Legal

Privacy Policy

Privacy Policy

Privacy Policy

Effective date: 8 July 2026 · Last updated: 8 July 2026

Summary

NexusMedia Denis Werbicki, a sole proprietorship (jednoosobowa działalność gospodarcza) registered in Poland, operated by Denis Werbicki, d/b/a “TrackYourApp”.

ul. Dziatwy 18B/32, 03-109 Warsaw, Poland · EU VAT / NIP: PL5242901092

Throughout this Policy, the “In plain terms” boxes are informal summaries provided for convenience only. The numbered clauses are the legally binding text; if a summary and a clause conflict, the clause governs.

1. Introduction, our roles & contact

1.1 Who we are

This Privacy Policy (the “Policy”) describes how NexusMedia Denis Werbicki, a sole proprietorship (jednoosobowa działalność gospodarcza) registered in Poland and operated by Denis Werbicki, doing business as “TrackYourApp” (“TrackYourApp”, the “Provider”, “we”, “us” or “our”), collects, uses, discloses and protects personal data. Our registered address is ul. Dziatwy 18B/32, 03-109 Warsaw, Poland, and our EU VAT / NIP is PL5242901092.

For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), and comparable laws, the Provider is the entity responsible for the processing described in this Policy where it acts as controller.

1.2 Scope

This Policy applies to personal data processed in connection with:

• our marketing website at https://trackyourapp.dev;

• our hosted application at https://app.trackyourapp.dev (the “App”); and

• the self-hostable dashboard, our HTTP API, our MCP (Model Context Protocol) endpoint, and related services,

together, the “Service”. A person who registers for or uses the Service is a “User” (“you”). The Service is offered to business and professional users; the contractual terms are set out in our Terms of Service. Nothing in this Policy limits any mandatory data-protection right you have under the law of your country of habitual residence, including your rights in Section 10 and the ability to complain to a supervisory authority.

1.3 Our two roles

We process personal data in two distinct capacities, and the role matters for your rights:

• Controller of Account Data. When you register for and use the Service, we determine the purposes and means of processing your account and usage information. We are the controller of “Account Data” (defined in Section 2).

• Processor of Connected Data. When you connect an optional integration (Google Analytics or Shopify Partner), we access and process the resulting “Connected Data” (defined in Section 2) solely on your documented instructions. In respect of Connected Data, you are the controller and we are the processor. That relationship is governed by our Data Processing Agreement (“DPA”), which is incorporated by reference and prevails over this Policy to the extent of any conflict about Connected Data.

1.4 How to contact us about privacy

For all privacy matters — including data-subject and consumer requests under the GDPR, UK GDPR, FADP, CCPA/CPRA, PIPEDA, Quebec Law 25 and similar laws, and to request our DPA — contact us at privacy@trackyourapp.dev. Postal contact details are in Section 15.

We are not required to appoint, and have not appointed, a Data Protection Officer under Article 37 GDPR; you may direct all privacy queries to privacy@trackyourapp.dev. As an EU-established controller, we are not required to designate a representative under Article 27 GDPR. Our designated person in charge of the protection of personal information for the purposes of Quebec Law 25 (our “Privacy Officer”) is also reachable at that address (Section 12).

2. Personal data we collect

2.1 Account Data (we are the controller)

“Account Data” means personal data relating to you as a User and to your use of the Service, including:

• Identity & contact: your full name and email address.

• Authentication data: your Google OAuth identifier when you sign in with Google, and one-time passcodes (OTP) used to verify sign-in. Passwords, where set, are stored only as salted cryptographic hashes; some accounts are OAuth-only and have no password. These account-access credentials are treated as sensitive personal information under certain US state laws (see Section 11.1).

• Account, plan & preferences: your account settings, current Plan, notification and email-digest preferences, followed apps and competitors, excluded keywords and similar configuration.

• Product usage & technical logs: IP address, device and browser characteristics, request timestamps, pages/endpoints accessed, and diagnostic and error information generated as you use the Service.

