Privacy Policy

Last updated: March 26, 2026

1. Introduction

Power Consulting, LLC ("Company," "we," "us," or "our"), a Washington State limited liability company, operates the Trcker affiliate tracking platform at trcker.io ("Service"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Name and email address
  • Password (stored as a one-way hash, never in plain text)
  • Account role (Brand or Partner)
  • Company or website information (if provided)

2.2 Tracking Data

When end users click affiliate links or complete conversions, we automatically collect:

  • IP address
  • Browser type and version (User-Agent)
  • Device type and operating system
  • Referring URL
  • Approximate geographic location (country, region, city — derived from IP address)
  • Click timestamps and conversion events

This data is collected for the purpose of affiliate attribution, fraud detection, and reporting. It is associated with the Brand's affiliate program, not with individual user profiles.

2.3 Cookies

We use the following cookies:

  • trcker_click_id — A first-party tracking cookie set when a user clicks an affiliate link. Used to attribute conversions to the correct partner. Expires after 90 days. This cookie is essential for the Service to function.
  • Session cookies — Used to maintain your authenticated session when logged into the dashboard. These are essential cookies.

2.4 Analytics

We use Vercel Analytics to collect anonymous, aggregated usage data about how visitors interact with our marketing pages. This data does not identify individual users and is used solely to improve the Service. Vercel Analytics does not use cookies and is privacy-focused by design.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Track clicks and attribute conversions to the correct affiliate partner
  • Detect and prevent fraud (bot filtering, velocity checks, IP scoring)
  • Send transactional emails (account setup, partner onboarding, daily reports)
  • Process payments and manage subscriptions
  • Respond to support requests
  • Comply with legal obligations

4. How We Share Your Information

We do not sell your personal information. We share information only in these circumstances:

4.1 Service Providers

We use the following third-party services to operate the platform:

  • Vercel — Hosting, deployment, and analytics
  • Neon — Database hosting (PostgreSQL)
  • Upstash — Rate limiting and caching (Redis)
  • Resend — Transactional email delivery
  • Dub — Branded short link generation

These providers process data on our behalf and are bound by their own privacy policies and data processing agreements.

4.2 Brand-Partner Data Sharing

Brands can view performance data (clicks, conversions, earnings) for Partners in their affiliate program. Partners can view their own performance data. We do not share one Brand's data with another Brand.

4.3 Legal Requirements

We may disclose your information if required by law, subpoena, court order, or government regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

5. Data Retention

We retain tracking data (clicks, conversions) for up to 24 months from the date of collection. Account information is retained for the duration of your account plus 90 days after deletion. Fraud-related data for banned or rejected partners is anonymized after 90 days but retained for cross-reference purposes.

6. Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption in transit (TLS/HTTPS on all connections)
  • Encryption at rest for sensitive data (API keys, secrets)
  • Password hashing with bcrypt
  • Rate limiting on all public endpoints
  • Security headers (HSTS, CSP, X-Frame-Options)

No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Your Rights

7.1 All Users

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your account and associated data
  • Export your data in a portable format

7.2 California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know — You may request that we disclose the categories and specific pieces of personal information we have collected about you.
  • Right to Delete — You may request that we delete your personal information, subject to certain exceptions.
  • Right to Non-Discrimination — We will not discriminate against you for exercising your privacy rights.
  • No Sale of Personal Information — We do not sell personal information as defined by the CCPA.

To exercise any of these rights, contact us at legal@trcker.io. We will respond to verifiable requests within 45 days.

8. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will delete that information promptly.

9. International Data Transfers

The Service is hosted in the United States. If you access the Service from outside the United States, your information may be transferred to and processed in the United States. By using the Service, you consent to this transfer.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the revised policy.

11. Contact Us

For privacy-related questions or to exercise your rights, contact us at:

legal@trcker.io
Power Consulting, LLC
Washington State, United States