BETA

Scope

This Privacy Policy applies to Sarge websites, dashboards, hosted tracking endpoints, verification pages, and related services. Customer websites that install Sarge remain responsible for their own privacy notices and consent flows.

Information we collect

  • Account information, such as your name, email address, authentication identifiers, workspace name, billing status, and plan selection.
  • Product configuration, such as projects, environments, tracking domains, notification settings, webhook destinations, and collaboration invites.
  • Browser event data sent through the Sarge pixel, including event names, timestamps, page URLs, referrers, session identifiers, user identifiers supplied by your implementation, affiliate/referral fields, and event properties.
  • Server and postback event data that you send to Sarge for order, subscription, affiliate, or conversion reconciliation.
  • Operational data, such as IP address, user agent, request metadata, logs, diagnostics, security events, and support communications.

How we use information

  • Provide Sarge dashboards, event streams, diagnostics, monitoring, alerts, verification links, and agent-ready troubleshooting context.
  • Maintain account security, investigate abuse, enforce limits, debug outages, and improve reliability.
  • Process billing, manage subscriptions, and communicate product, security, legal, and support updates.
  • Analyze aggregated or de-identified usage so we can improve the service without identifying individual visitors.

Sharing and service providers

  • We use service providers for hosting, authentication, database infrastructure, payments, email delivery, analytics, and customer support.
  • We do not sell personal information. We do not use customer event data to build advertising profiles.
  • We may disclose information if required by law, to protect Sarge or others, or as part of a merger, financing, acquisition, or sale of assets.

Customer responsibilities

  • You decide what browser event data, identifiers, and properties your implementation sends to Sarge.
  • Do not send sensitive personal information, payment card numbers, passwords, health information, or other regulated data unless a separate written agreement permits it.
  • You are responsible for any notices, consent banners, opt-out flows, and lawful bases required for your own websites, apps, and visitors.

Retention and deletion

  • Event retention depends on your plan and product configuration. Billing, security, and legal records may be retained longer when needed for legitimate business or legal purposes.
  • Workspace owners can request export, correction, or deletion of account data. Some records may remain in backups for a limited period before automatic rotation.
  • We may retain aggregated or de-identified information that no longer identifies a person or workspace visitor.

Security

  • We use access controls, transport encryption, credential hashing, security headers, scoped tokens, and tenant-scoped data access patterns.
  • No internet service is perfectly secure. Please report suspected vulnerabilities to security@sargetrack.app.

Your choices and requests

To request access, correction, deletion, export, or another privacy review, email privacy@sargetrack.app. We may need to verify your authority over the relevant workspace before acting on a request.

If you are a visitor to a customer website that uses Sarge, contact that website owner first. Sarge acts as a service provider or processor for customer-controlled event data.

Changes

We may update this policy as Sarge changes. If changes are material, we will update the effective date and may require workspace owners to acknowledge the new version in the dashboard.