Privacy Policy
Black Track is an ad tracking and attribution platform for performance advertisers, such as media buyers, agencies and online sellers. This Privacy Policy explains what personal data we collect and process, why we process it, how long we keep it, who we share it with, and the rights and choices you have.
It applies to our website at blacktrack.org, the Black Track application at app.blacktrack.org, the Black Track tracking script and tracking endpoints, and our integrations (together, the "Service"). Black Track is operated by GLOBAL EQUITY ENT. LTDA, a company registered in Brazil. "Black Track", "we", "us" and "our" refer to that company.
Summary
- We collect the information you give us when you create and use a Black Track account, plus the technical data we need to run and secure the Service.
- Our customers use Black Track to measure their own advertising. For the visitor and order data a customer sends to Black Track, the customer decides what is collected and why, and we process it only on that customer's instructions.
- When you connect Meta (Facebook), we use the data Meta shares with us only to provide Black Track to you. We never sell it, never share it with other customers and never use it for our own advertising.
- You can disconnect Meta and ask us to delete your data at any time. See our Data Deletion Instructions.
- Questions about privacy: privacy@blacktrack.org.
Who we are
- Legal name: GLOBAL EQUITY ENT. LTDA
- CNPJ: 64.439.738/0001-32
- Registered office: Praça dos Gerânios 70, Condomínio Portal de Itu, Itu — SP, CEP 13301-619, Brazil
- General contact: contact@blacktrack.org
- Data Protection Officer (Encarregado): Lucas Machado, privacy@blacktrack.org, who also receives privacy requests
Our role: controller and processor
Brazil's General Data Protection Law (Lei Geral de Proteção de Dados, Law No. 13.709/2018, "LGPD") and the EU General Data Protection Regulation ("GDPR") distinguish between the party that decides how and why personal data is processed (the controller, or "controlador") and the party that processes it on the controller's behalf (the processor, or "operador"). Our role depends on the data:
- We are the controller of the data about our own customers and their team members: account and workspace information, billing information, communications with us, and the usage and security logs of our website and application.
- We are a processor of the data our customers collect through the Service about people who visit their websites or buy from them ("End User Data"). The customer is the controller of that data. We process it only to provide the Service to that customer and according to their instructions.
- For Meta Platform Data, we act on behalf of the customer who connected the Meta account, as a service provider (a "Tech Provider" in Meta's terms). We use it only to provide the Service to that customer, as described in Meta Platform Data.
Information we collect
Information you provide
- Account information: your name, email address and password. Passwords are stored only as a secure hash by our authentication provider; we never store them in readable form.
- Workspace information: workspace name, team members and their roles, invitations you send (including the invitee's email address), and your settings, such as campaigns, offers, landing pages, domains, conversion types, attribution settings and integration settings.
- Integration credentials: keys, tokens or webhook secrets you enter to connect a checkout or another service. We use them only to operate that integration.
- Billing information: when you subscribe to a paid plan, the billing contact, company name, tax ID, billing address, plan and invoice history. Payments are processed by the payment provider shown at checkout; we do not receive or store full card numbers.
- Communications: the content of messages you send us, such as support requests, and our replies.
Information collected automatically on our website and application
- Log and device data: IP address, browser and operating system, pages and features used, date and time of access, referring page, and error logs.
- Security data: sign-in events, failed sign-in attempts and other signals we use to protect accounts and the Service.
- Cookies and local storage that are strictly necessary to sign you in and keep your session secure. See Cookies and similar technologies.
Information from Meta
If you connect a Meta business portfolio or ad account, we receive the data described in Meta Platform Data.