• Billing metadata from Paddle: limited transaction metadata (such as plan purchased, amount, currency, invoice reference, billing country and the last four digits/card brand where provided by Paddle). We do not receive or store full payment-card numbers or equivalent full payment credentials — those are handled by Paddle as described in Sections 6 and 3.

2.2 Connected Data (we are the processor)

“Connected Data” means data that you authorize us to access from your third-party accounts through optional integrations. You are the controller of Connected Data; we process it only to provide the Service to you. It may include:

• Google Analytics (via Google OAuth): analytics about visitors to your Shopify App Store listing, such as sessions, traffic sources, conversions and related aggregated statistics for the properties you select.

• Shopify Partner data: app events (installs, uninstalls, subscriptions, and payment/transaction events) and general merchant information such as merchant email and merchant location.

We do not persist raw sensitive exports of Connected Data. We may cache limited aggregated financial and conversion statistics in order to render your dashboards. OAuth access and refresh tokens for these integrations are stored encrypted and are revoked when you disconnect the integration or delete your account. See Section 4 for details.

2.3 Publicly available Shopify App Store data

The Service tracks positions of apps and keywords on the Shopify App Store using publicly available App Store data (for example, listing titles, ratings, review counts, descriptions, prices and ranking positions). This tracked data is shared across the Service and is generally not personal data about you; where any personal data appears in such public listings, we process it for the legitimate interest of providing the tracking Service.

2.4 Cookies and similar technologies

We and our providers use cookies and similar technologies on the marketing site and the App. Essential cookies keep you signed in and secure the Service; non-essential cookies are used only with your consent where required. Full details are in our Cookie Policy.

2.5 Sources of data

We obtain personal data from: (a) you directly, when you register, configure the Service or contact support; (b) your device and browser automatically, as you use the Service (usage and log data); (c) the integrations you connect (Google, Shopify Partner), acting on your authorization; (d) Paddle, our Merchant of Record, which provides limited billing metadata; and (e) public Shopify App Store sources.

2.6 Whether provision of data is required

Providing your identity, contact and authentication data is necessary to create and operate your account; if you do not provide it, we cannot make the Service available to you. Providing optional integration data is entirely voluntary and is processed only if you choose to connect an integration; you may decline or disconnect at any time without affecting your ability to use the core Service.

3. How and why we use personal data, and our legal bases

Where the GDPR or UK GDPR applies, we rely on the following legal bases. Where the Swiss FADP applies, we process on the equivalent grounds (in particular contract performance, overriding legitimate interest, legal obligation and consent).

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms and concluded that our processing does not override them; you may object as described in Section 10, and you may obtain further information about our balancing assessment on request. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Electronic marketing. We send direct marketing or promotional electronic messages only where you have given the prior consent required under applicable e-privacy law — including the ePrivacy Directive (2002/58/EC) and, in Poland, Article 172 of the Telecommunications Law (Prawo telekomunikacyjne) and Article 10 of the Act on Providing Services by Electronic Means (ustawa o świadczeniu usług drogą elektroniczną). This consent requirement applies to business (B2B) recipients as well, and it is separate from, and not displaced by, any legitimate-interest basis under the GDPR. You may withdraw marketing consent at any time, including via the unsubscribe link in each message.

We do not use your personal data to make decisions based solely on automated processing that produce legal or similarly significant effects concerning you, and we do not carry out such automated decision-making or profiling. We may derive limited inferences from your settings and usage to operate and improve the Service, but we do not use those inferences for automated decisions with legal or similarly significant effects.

4. Connected integrations

4.1 What we access

If you choose to connect an integration, we access the following on your authorization:

• Google Analytics (Google OAuth): analytics about visitors to your Shopify App Store listing for the Google Analytics properties you select.

• Shopify Partner: app events (installs, uninstalls, subscriptions, payment/transaction events) and general merchant information such as merchant email and merchant location.

4.2 We act only on your instructions (processor role)

For Connected Data we act solely as your processor, on your documented instructions, and only to provide the Service to you. Our processing of Connected Data is governed by the DPA. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements; likewise, our use of Shopify Partner data adheres to Shopify’s applicable terms.

