Privacy Policy

Last updated: June 6, 2026

This Privacy Policy explains how CapiTracker collects, uses, stores, and shares information when you use the CapiTracker service, dashboard, WooCommerce plugin, Shopify integration, API endpoints, and related tools.

1. Information We Collect

CapiTracker may collect account information, business settings, connected store configuration, allowed domains, platform identifiers, Meta ad account and Pixel identifiers, API connection status, billing or subscription status, and support communications.

2. Tracking and Event Data

When installed on a store, CapiTracker may process event and attribution data such as event name, event ID, page URL, referrer, UTM parameters, Meta click/browser identifiers, browser user agent, IP address, product IDs, product names, cart data, order ID, order status, order totals, currency, timestamps, and hashed customer contact fields when available.

3. WooCommerce and Shopify Data

For commerce reporting and event routing, CapiTracker may process product, order, checkout, refund, customer, and fulfillment information received from connected commerce platforms. The specific data depends on enabled integrations and store configuration.

4. Meta and Advertising Integrations

CapiTracker may use configured Meta credentials to send Conversions API events, read advertising performance data, and connect ad account information to store activity. Meta access tokens are stored server-side in CapiTracker and are not exposed in public browser scripts by the CapiTracker WordPress plugin.

5. How We Use Information

  • Provide tracking, attribution, reporting, and synchronization features.
  • Route browser and server-side events to configured destinations.
  • Detect setup issues, duplicate events, API failures, and integration health.
  • Improve dashboard functionality, reliability, and support.
  • Comply with legal, security, and platform requirements.

6. External Services

CapiTracker connects with external services selected or configured by the customer, including WooCommerce, Shopify, Meta, Ecomcountant, hosting providers, delivery/status APIs, and payment providers. Those services process information according to their own policies.

7. Cookies and Browser Storage

The CapiTracker plugin may use an opaque first-party visitor identifier, a rotating session identifier, and attribution information such as observed click IDs, browser IDs, UTM parameters, landing page, and sanitized referrer so legitimate events can be connected to store sessions and orders. CapiTracker does not create paid identifiers that were not observed and does not derive a visitor identity from an IP address and user agent.

8. Data Sharing

CapiTracker does not sell customer data. Data may be shared with configured integrations, infrastructure providers, analytics or logging systems used to operate the service, legal authorities when required, and service providers needed to deliver CapiTracker functionality.

9. Security

We use technical and organizational measures designed to protect stored credentials and customer data. First-party visitor identifiers are stored in store-scoped hashed form where appropriate, and customer matching fields sent to supported advertising integrations are normalized and hashed. No system can be guaranteed completely secure, and customers are responsible for protecting their own accounts, domains, API keys, and connected platform credentials.

10. Data Retention

Tracking identities, sessions, evidence, and delivery records are subject to configured retention periods and may be purged when they expire. Commerce orders remain controlled by the connected commerce platform and are not deleted by a CapiTracker identity-erasure request.

11. Customer Responsibilities

Customers are responsible for providing any notices, cookie banners, consent mechanisms, privacy disclosures, and legal bases required for their stores, regions, and advertising platforms. Customer matching, anonymous external identifiers, IP addresses, and user agents are restricted by the configured consent and lawful-use policy.

12. Your Choices

You may disable integrations, remove tracking scripts, revoke platform credentials, withdraw applicable consent, or request erasure of retained tracking identity data through CapiTracker. Identity erasure removes eligible tracking links and payload data without modifying WooCommerce orders. Some requests require identity or store-ownership verification.

13. Changes

We may update this Privacy Policy as the service changes. The updated date shows when the latest version was published.

14. Contact

For privacy questions, contact CapiTracker through the contact details provided in your CapiTracker account or at capitracker.com.