Information we process on behalf of our customers (End User Data)
When a customer installs the Black Track script on their pages and connects their checkouts, we process the following on that customer's behalf:
- Click and visit data: a click ID generated by Black Track; IP address; user agent; device type, operating system and browser; approximate location (country, region and city) derived from the IP address by our hosting provider, Cloudflare; network provider; referring page; landing page URL and its parameters, including UTM parameters and ad click IDs such as
fbclid; the Meta browser identifiers stored in the_fbpand_fbccookies, when present; and timestamps. - Interaction data: page views, time on page, video progress, clicks on links and checkout buttons, and custom events the customer chooses to send. Customers can see these interactions in near real time.
- Conversion data sent by the customer's checkout or through postbacks: order or transaction ID, amount, currency, status (for example approved, pending, refunded or charged back), product, payment method, and the buyer's email address and phone number. In conversion records, we store the email address and phone number only as SHA-256 hashes. The original notification sent by the checkout is kept for a limited time in a webhook log, for troubleshooting and reprocessing, and may contain the buyer's details in plain text if the checkout includes them (see How long we keep data).
- Hashed email from the page: if the customer's page explicitly passes an email address to the Black Track script, the script hashes it with SHA-256 in the visitor's browser, so the address itself never reaches our servers. The script does not read form fields on its own.
- Conversions API delivery logs: the events sent to the customer's Meta dataset and Meta's responses.
To attribute a visit that moves from an in-app browser (for example, Instagram's) to the device's default browser, the Service may match the visit to a recent ad click in the same customer's workspace that has the same IP address, operating system and device type, within 60 minutes. This matching never crosses customers' workspaces.
The Service is not designed to process sensitive personal data, such as health information or data revealing racial or ethnic origin, religious beliefs or sexual orientation, and our Terms of Service prohibit customers from sending it.
Meta Platform Data
Black Track lets customers connect Meta (Facebook) through Facebook Login for Business, Meta's official login for business tools. During the connection, you choose the business portfolio, ad accounts and datasets (pixels) that Black Track may access. Meta issues an access token directly to Black Track; we never see your Facebook password. You can change or remove this access at any time in your Facebook or Meta Business settings, or in Black Track.
Permissions we request and the data we receive
- Connection details: the ID and name of the business portfolio you connect, the IDs and names of the ad accounts and datasets you select, the permissions you granted, and the access token Meta issues to Black Track.
public_profile: we read your name and your app-scoped user ID (a Facebook ID that is specific to Black Track). We use them to show which person connected the account and to process deauthorization and data deletion requests that Meta sends us. We do not read other profile fields.ads_read: read-only access to the ad accounts you select. We read the ad account ID, name, currency, time zone and status; the names and IDs of campaigns, ad sets and ads; and ad performance data (insights) such as spend, impressions, clicks, reach and conversions. We retrieve this data periodically, currently about every 15 minutes, to show your ad spend next to the results Black Track tracks and to calculate metrics such as return on ad spend, cost per acquisition and profit. We also use this access to list the datasets you can select for the Conversions API and to send events to them.
We do not request permission to create, edit or pause ads, to manage Pages or to read messages. If a future feature needs another permission, we will update this policy before we ask for it, and you will be asked to approve it through Meta's login.
Conversions API
When you enable a Conversions API integration, Black Track sends conversion events from your own checkouts and pages to the Meta dataset you select, on your instructions. Each event can include the event name, time and ID (used to deduplicate it against the Meta Pixel), the page URL, value, currency, order ID and product details, and customer information parameters: email address and phone number hashed with SHA-256, a hashed external ID, IP address, user agent, and the fbp and fbc browser identifiers. Meta requires IP address and user agent to be sent unhashed.
We send events only from your workspace and only to the datasets you choose. You can also connect a dataset with an access token generated in Meta Events Manager; the same rules apply. Meta processes the events it receives under its own terms, including the Meta Business Tools Terms, with you as the business sharing the data.
How we use Meta Platform Data
We use Meta Platform Data only to provide the Service to the customer who connected it:
- to show ad spend and performance next to Black Track's tracked clicks and conversions in reports and dashboards;
- to match costs to the right campaigns, ad sets and ads, and calculate metrics such as return on ad spend and cost per acquisition;
- to send the customer's own conversion events to the customer's own dataset through the Conversions API;
- to monitor the health of the connection and show errors, such as an expired or revoked token;
- to provide support when the customer asks for it; and
- to keep the Service secure and to comply with Meta's terms and the law.
