Legal

    Privacy Policy

    Your privacy is our priority. Learn how we protect and handle your data.

    Effective Date: 03-08-2026

    1. Introduction

    This Privacy Policy explains how Tracking Hippo (a commercial name of FrontLetter BV, located at Kwadestraat 155 - 5.3, 8800 Roeselare, Belgium) collects, processes, and protects your personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable laws.

    2. Who We Are

    Tracking Hippo is a SaaS platform that enables the hosting of Google Server Tag containers on European infrastructure.

    Contact Details:

    FrontLetter BV
    Kwadestraat 155 - 5.3
    8800 Roeselare, Belgium
    Enterprise number (KBO/BCE): 0694.877.811
    VAT number: BE0694.877.811
    Data Protection Officer: data@trackinghippo.io

    3. What Personal Data We Collect

    TypeDescription
    Account DataEmail, password (hashed), language, account creation timestamps
    Billing DataCompany name, billing address, VAT number, payment details (processed via Stripe)
    Technical DataIP address, browser type, session metadata, login events
    Container LogsServer-side logs that may include user identifiers or IPs (see Section 6)
    Tracking DataCollected via cookies and analytics (see Section 7)
    Support MessagesAny personal data included in communications with support

    4. Legal Bases for Processing

    We process your personal data under the following bases:

    • Contractual necessity – to provide and bill the service
    • Legitimate interest – to secure and improve our services
    • Legal obligation – e.g. tax or accounting compliance
    • Consent – for non-essential cookies and marketing analytics

    5. How We Use Your Data

    We use your data for the following purposes:

    • To provide access to the Tracking Hippo platform
    • To manage billing and payment processing
    • To monitor service usage and prevent abuse
    • To protect forms and Platform functionality against spam, bots and automated abuse
    • To respond to support inquiries
    • To comply with legal obligations
    • To analyze traffic and improve the website (based on cookie consent)

    6. Container Logs

    6.1 Active containers and supporting services generate technical, security, debugging and operational logs. These logs are stored in the European Union for 90 days and then automatically deleted. They are used solely for:

    • Debugging
    • Abuse detection
    • Performance optimization

    6.2 These logs may contain personal data if the Client configures the container to process user identifiers, IP addresses, or request parameters.

    6.3 Tracking Hippo does not access or use container logs unless necessary for support (upon Client request) or abuse prevention. The Client is responsible for lawful data collection and disclosure to end-users.

    7. Tracking and Analytics

    7.1 Our website and platform use cookies and third-party tracking tools, including:

    • Google Analytics
    • Google Tag Manager
    • Google Ads Conversion Tracking
    • Meta Pixel (Facebook/Instagram)
    • LinkedIn Insight Tag

    7.2 These tools may collect data such as:

    • IP address
    • Pages visited
    • Click behavior
    • Device and browser type

    7.3 Data collected may be transferred to the US and other third countries. We implement safeguards like IP anonymization and Standard Contractual Clauses where required.

    7.4 These cookies are not set without prior consent. You can manage or withdraw consent via our cookie banner.

    8. Cookies

    We use cookies for:

    • Session management (essential)
    • User preferences (functional)
    • Website analytics (optional, based on consent)
    • Conversion tracking and remarketing (optional, based on consent)

    You can find more information in our Cookie Policy.

    9. Data Sharing

    We do not sell or rent your data. We may share it with:

    RecipientPurpose
    StripePayment processing
    UpCloud OyKubernetes-based infrastructure and hosting for server-side containers in selected EU data centers
    BunnyWay d.o.o. (bunny.net)European hosting for the frontend website, application database and logs, plus authoritative DNS
    UptimeRobot s. r. o.Uptime monitoring and the public status page; processes monitored endpoint and incident metadata and, if you subscribe to status updates, your email address
    Friendly Captcha GmbHEU-based bot and spam protection for contact, feedback and other protected forms
    Analytics & Ad platformsIf you give cookie consent
    Legal authoritiesOnly when required by law

    The current infrastructure subprocessor list and the distinction between customer-data subprocessors and operational providers are published in our Data Processing Agreement.

    Friendly Captcha processes connection, environment, interaction and functional data when a protected form is used so it can distinguish legitimate users from automated abuse. This processing is necessary for our legitimate interest in securing the website and Platform. Friendly Captcha GmbH acts as our processor, processes data in the European Union, anonymizes potentially identifying data such as IP addresses using one-way hashing, and does not use HTTP cookies or persistent browser storage. See Friendly Captcha's privacy information for end users.

    10. International Transfers

    Customer data processed through the managed server-side container service, including all service and container logs, is stored and processed only within the European Union. Optional analytics and advertising services described in Section 7 may independently process website data outside the EEA after consent. Where such a transfer occurs, we use an applicable GDPR transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, together with supplementary safeguards where appropriate.

    11. Data Retention

    Data TypeRetention Period
    Account & BillingDuration of use + up to 7 years (legal)
    Container Logs90 days during an active account; within 30 days after account deletion
    Analytics DataBased on cookie/tool defaults (e.g. 2 years for GA)
    Support MessagesUp to 12 months

    12. Your Rights

    Under the GDPR, you may:

    • Access your data
    • Correct or update your data
    • Request deletion (right to be forgotten)
    • Restrict or object to processing
    • Request data portability
    • Withdraw consent at any time

    To exercise any of these rights or request an export or deletion, email data@trackinghippo.io. We may ask for proof of identity or authority. When a customer deletes its account, its personal data, containers and logs are deleted within 30 days unless retention is legally required.

    13. Data Security

    We implement strong technical and organizational measures including:

    • TLS encryption
    • Secure container infrastructure (EU-based)
    • Role-based access control (RBAC)
    • Auto-expiring logs and session limits
    • Continuous monitoring and patching

    14. Children

    Our platform is not intended for use by children under 16. We do not knowingly collect data from minors.

    15. Complaints

    You can file a complaint with:

    Gegevensbeschermingsautoriteit (Belgian DPA)
    Drukpersstraat 35, 1000 Brussels
    https://www.gegevensbeschermingsautoriteit.be

    16. Changes to This Policy

    We may update this Privacy Policy from time to time. The latest version will always be available at https://trackinghippo.io/privacy. If the changes are material, we will notify you by email or through the platform.