4.3 We do not sell; we cache only aggregated statistics

We do not sell Connected Data and do not use it for advertising. We do not persist raw sensitive exports. To render your dashboards we may cache limited aggregated financial and conversion statistics. We do not route Connected Data to our AI-assisted software development tooling (Claude, provided by Anthropic, PBC) in the ordinary course of business (see Section 6, Sub-processor 8).

4.4 Tokens and how to disconnect

OAuth access and refresh tokens are stored encrypted. You may disconnect any integration at any time from your account settings. On disconnection — and on account deletion — the associated OAuth tokens are deleted and/or revoked, and cached aggregated statistics associated with that integration are removed in accordance with Section 8.

5. Cookies & similar technologies

We use cookies, local storage and similar technologies to keep you signed in, secure the Service, remember your preferences and, subject to your consent where required, to measure and improve the Service. Strictly necessary cookies do not require consent; all other categories are set only where you have consented, and you can change your choices at any time. For the categories we use, their purposes and durations, and how to manage them, see our Cookie Policy.

6. Disclosure & Sub-processors

6.1 Sub-processors

We engage the following sub-processors to help provide the Service. Each is bound by a written contract imposing data-protection obligations no less protective than those in the GDPR and our DPA. The same table appears in Annex III of our DPA. The numbering below is used for cross-references elsewhere in this Policy.

6.2 Paddle as an independent controller for payment data

Paddle.com Market Ltd acts as our Merchant of Record and as an independent controller of the payment and cardholder data it collects at checkout. Paddle’s processing of that data is governed by Paddle’s own privacy notice and Buyer Terms. We receive only limited billing metadata from Paddle (Section 2.1).

6.3 Other disclosures

We may also disclose personal data: (a) to professional advisers (lawyers, accountants, auditors) under confidentiality; (b) to competent authorities, courts or other third parties where required to comply with a legal obligation, lawful request or valid legal process, or to establish, exercise or defend legal claims; and (c) to a successor entity in connection with a merger, acquisition, financing or sale of assets, subject to this Policy or a notice at least as protective.

6.4 No sale, no cross-context behavioral advertising

We do not sell personal information and do not “share” it for cross-context behavioral advertising, as those terms are defined under US state privacy laws, and we have not done so. See Section 11.

7. International data transfers

Our primary hosting and infrastructure are located in the EEA (Amsterdam, Netherlands). Some sub-processors (Section 6.1) process personal data in the United States or other countries outside the European Economic Area, the United Kingdom or Switzerland. Where we transfer personal data to such countries, we rely on one or more of the following safeguards:

• the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914, the “SCCs”);

• the UK International Data Transfer Addendum to the SCCs (or the UK IDTA) for UK transfers;

• for transfers subject to the FADP, the SCCs as adapted by the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) — so that references to the GDPR and to EU institutions are read as references to the FADP and the FDPIC, and (where applicable) the protection extends to data about legal entities;

• an adequacy decision of the European Commission, the UK or Switzerland, where available for the destination — including, where a US recipient is self-certified under an applicable framework such as the EU–US Data Privacy Framework (and its UK Extension / Swiss–US framework), reliance on that adequacy decision; and/or

• additional technical, organizational and contractual safeguards where appropriate following a transfer impact assessment.

You may request a copy of the relevant safeguards, or information about where a specific transfer takes place, by emailing privacy@trackyourapp.dev (we may redact commercially confidential or third-party information).

8. Data retention

We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by law:

• Account Data is retained while your account is active and you use the Service.

• On account deletion, records associated with the account are deleted from our production systems within 48 hours, except for the limited data we are required or permitted to retain (for example, billing and tax records, and data needed to comply with a legal obligation or to establish, exercise or defend legal claims), which is retained only for the period and to the extent necessary and then deleted or anonymized.

• Product usage, technical and security logs are retained for up to 12 months and then deleted or anonymized, unless a longer period is required to investigate a security incident or to establish, exercise or defend a legal claim. Such logs may outlive the account where necessary for these purposes.

• Encrypted backups stored with Dropbox rotate on a rolling basis; residual data is retained encrypted and overwritten within 12 months.

• OAuth tokens are deleted and/or revoked on integration disconnect or account deletion.

