Legal
Privacy policy
Last updated: August 19, 2026
Operator and contact
Trytracegrid is operated by Ahmed Refaat Abdelzaher in Egypt. Contact support@trytracegrid.com for privacy questions or requests. A personal postal address is not published on this website.
Roles
Trytracegrid acts as controller for account, billing-administration, security, and direct support data. For tracking data, connected-platform data, and evidence submitted by an agency or client, the customer is normally the controller and Trytracegrid acts as processor under the Data Processing Addendum.
Data we process
We process account identity and contact details; workspace membership and permissions; billing and subscription identifiers; device, request, session, and security logs; connected-account metadata; encrypted OAuth credentials; configuration, event, campaign, catalog, and audit evidence; approvals, proposed changes, verification results, and support communications.
Purposes and legal bases
We use data to provide, secure, support, and improve the contracted service; authenticate users; perform authorized audits; produce evidence and reports; execute explicitly approved test changes; prevent fraud and abuse; meet legal obligations; and communicate service information. Depending on context, processing relies on contract, legitimate interests, legal obligation, consent, or the customer's documented instructions.
Connected providers and Google user data
After authorization, Trytracegrid accesses only selected resources within granted scopes. This may include GTM containers and versions, GA4 properties and reporting, Google Ads accounts and URL fields, and equivalent resources from other connected providers. We use the data to inspect configuration, compare evidence, identify measurement problems, prepare authorized changes, and verify supported outcomes. We do not sell connected-account data or use it for targeted advertising.
Use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including Limited Use requirements.
AI processing
Trytracegrid does not use customer data to train its own models. AI requests use minimized, redacted context; exclude credentials; and use OpenAI with store: false. Deterministic server controls, not the AI, authorize any provider action. Further details are in the AI data-use policy.
Sharing and subprocessors
Data is shared only with service providers needed to operate Trytracegrid, connected providers selected by the customer, professional advisers, authorities where legally required, or a successor in a legitimate business transfer. Current subprocessors and data categories are published in the Subprocessor List.
Security and international transfers
Security measures include database tenant isolation, encryption of stored credentials, session controls, role-based authorization, rate limits, security headers, and restricted write workflows. No method is risk-free. Processing locations depend on the configured infrastructure and subprocessor agreements. Trytracegrid does not claim EU-only residency unless an EU deployment is expressly documented.
Retention, export, and deletion
Credentials are deleted immediately when an integration is disconnected. Active account and workspace data is removed after a verified deletion request; residual encrypted backups are targeted for purge within 30 days, subject to legal, fraud, and security exceptions. Billing records may be retained by Paddle as legally required. Self-service export and deletion controls are available from account settings.
Your rights
Depending on applicable law, you may request access, correction, export, deletion, restriction, objection, or withdrawal of consent. We may verify identity and refer requests about customer-controlled data to the applicable customer.
Cookies
Essential cookies support authentication, security, preferences, and checkout. Non-essential attribution cookies are set only after consent. You may change your choice through the cookie control.
Complaints and changes
You may contact us first and may also complain to a competent data-protection authority. Material policy changes will be dated and, where appropriate, communicated in the service.