Privacy Policy
Effective August 25, 2026
Elite Email Tracker provides email engagement tracking, link tracking, account analytics, and team administration. This policy describes the data the service actually processes.
Data we process
- Account and billing: account email, password hash, plan, team membership, roles, device activations, and billing identifiers. Payment card details are processed by our payment provider, not stored by us.
- Tracked-message metadata: sender, recipient addresses and recipient type, subject, provider, send time, tracking status, and registered link destinations. Standard pixel and link tracking does not upload the message body.
- Outreach content: when a user deliberately uses Outreach, we store contacts, lists, templates, snippets, signatures, campaign steps, rendered message content, delivery state, and uploaded files so the service can personalize, schedule, send, retry, and report on that campaign.
- Engagement signals: pixel requests and tracked-link redirects, timestamps, IP address, user-agent, referrer when supplied, and derived browser, mail client, operating system, device class, network/ASN/ISP, approximate city/region/country, and signal classification.
- Operations: security audit events, support messages, error diagnostics, request-rate data, and delivery state needed to operate and protect the service.
- Account and organization verification: email-verification status, hashed and expiring verification challenges, exact-email Team invitations, optional organization domain claims and DNS verification state, enrollment policy, join requests, and administrator audit events. Raw email, invitation, DNS, OAuth state, and session tokens are not stored in operational metrics.
What engagement intelligence means
Remote-image requests are signals, not guaranteed proof that a particular person read a message. Mail providers, privacy relays, and security scanners may fetch images or links. We classify these separately and display confidence and provenance. A proxy IP or user-agent can describe the proxy rather than the recipient; unavailable values remain unknown. Group messages use group attribution unless the provider permits recipient-specific delivery.
How data is used and shared
We use data to provide tracking, analytics, notifications, authentication, billing, fraud prevention, support, and service reliability. Team data is visible according to administrator-configured roles. We may use infrastructure, email, geolocation-database, payment, and push-notification processors under service agreements. We do not sell personal information or use tracked-message data for third-party advertising.
Google sign-in uses the verified primary email to establish an account. A separately initiated Gmail connection may process message metadata, snippets, labels, thread identifiers, and attachment descriptors for inbox and productivity views; message content or an attachment is fetched when the user opens it. Gmail send and compose permissions deliver user-created or scheduled messages, while full mailbox mode applies only the mailbox action selected by the user. Provider tokens are encrypted at rest and can be revoked by disconnecting. Our use and transfer of Google user data complies with the Google API Services User Data Policy, including Limited Use requirements; we do not use it for advertising, resale, or generalized AI model training.
Approximate IP geolocation and network data includes DB-IP Lite data under CC BY 4.0. IP Geolocation by DB-IP.
Roles and legal bases
For customer-directed tracking, the customer determines the purpose and means and is generally the controller or business; Elite Email Tracker acts as its processor or service provider. We are controller for account administration, security, billing, and our own legal obligations. Depending on context, processing may rely on consent, contract, legal obligation, or legitimate interests after the customer assesses necessity, balancing, notice, and local electronic-communications rules. Strict permission mode lets an organization require recorded recipient permission before a tracker can be inserted.
Security and retention
We use scoped installation credentials, hashed opaque tokens, encryption for provider refresh credentials, encrypted transport in production, role-based access, rate limits, audit logs, and restricted production secrets. Customers can configure engagement-event retention from 1 to 2,555 days and separate network/location retention from 0 to 365 days; defaults are 365 and 30 days. Those settings also remove old outreach delivery events and redact or delete tracked-file network events. Outreach content and files remain until the user archives or deletes them or deletes the account. Account, billing, security, and verified rights-request records may be retained longer where necessary. Backups may persist for a limited recovery window before expiration.
International transfers
Data may be processed in countries different from the sender or recipient. Where required, transfers use an applicable adequacy decision, contractual safeguards such as the European Commission Standard Contractual Clauses, and supplementary security measures. Customers should review the subprocessor list and execute the Data Processing Addendum before regulated production use.
Your choices and rights
Users can disable tracking for a message, disconnect or revoke an installation, export authorized team analytics, leave or be removed from a team, and uninstall the extension. Depending on location, account holders and recipients may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or appeal, and may complain to a regulator. Submit a verified privacy request. We may retain records required for security, disputes, or law and will explain any applicable exception.
Team owners may invite people by exact email without claiming a company domain. Optional DNS TXT verification proves control of a domain and enables invite-only, request, automatic-enrollment, or blocked policies. New verified domains remain invite-only until an administrator changes the policy. Explicit external invitations remain available unless the Team owner disables them.
Recipient responsibilities
Customers control whom they email and must use the service lawfully, provide any notices or consent their circumstances require, and avoid tracking where prohibited. The service is not intended for children under 13.
Changes and contact
We may update this policy as the product or law changes and will revise the effective date. For privacy questions or requests, contact us.