HEXTrack

HexTrack Privacy Policy

Effective date: 28 July 2026

This Policy is written for the United States and reflects the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable U.S. state privacy laws (including the privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, and other states with comparable laws) (together, "U.S. State Privacy Laws").


1. Our Two Roles: Business/Controller vs. Service Provider/Processor

HexTrack handles personal information in two distinct capacities, and your rights and our obligations differ accordingly.

1.1 Account data — HexTrack is the Business/Controller. For information about our own customers (the businesses and users that register for and administer the Service) and visitors to our websites, HexTrack determines the purposes and means of processing. This includes account, billing, support, and usage information. This Policy governs that processing directly.

1.2 End-Customer Data — HexTrack is the Service Provider/Processor. When a customer (a "Tenant") uses the Service to manage its own leads, contacts, and end-customers, HexTrack processes that information ("End-Customer Data") only on the Tenant's behalf and on its instructions. For End-Customer Data:

  • The Tenant is the business/controller and is responsible for the lawfulness of the data, for privacy notices to its own contacts, and for handling privacy-rights requests from those individuals.
  • HexTrack does not sell End-Customer Data, does not share it for cross-context behavioral advertising, and does not use it except to provide, secure, and support the Service, or as otherwise permitted by U.S. State Privacy Laws and our contract with the Tenant.
  • If you are an end-customer or contact of a Tenant and wish to exercise privacy rights, please contact that Tenant. We will assist the Tenant in responding, or refer your request to them.

2. Personal Information We Collect

The categories below use the CCPA/CPRA framework. We collect these categories both directly and as End-Customer Data provided by Tenants.

CCPA/CPRA categoryExamplesRole
IdentifiersName, email address, phone number, account ID, IP address, device identifiersAccount data (our users) and End-Customer Data (Tenant contacts)
Customer recordsBilling name, payment method reference (tokenized via Stripe), transaction historyAccount data
Commercial informationSubscription plan, purchases, usage of featuresAccount data
Internet/network activityLog data, pages viewed, feature interactions, referring URLsAccount data
Communications contentMessages, conversation content, and attachments processed through funnels, WhatsApp/omnichannel, and AI featuresEnd-Customer Data (Tenant-directed) and support communications
Advertising/traffic identifiersAd click and campaign identifiers such as `gclid`, `fbclid`, and UTM parametersAccount data and End-Customer Data used for attribution/reporting
Geolocation (approximate)City/region inferred from IPAccount data
InferencesLead scoring, pipeline status, engagement signals derived from CRM activityEnd-Customer Data (Tenant-directed)

Sensitive personal information. HexTrack does not seek to collect "sensitive personal information" as defined by U.S. State Privacy Laws for its own purposes. Tenants must not upload special categories of data into the Service without an appropriate legal basis and, where required, consent. We do not use or disclose any sensitive personal information for purposes that would require offering a "Limit the Use of My Sensitive Personal Information" right beyond those permitted uses.


3. How We Collect Personal Information

  • Directly from you when you create an account, subscribe, contact support, or use the Service.
  • Automatically through cookies and similar technologies (see the Cookie Policy) and server logs.
  • From Tenants who upload or generate End-Customer Data through the Service.
  • From third parties such as our payment processor, advertising platforms (for attribution identifiers), and integrated channels like WhatsApp/Meta.

4. Purposes of Processing (and Legal Bases)

We process personal information for the purposes below. U.S. State Privacy Laws frame these as "business and commercial purposes"; for users in jurisdictions that require a stated legal basis, the corresponding basis is noted.

PurposeDescriptionBasis (where applicable)
Provide the ServiceCreate accounts, deliver features, host and process Customer ContentPerformance of a contract
BillingProcess subscription payments via Stripe, invoicing, taxPerformance of a contract; legal obligation
AI featuresSend prompts and relevant content to AI providers to generate AI Output at the Tenant's directionPerformance of a contract; legitimate business interest
MessagingDeliver and receive messages via WhatsApp/omnichannel at the Tenant's directionPerformance of a contract
Advertising attribution & reportingAssociate ad identifiers (gclid/fbclid/utm) with activity for the Tenant's reportingLegitimate business interest; Tenant instruction
SupportRespond to inquiries and troubleshootPerformance of a contract; legitimate business interest
Security & fraud preventionProtect the Service, detect abuse, maintain logsLegitimate business interest; legal obligation
Product improvementUnderstand aggregate usage to improve the Service (we do not use End-Customer Data content to train third-party AI models)Legitimate business interest
Legal complianceComply with law and enforce our termsLegal obligation; legitimate business interest
Marketing to our own usersSend service and, where permitted, promotional communications; you may opt outConsent or legitimate business interest

No sale; no cross-context behavioral advertising of End-Customer Data. We do not sell personal information for money, and we do not use End-Customer Data for cross-context behavioral advertising. To the extent our own website uses advertising or analytics cookies that may constitute "sharing" or a "sale" under some U.S. State Privacy Laws, you can opt out as described in Sections 8 and 9 and in the Cookie Policy.