What we never do with Meta Platform Data
- We never sell, license, rent or purchase it.
- We never share it with other customers, combine it across customers, or use one customer's data to benefit another customer.
- We never use it for our own advertising or marketing, or to build profiles of people.
- We never transfer it to data brokers, advertising networks or other monetization services.
- We never use it to make decisions about a person's eligibility for housing, employment, credit, insurance or education, to discriminate, or for surveillance.
- We never disclose it to anyone except our service providers bound by confidentiality and security obligations, the parties the customer directs us to send it to, or where the law requires it.
Retention and deletion of Meta Platform Data
- We keep the access token only while the connection is active. We delete it as soon as you disconnect in Black Track, remove Black Track in your Facebook or Meta Business settings, or ask us to delete your data.
- We keep the other Meta Platform Data while the connection is active and your workspace exists. After you disconnect or ask for deletion, we delete it within 30 days. Copies in encrypted backups are deleted within up to 30 additional days.
- To request deletion or correction of Meta Platform Data, follow our Data Deletion Instructions or email privacy@blacktrack.org.
We handle Meta Platform Data in accordance with Meta's Platform Terms and Developer Policies.
How we use information and our legal bases
As controller, we use personal data for the purposes below. The legal bases are those of the LGPD (Article 7) and, where the GDPR applies, the GDPR (Article 6).
- To provide the Service: create and manage accounts and workspaces, run tracking, reports and integrations, and process payments. Legal basis: performance of a contract (LGPD Art. 7, V; GDPR Art. 6(1)(b)).
- To keep the Service secure: authenticate users, prevent fraud and abuse, investigate incidents and enforce our Terms. Legal basis: legitimate interests (LGPD Art. 7, IX; GDPR Art. 6(1)(f)).
- To support and communicate with you: answer requests and send service messages, such as security alerts, connection errors and changes to our terms. Legal basis: performance of a contract and legitimate interests.
- To improve the Service: understand how our application is used and how it performs, using aggregated information where possible. We do not use End User Data or Meta Platform Data for this purpose. Legal basis: legitimate interests.
- To send product news: only where you agreed or the law allows it. You can unsubscribe at any time. Legal basis: consent or legitimate interests (LGPD Art. 7, I or IX; GDPR Art. 6(1)(a) or (f)).
- To meet legal obligations: keep access logs as required by Brazil's Internet Civil Framework (Marco Civil da Internet, Law No. 12.965/2014), keep tax and accounting records, and respond to lawful requests from competent authorities. Legal basis: compliance with a legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).
- To establish, exercise or defend legal claims. Legal basis: regular exercise of rights (LGPD Art. 7, VI) and legitimate interests (GDPR Art. 6(1)(f)).
As processor, we use End User Data only to provide the Service to the customer who collected it. The customer is responsible for choosing the legal basis for that processing and for informing the people concerned.
Automated processing. The Service classifies traffic that appears to be automated, such as search engine crawlers, link preview bots, uptime monitors and headless browsers, so that it is excluded from the customer's analytics. This classification only affects reporting. It never changes where a visitor is sent or what content anyone sees. Neither this classification nor the attribution features make decisions that produce legal or similarly significant effects on any person.
How we share information
We do not sell personal data. We share it only as described below.
- Service providers (subprocessors) that host and run the Service for us, under contracts that require them to protect the data and use it only to provide their services to us:
- Cloudflare, Inc. (United States): hosting, edge computing, queues and storage, network security, and IP-based location.
- Supabase, Inc. (United States): managed Postgres database and user authentication. Our database is hosted in the United States (AWS us-east-2, Ohio).
