Privacy Policy

Last updated: [date]

1. Who this applies to

This policy covers [Company Legal Name] ("ClientTrack," "we," "us"), the ClientTrack website and application, and the two kinds of people who use it: staff (the freelancer or agency running the account) and clients (the people staff invite to view and pay invoices in the portal).

2. What we collect

  • Account data: name, email, and authentication details, handled by our authentication provider, Clerk.
  • Business data you enter: clients, projects, invoices, messages, and files you or your clients add to the product.
  • Payment data: invoice amounts and payment status. Card and bank details are handled directly by our payment processor, Stripe; we do not store full card numbers.
  • Files you upload: stored in a private cloud storage bucket, accessible only to the org and clients they're shared with.
  • Usage data: basic technical logs (IP address, browser, timestamps) needed to operate and secure the service.

3. Who we share it with

We use a small number of service providers to run ClientTrack, each only for the purpose below:

  • Clerk: authentication and account management.
  • Stripe: payment processing for invoices paid by card.
  • SendGrid: transactional email (invites, invoice notifications).
  • Cloud infrastructure providers: hosting, database, and file storage.

We do not sell personal data, and we do not share it with anyone else for their own marketing purposes.

4. Client data specifically

If you're a client invited into someone's ClientTrack account: the staff org you work with controls what's visible to you, and you only ever see projects and invoices tied to you, never another client's data, even if that client uses the same org. Your relationship with an org (name, whether you've accepted an invite) is scoped to that org; your sign in identity is shared only if you're invited by more than one org.

5. How long we keep data

We retain account and business data for as long as the account is active, and for a reasonable period afterward to comply with legal, tax, and accounting obligations. You can request deletion of your account data by contacting us (below).

6. Your choices

You can access, correct, or request deletion of your personal data by contacting us at [support email]. If your account is a client relationship managed by a staff org, some requests may need to go through that org directly.

7. Changes to this policy

We'll update the date at the top of this page when this policy changes, and post material changes here before they take effect.

8. Contact

Questions about this policy: [support email].