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to you.

7. Your Rights

Depending on your location, you may have rights under applicable privacy laws (including the New Jersey Data Privacy Act and GDPR where applicable) to:

  • Access the personal data we hold about you.
  • Correct inaccurate personal data.
  • Request deletion of your personal data.
  • Export your data in a machine-readable format (available via Settings → Export).
  • Opt out of marketing communications (unsubscribe link in every email).

To exercise any of these rights, contact us at hello@tracktoclose.io.

8. Cookies

We use only essential session cookies required for authentication. We do not use analytics, advertising, or tracking cookies from third parties. You may disable cookies in your browser settings, but doing so will prevent you from logging in.

9. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such information, contact us at hello@tracktoclose.io and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice in the Service at least 14 days before the changes take effect. Your continued use of the Service after that date constitutes acceptance of the updated policy.

11. Contact Us

Questions about this Privacy Policy? Contact us at:

TrackToClose

Email: hello@tracktoclose.io

New Jersey, United States