5. Sub-Processors and Disclosures

We disclose personal information to service providers and sub-processors that help us operate the Service, under contracts that restrict their use of the information to providing services to us. Current categories and providers:

Sub-processor / categoryPurposeData involved
Stripe (payments, USD)Payment processing, billing, fraud preventionBilling identifiers, tokenized payment method, transaction data
OpenAI (AI provider)Generating AI Output for AI featuresPrompts and relevant content submitted to AI features
Anthropic (AI provider)Generating AI Output for AI featuresPrompts and relevant content submitted to AI features
Email delivery providerTransactional and, where applicable, marketing email deliveryEmail addresses, message content
Cloud hosting providerHosting, storage, and processing of the ServiceAll categories, as stored in the Service
WhatsApp / MetaOmnichannel messaging delivery and receiptPhone numbers, message content, metadata

We may also disclose personal information: (a) to professional advisors; (b) to comply with law, legal process, or lawful requests; (c) to protect rights, safety, and property; and (d) in connection with a merger, acquisition, or asset sale, subject to this Policy.

AI providers process content to return AI Output and, under our agreements, do not use content submitted through the Service to train their models except as configured and permitted. An up-to-date list of sub-processors is available on request at contato@hextrack.com.br.


6. International Data Transfers

We are based in the United States and process personal information there. Some sub-processors may process data in other countries. Where we transfer personal information across borders, we use appropriate safeguards required by applicable law (such as standard contractual clauses or equivalent mechanisms) and require recipients to protect the information consistent with this Policy.


7. Retention

We retain personal information for as long as needed to provide the Service and for the purposes described in this Policy, then delete or de-identify it. Specifically:

  • Account data: retained for the life of your account and for a reasonable period afterward to meet legal, tax, accounting, and security obligations.
  • End-Customer Data: retained according to the Tenant's configuration and instructions; on account termination, retained for the export window described in the Terms, then deleted in the ordinary course, subject to backup cycles.
  • Logs and security records: retained for a limited period consistent with security needs.
  • Backups: residual copies may persist in backups for a limited period before being overwritten.

8. Your Privacy Rights

Depending on where you live and your relationship with us, you may have the following rights. These rights generally apply to account data for which HexTrack is the business/controller. For End-Customer Data, direct your request to the relevant Tenant (see Section 1.2).

Rights available under U.S. State Privacy Laws:

  • Right to know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients.
  • Right to delete personal information we hold about you, subject to legal exceptions.
  • Right to correct inaccurate personal information.
  • Right to data portability — receive your information in a portable, readable format.
  • Right to opt out of "sale" or "sharing" of personal information and of targeted/cross-context behavioral advertising.
  • Right to limit the use and disclosure of sensitive personal information (where such uses occur; see Section 2).
  • Right to opt out of certain profiling that produces legal or similarly significant effects, where provided by your state's law.
  • Right to non-discrimination — we will not discriminate against you for exercising your rights.
  • Right to appeal — in states that provide it (such as Virginia, Colorado, Connecticut, and others), if we decline your request you may appeal, and we will respond within the statutory period.

California-specific disclosures (CCPA/CPRA): In the preceding 12 months, we have collected the categories in Section 2 for the purposes in Section 4 and disclosed them to the sub-processor categories in Section 5. We do not sell personal information for monetary value and do not knowingly sell or share the personal information of individuals under 16. California residents may also designate an authorized agent to make requests, and may request information about our disclosures of personal information.


9. How to Exercise Your Rights

9.1 Submitting a request. Email contato@hextrack.com.br or contact us using the details in Section 13. You may also use available in-product controls. To exercise the right to opt out of sale/sharing or targeted advertising on our website, use the "Do Not Sell or Share My Personal Information" / cookie-preferences link on our site and see the Cookie Policy.

9.2 Verification. To protect you, we will verify your identity before fulfilling access, deletion, correction, or portability requests. We may ask for information to match against what we hold.

9.3 Authorized agents. Where permitted, an authorized agent may submit a request with proof of authorization; we may still verify your identity.

9.4 Response times. We will acknowledge and respond within the timeframes required by applicable law (generally 45 days, extendable where permitted). For opt-out requests, we will act within 15 business days.

9.5 Universal opt-out mechanisms. Where required by applicable law (for example, in California, Colorado, Connecticut, and Texas), we honor recognized universal opt-out signals such as the Global Privacy Control (GPC) as a valid opt-out of sale/sharing and targeted advertising for the browser or device that sends the signal.

9.6 Appeals. If we decline a request and you are in a state that provides an appeal right, you may appeal by replying to our decision or emailing contato@hextrack.com.br. You may also contact your state Attorney General.


10. Security

We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit, access controls, authentication options (such as two-factor authentication), logging, and regular review of our practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify affected parties and regulators as required by applicable law.


11. Children's Privacy

The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children. Tenants must not use the Service to collect data from children in violation of applicable law.


12. Cookies and Tracking

We use cookies and similar technologies on our websites and in the Service. For details on categories, purposes, and how to manage your preferences, see the Cookie Policy.


13. Contact Us and Data Protection Officer

For privacy questions or to exercise your rights:

ÓRUS DIGITAL

Privacy / Data Protection Officer: contato@hextrack.com.br

Privacy requests: contato@hextrack.com.br

General contact: contato@hextrack.com.br


14. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by email or in-product notice) and update the effective date above. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.