• Limited billing and tax records may be retained for the periods required by applicable tax and accounting law, after which they are deleted or anonymized.

Where no fixed period is stated above, we determine retention by reference to the purpose of the processing, our legal obligations, and any applicable limitation periods for legal claims, after which the data is deleted or anonymized.

9. Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and accidental loss, destruction or damage, including:

• Encryption in transit (TLS/HTTPS) and encryption at rest for sensitive data, including encrypted storage of OAuth tokens and encrypted off-site backups;

• access controls on a least-privilege, need-to-know basis, with authentication for administrative access;

• monitoring of application performance and errors via Laravel Nightwatch, and logging to support security and incident response;

• vetted sub-processors bound by confidentiality and data-protection obligations.

Despite these measures, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach affecting your data, we will notify you and the competent authorities where and as required by applicable law (see Section 12 for our Canadian breach-reporting commitments).

10. Your EEA / UK / Swiss rights

Subject to the conditions and exceptions in the GDPR, UK GDPR and FADP, you have the right to:

• Access your personal data and obtain a copy;

• Rectification of inaccurate or incomplete data;

• Erasure (“right to be forgotten”) in certain circumstances;

• Restriction of processing in certain circumstances;

• Data portability — to receive data you provided in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller;

• Object to processing based on our legitimate interests, and to object at any time to direct marketing;

• Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing;

• Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects — we perform no such automated decision-making.

To exercise any right, email privacy@trackyourapp.dev. We will respond within one month of receipt, extendable by two further months for complex or numerous requests (we will tell you if an extension applies). We may need to verify your identity.

You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, “UODO”), ul. Stawki 2, 00-193 Warsaw, Poland. EEA residents may also contact their local supervisory authority; UK residents may contact the Information Commissioner’s Office (ICO). Individuals in Switzerland may contact the Federal Data Protection and Information Commissioner (FDPIC); note, however, that under the revised FADP the FDPIC does not adjudicate individual complaints in the way an EU supervisory authority does, and Swiss data subjects generally enforce their rights before the competent Swiss civil courts. We would, in every case, appreciate the chance to address your concerns first.

11. US privacy rights

11.1 Notice at collection and categories

This section supplements the Policy for residents of California under the California Consumer Privacy Act, as amended by the CPRA (together, “CCPA”), and provides the “notice at collection” required by California law. The table below describes the categories of personal information we collect, the business or commercial purposes, the categories of recipients, and the retention period or criteria for each category.

Sensitive personal information. The only sensitive personal information we collect is the account access credentials identified above (your Google OAuth identifier and one-time passcodes). We collect and use it solely to perform the Service and secure your account. We do not use or disclose sensitive personal information for purposes that would trigger the right to limit under Cal. Civ. Code § 1798.121, so no “Limit the Use of My Sensitive Personal Information” link is required.

11.2 No sale or sharing

We do not sell your personal information and do not “share” it for cross-context behavioral advertising, and we have not done so in the preceding twelve (12) months (or, if the Service or the relevant processing has existed for less than twelve months, since it began). We also do not knowingly sell or share the personal information of consumers under 16. Because we do not sell or share personal information, we do not provide a “Do Not Sell or Share My Personal Information” link, and no such link is required under the CCPA.

11.3 Your California rights

• Right to know / access the categories and specific pieces of personal information collected, the sources, purposes and recipients;

• Right to delete personal information, subject to legal exceptions;

• Right to correct inaccurate personal information;

• Right to opt out of the sale or sharing of personal information (not applicable, as we do neither);

• Right to limit the use and disclosure of sensitive personal information (we do not use it beyond permitted purposes);

• Right to non-discrimination for exercising your rights.

How to exercise. Submit a request to privacy@trackyourapp.dev. We will verify your request by matching the information you provide against our records; for sensitive requests we may require additional verification. You may use an authorized agent with your written permission (and we may require verification of your identity and the agent’s authority). We will respond within 45 days, extendable by a further 45 days with notice.

California “Shine the Light”. California residents may request information about disclosures of personal information to third parties for their direct-marketing purposes; we do not make such disclosures.