- Meta and other platforms, when a customer directs us to: for example, to send the customer's conversion events to their Meta dataset through the Conversions API, or to send a postback to another advertising platform the customer has configured. We send only the data the customer's settings call for.
- Members of your workspace: people you invite to a workspace can see its data according to the role you give them.
- Legal requirements: when required by law, a court order or a lawful request from a competent authority. We disclose only what is required and, where the law allows, we notify the affected customer first.
- Business transfers: if our company is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction. Any successor must continue to protect it as described in this policy and, for Meta Platform Data, as Meta's Platform Terms require.
- With your consent or at your direction in any other case.
International data transfers
We are based in Brazil, and our service providers process data in other countries, including the United States. Cloudflare runs a global network, so requests to the Service may be handled in the Cloudflare data center closest to the visitor.
We transfer personal data internationally only under the safeguards allowed by Article 33 of the LGPD and, where the GDPR applies, Chapter V of the GDPR, such as the standard contractual clauses approved by the ANPD (Resolution CD/ANPD No. 19/2024) and, for the GDPR, the European Commission's standard contractual clauses, as incorporated in our service providers' data processing agreements. You can ask us for more information about these safeguards at privacy@blacktrack.org.
How long we keep data
We keep personal data only as long as we need it for the purposes described in this policy, unless the law requires us to keep it longer.
- Account and workspace information: while your account is active. After you close your account, we delete it within 30 days, except records we must keep by law.
- Billing and tax records: for the period required by Brazilian tax and accounting law, generally five years.
- Access logs of our website and application: six months, as required by the Marco Civil da Internet, or longer only when a competent authority lawfully requests it.
- Workspace audit log (who changed what, and when): 24 months.
- Click, interaction and conversion data: for the data retention period of the customer's plan, which is 12 months by default, or until the customer deletes it or closes the workspace, whichever comes first. After that, individual records are deleted; aggregated report totals that do not identify any person may remain for the life of the workspace.
- Webhook log (original notifications from checkouts and postbacks): 90 days.
- Outbound postback log: 90 days.
- Conversions API delivery log: 30 days.
- Ad cost synchronization log: 30 days.
- Meta access tokens: until the connection is removed or you ask for deletion, then deleted immediately.
- Other Meta Platform Data: while the connection is active and the workspace exists, then deleted within 30 days of disconnection or a deletion request.
- Support communications: up to 24 months after the conversation ends.
- Backups: data deleted from the Service can remain in encrypted backups for up to 30 more days, until those backups are overwritten. Backups are used only to restore the Service after a failure.
When a workspace is closed, we delete its data within 30 days, subject to the backup period above and to any record we must keep by law.
Security
We protect personal data with technical and organizational measures appropriate to the risk, including:
- encryption in transit (HTTPS/TLS) and encryption at rest;
- strict separation between customers: every request is checked against the workspace it belongs to, and the database enforces that separation again with row-level security;
- Meta access tokens that are used only by our servers, never shown in the application, and stored in our access-controlled database, and integration credentials that only authorized members of the workspace can access;
- hashing of email addresses and phone numbers in conversion records and in events sent to Meta;
- access to production systems limited to the people who need it, with strong authentication;
- secrets kept in dedicated secret storage, never in source code; and
- audit logs of changes made in each workspace.
No system is completely secure. If a security incident affects personal data, we will notify affected customers without undue delay and notify Brazil's National Data Protection Authority (ANPD), affected people and, for Meta Platform Data, Meta, as required by law and by Meta's terms.
Your rights
Under the LGPD (Brazil)
Under Article 18 of the LGPD, you have the right to:
- confirmation that we process your personal data, and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of data that is unnecessary, excessive or processed in breach of the LGPD;
- portability of your data to another provider, subject to ANPD regulations and to trade secrets;
- deletion of data processed on the basis of your consent;
- information about the public and private entities we share your data with;
- information about the possibility of not giving consent and the consequences of refusing;
- withdrawal of consent at any time;
- objection to processing carried out on another legal basis, if it does not comply with the LGPD; and
- review of decisions made solely by automated processing that affect your interests (Article 20).
