Tracya
EN FR
← tracya.io
GDPR / Privacy

Privacy Policy

Last updated: July 21, 2026 - Version 2.0

This is an English translation provided for convenience. In the event of any discrepancy, the French version prevails.

1. Data controller

CompanyAthivia Labs SAS
SIREN104 290 911 R.C.S. Metz
AddressCentre d'Affaires - 29 Rue de Sarre, 57070 Metz, France
Emailsupport@tracya.io

In accordance with the General Data Protection Regulation (GDPR - EU 2016/679) and the French Data Protection Act, Athivia Labs SAS is committed to protecting users' privacy. This policy describes the processing for which Athivia Labs SAS acts as data controller, meaning data relating to its customers and to visitors of its websites. Data of the end users of our customers' applications, processed by Tracya as a processor, is governed by the Data Processing Agreement (DPA), available on tracya.io.

Governing language. This policy exists in French and English. In the event of any discrepancy in interpretation between the two versions, the French version prevails.

2. Data collected and legal basis

Account data
DataEmail address, hashed password (bcrypt), account creation date, email verification status.
Legal basisPerformance of contract (Art. 6.1.b GDPR)
RetentionDuration of account, then 3 years after deletion
Authentication & security data
DataJWT tokens (short-lived access token, httpOnly refresh token stored hashed), login logs, failed login history, two-factor authentication status.
Legal basisLegitimate interest, security (Art. 6.1.f GDPR)
RetentionRefresh token: 30 days. Security logs: 90 days.
Subscription & billing data
DataActive plan (Indie / Growth / Scale), subscription status, billing date, Stripe customer ID. Payment card data is processed exclusively by Stripe: we have no access to it.
Legal basisPerformance of contract and legal obligation (Art. 6.1.b & 6.1.c GDPR)
Retention10 years (accounting obligation)
Onboarding flows data
DataFlows created by the customer: CSS selectors, step titles and content, component types, placement settings. No end-user personal data is stored in them by Tracya.
Legal basisPerformance of contract (Art. 6.1.b GDPR)
RetentionDuration of subscription, then 30 days after cancellation
Widget analytics data (end-user events)
DataFlow events: step started, step viewed, step completed, flow completed, flow abandoned, with timestamps. Each event is linked to the project ID and to a pseudonymous visitor identifier: a randomly generated UUID, stable per visitor and per project, stored in the end user's browser. This identifier is not linked to any identity. No names, email addresses or IP addresses are collected.
Role and legal basisTracya acts here as a processor on behalf of its customers, who are the data controllers. The legal basis and, where required, the collection of end-user consent are the customer's responsibility. This processing is governed by the DPA.
Retention13 months rolling
Browser Extension data
DataExtension authentication token (long-lived, revocable), active project ID. Stored locally in chrome.storage.local on the user's device. Never transmitted to third parties.
Legal basisPerformance of contract (Art. 6.1.b GDPR)
RetentionUntil the user revokes the token from the Tracya dashboard or uninstalls the extension.
Transactional emails
DataEmail address used to send account-related messages: email verification, password reset, subscription confirmations, and service notifications.
Legal basisPerformance of contract (Art. 6.1.b GDPR)
RetentionDuration of account

Additional clarification: the Tracya browser extension (Chrome, Edge, Firefox) injects a visual Builder interface solely on the domain of the customer's own web application, and only when the Builder is explicitly activated by the user. The extension does not read, record, intercept, or transmit any content from pages visited by the browser. It communicates exclusively with api.tracya.io. No data from end users of the customer's application is collected by the extension.

3. Cookies and trackers

On tracya.io and app.tracya.io, we use only trackers necessary for the service to function. No advertising, profiling, or third-party audience-measurement cookies are used.

of_refresh_token
TypehttpOnly, Secure, SameSite=Lax cookie (dashboard only)
PurposeMaintains the authenticated dashboard session. Enables silent access token renewal.
Duration30 days
ConsentNot required (strictly necessary)
Stripe
TypePayment tracker (Stripe Payments Europe, Limited)
PurposeSecuring payment transactions and fraud prevention.
DurationSession / per Stripe policy
ConsentNot required (strictly necessary for contract execution)

The Tracya widget, installed by our customers on their own applications, writes to the end user's browser: a pseudonymous visitor identifier (see section 2) and flow display markers (flow already seen, flow seen this session), which are not transmitted to our servers. Informing end users and, where required by applicable law (Article 82 of the French Data Protection Act), collecting their consent are the customer's responsibility, as data controller of its application. The DPA sets out this allocation of roles.