11.4 Other US states

Residents of Virginia, Colorado, Connecticut, Utah, Texas and other US states with comprehensive consumer-privacy laws have equivalent rights — including to access, correct, delete and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, and profiling in furtherance of decisions that produce legal or similarly significant effects. We do not engage in targeted advertising or the sale of personal data, and we do not carry out profiling in furtherance of decisions that produce legal or similarly significant effects (see Section 3). We may derive limited inferences to operate and improve the Service, but we do not use them for such automated decisions.

The categories of personal information we process, our purposes, the categories of recipients, and how to exercise your rights are described in Sections 2, 3, 6 and this Section 11, and those disclosures are intended to satisfy the privacy-notice requirements of the Virginia, Colorado, Connecticut, Utah and Texas statutes. We do not process sensitive data for the purposes of sale or targeted advertising, which also addresses the specific disclosure required under the Texas Data Privacy and Security Act (§ 541.102) by negative.

Appeals. If we decline to act on your request, you may appeal by emailing privacy@trackyourapp.dev with “Privacy Appeal” in the subject line within a reasonable time after our decision. We will respond to your appeal within 45 days (60 days for Colorado and Connecticut, and otherwise as the applicable state law requires), and if we deny the appeal we will provide you with a means to contact your state Attorney General to submit a complaint.

12. Canada (PIPEDA & Quebec Law 25)

Where the Personal Information Protection and Electronic Documents Act (“PIPEDA”) applies, we handle personal information in accordance with its ten fair-information principles: accountability; identifying purposes; consent; limiting collection; limiting use, disclosure and retention; accuracy; safeguards; openness; individual access; and challenging compliance.

PIPEDA breach reporting. Under PIPEDA, where a breach of security safeguards creates a real risk of significant harm, we will report the breach to the Office of the Privacy Commissioner of Canada (OPC) and notify affected individuals as soon as feasible, and we maintain records of all breaches of security safeguards as required by law.

Where Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25, applies:

• our designated person in charge of the protection of personal information (Privacy Officer) is reachable at privacy@trackyourapp.dev;

• we conduct privacy impact and transfer assessments where required before transferring personal information outside Quebec;

• you may exercise rights of access and rectification; portability of the computerized personal information you provided to us, in a structured, commonly used technological format; and, in the circumstances provided by Law 25, de-indexing (cessation of dissemination);

• we obtain consent as required and inform you of the purposes at or before collection; and

• we will report confidentiality incidents presenting a risk of serious injury to the Commission d’accès à l’information (CAI) and to affected individuals, and keep a register of such incidents, as required.

We will respond to access and correction requests under PIPEDA and Quebec Law 25 within 30 days of receipt (extendable as those laws permit).

13. Children

The Service is intended for business and professional users and is not directed to individuals under 18. The minimum age to register is 18. We do not knowingly collect personal data from anyone under 18, and the Service is not directed to children under 13 for the purposes of the US Children’s Online Privacy Protection Act (COPPA). If we learn that we have collected personal data from a person under 18, we will delete it. If you believe a minor has provided us personal data, contact privacy@trackyourapp.dev.

14. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date and provide reasonable notice by posting the revised Policy and, where appropriate, notifying you by email or within the App before the change takes effect. Your continued use of the Service after the effective date of an update constitutes acceptance of the revised Policy, except where separate consent is required by law.

Contact

Questions or rights requests

To exercise any of the rights in this Policy, or for any privacy question, contact us at privacy@trackyourapp.dev or by post at the address below. We aim to respond promptly and within the statutory timelines — approximately one month under the GDPR/UK GDPR/FADP, 45 days under the CCPA and comparable US state laws, and 30 days under PIPEDA and Quebec Law 25 (each extendable as those laws permit). We may need to verify your identity before acting on a request.

Postal address

ul. Dziatwy 18B/32, 03-109 Warsaw, Poland

TrackYourApp

Full-funnel analytics for Shopify app developers.
Rankings are a means. Revenue is the metric.

© 2026 TrackYourApp

Company

TrackYourApp

Full-funnel analytics for Shopify app developers.
Rankings are a means. Revenue is the metric.

© 2026 TrackYourApp

Company