You also have the right to file a complaint with Brazil's National Data Protection Authority (Autoridade Nacional de Proteção de Dados, ANPD) at www.gov.br/anpd. We encourage you to contact us first so we can try to resolve your concern.
Under the GDPR (European Economic Area and United Kingdom)
Where the GDPR or the UK GDPR applies, you have the right to access, rectify and erase your personal data, to restrict or object to its processing, to data portability, and to withdraw consent at any time without affecting processing carried out before the withdrawal. You also have the right to lodge a complaint with the data protection supervisory authority where you live or work, or where an alleged infringement took place.
Other privacy laws
If you live in a place with other privacy laws, such as some U.S. states, you may have similar rights, and we will honor them as those laws require. We do not sell personal data or share it for cross-context behavioral advertising.
How to exercise your rights
Email privacy@blacktrack.org. We may ask you to confirm your identity before we act on a request, for example by replying from the email address on your account. We will respond within the time the law requires: for a complete LGPD access request, within 15 days; for GDPR requests, within one month, which may be extended where the GDPR allows. Exercising your rights is free of charge.
If your request concerns End User Data that we process on behalf of a customer, we will forward it to that customer, who is the controller, and help them respond.
If you visited a website that uses Black Track
If you visited a website, clicked an ad or bought from a business that uses Black Track, that business is responsible for the data collected about you and decides how it is used. Its own privacy policy should explain this. We process that data only on the business's behalf.
- To exercise your rights, contact the business directly. If you contact us instead, tell us the website or business concerned, and we will forward your request to them and help them respond.
- You can delete or block cookies in your browser settings. Doing so removes the Black Track click ID from that browser.
- We never combine data about you across different businesses that use Black Track.
Cookies and similar technologies
On our website and application
We use only cookies and browser storage that are strictly necessary to sign you in, keep your session secure and remember basic preferences. We do not use advertising cookies or third-party analytics cookies on blacktrack.org or app.blacktrack.org. If this changes, we will update this policy and ask for consent where the law requires it.
On our customers' websites
When a customer installs the Black Track script on their website, the script runs on the customer's own domain, and the customer decides whether and how to use it. The script can use:
btkcookie: a first-party cookie set on the customer's domain that stores a random Black Track click ID, so that a later purchase can be attributed to the ad or link that brought the visitor. It lasts for the attribution window the customer configures: 90 days by default and never more than 180 days.- Session and local storage: a copy of the click ID for the current browsing session, and counters that give each event a unique ID so it is not counted twice.
- Meta cookies: the script reads the
_fbpand_fbccookies set by the Meta Pixel, when they exist, so that events sent through the Conversions API can be matched by Meta. Black Track does not set these cookies.
The click ID is specific to each customer's workspace and is not used to follow people across different customers' websites. Customers are responsible for telling their visitors about these technologies and for obtaining consent where the law requires it.
Children
The Service is a business tool for adults. You must be at least 18 years old to create an account. We do not knowingly collect personal data from children, and our Terms prohibit customers from using Black Track on websites or offers directed to children. If you believe a child has provided personal data to us, contact privacy@blacktrack.org and we will delete it.
Changes to this policy
We may update this policy to reflect changes in the Service or in the law. We will change the "Last updated" date at the top of this page and, if the changes are material, notify customers by email or in the application before they take effect. The current version is always available at blacktrack.org/privacy.
Contact us
For questions about this policy or to exercise your rights, contact our Data Protection Officer (Encarregado), Lucas Machado, at privacy@blacktrack.org. For anything else, write to contact@blacktrack.org.
GLOBAL EQUITY ENT. LTDA
CNPJ 64.439.738/0001-32
Praça dos Gerânios 70, Condomínio Portal de Itu, Itu — SP, CEP 13301-619
Brazil