4. Sub-processors and international transfers

We use the following sub-processors to deliver the service. Each provides contractual guarantees compliant with the GDPR.

Hetzner Online GmbHGermany (EU)
Role: Backend hosting, PostgreSQL database, frontend static files
Safeguards: No transfer outside the EU
Policy: hetzner.com/legal/privacy-policy
OVH SASFrance (EU)
Role: Transactional email delivery (SMTP)
Safeguards: No transfer outside the EU
Policy: ovhcloud.com/en/personal-data-protection
Stripe Payments Europe, LimitedIreland (EU)
Role: Payment processing, subscription management. Stripe contracting entity for an account domiciled in France; Stripe Technology Europe, Limited may be an additional party depending on the services. Processing may involve Stripe, Inc. (United States).
Safeguards: Any transfer to the United States is covered by the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses
Policy: stripe.com/privacy

5. Security

  • Encrypted communications (HTTPS/TLS).
  • Passwords hashed with bcrypt.
  • Short-lived JWT access tokens (15 minutes).
  • Auto-rotating refresh tokens, stored hashed in the database.
  • Optional two-factor authentication (TOTP) with recovery codes.
  • Security event logging (login, logout, failed attempts).
  • Global IP-based rate limiting.

6. Legal bases for processing

The table below summarises each processing activity, its legal basis under Art. 6 GDPR, and the applicable retention period.

Processing activity Legal basis (GDPR Art. 6) Retention
Account management Art. 6.1.b - Execution of contract Duration of account + 3 years
Payment & billing
Art. 6.1.b - Execution of contract Art. 6.1.c - Legal obligation (French accounting law)
10 years
Flow analytics (end users) Processor role: legal basis determined by the customer, see DPA 13 months rolling
Security logs Art. 6.1.f - Legitimate interest (fraud & intrusion detection) 90 days
Transactional emails Art. 6.1.b - Execution of contract Duration of account
Extension token storage Art. 6.1.b - Execution of contract Until revocation or uninstall
Dashboard session cookie Strictly necessary, Article 82 of the French Data Protection Act (exempt from consent) 30 days

Legitimate interest: in each case where Art. 6.1.f applies, a balancing test has been carried out to ensure that our legitimate interest is not overridden by the data subject's fundamental rights and freedoms. You may object to any processing based on legitimate interest at any time (Art. 21 GDPR) by writing to support@tracya.io.

7. Your rights (GDPR)

Under the GDPR, you have the following rights:

Right of access (Art. 15)
Obtain a copy of your personal data.
Right to rectification (Art. 16)
Correct inaccurate or incomplete data.
Right to erasure (Art. 17)
Request deletion of your data, subject to legal retention obligations.
Right to restriction (Art. 18)
Request suspension of processing of your data.
Right to data portability (Art. 20)
Receive your data in a structured, machine-readable format.
Right to object (Art. 21)
Object to processing based on legitimate interest.
Right to withdraw consent
At any time, without affecting the lawfulness of prior processing.

To exercise your rights, contact us at support@tracya.io. We will respond within a maximum of 30 days.

If you are unsatisfied with our response, you may lodge a complaint with the CNIL (French Data Protection Authority), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.

8. Amendments

This policy may be updated. In the event of a material change, we will notify you by email. The date of last update is indicated at the top of this page.

9. Contact

For any question regarding this policy or to exercise your rights: support@tracya.io

Legal home Legal notice Terms of sale DPA Security Acceptable use Accessibility FAQ Contact us Cookie preferences
Legal notice Terms of sale DPA Privacy policy Security Acceptable use Accessibility FAQ Contact us Cookie preferences

© 2026 Athivia Labs SAS - All rights reserved.