Privacy Policy — Trackili

Last updated:

1) Who we are & scope

Data Controller: SEKLAB Nadjim (individual developer), trading as “Trackili”.
Contact for any requests: [email protected]

This policy applies to the Trackili app and website. We collect the minimum data needed to provide the service, we are transparent about how we use it, and we do not sell your personal data.


2) What we collect and why (and the legal basis)

Account data (required): your email (required for sign-up and sign-in), your Firebase user ID (UID), a display name/username (required — you can choose any name), and session tokens (JWT) used to authenticate requests.
If you sign in with Google, we also receive your Google display name and profile photo URL to populate your in-app profile (we do not modify your Google account).
Purpose: create and manage your account, sign you in, secure your session, support communications, and confirm sensitive requests (e.g., account deletion).
Legal basis: Contract performance (Art. 6(1)(b)).


Parcel tracking numbers: the shipment numbers you add to view status and updates.
Purpose: fetch and display your shipment status, and help you restore your list when changing devices.
Legal basis: Contract performance.


User preferences: language, notification settings (opt-in/opt-out), country/currency to display regional prices for AliExpress.
Purpose: customize your experience.
Legal basis: Contract performance / Legitimate interests (Art. 6(1)(f)), as applicable.


Diagnostics & performance (Firebase Crashlytics and Firebase Analytics):
Technical information such as Android version, device model, app version/build, crash logs and stack traces, and aggregated usage metrics. These diagnostics are essential for stability and safety and cannot be disabled from within the app. We do not use this data for behavioral advertising and we do not collect precise location.
Purpose: detect/fix issues, improve stability, security, and quality.
Legal basis: Legitimate interests (Art. 6(1)(f)). If you do not agree with these diagnostics, please refrain from using the app; if you already have an account, you may delete it (see Section 6). Previously collected crash data may remain for the limited retention period managed by Firebase.


Push notification tokens (FCM): a device token generated by Firebase Cloud Messaging.
Purpose: send the notifications you enable (e.g., parcel progress, deals).
Legal basis: Consent (withdrawable at any time in the app or device settings).
Your control: you can withdraw consent at any time in the in-app settings or your device settings. We stop sending notifications and delete your FCM token when you disable notifications or delete your account.


Advertising identifiers: We do not use the Android Advertising ID, and we do not link it to FCM or other features.


Support communications: the content of your messages and your contact details when you contact us.
Purpose: respond to your requests and improve the service.
Legal basis: Contract performance / Legitimate interests.

We do NOT collect: full legal name, postal address, phone number, payment information, precise location, or access to camera/microphone/contacts for tracking purposes.


Plain-language notice:
Using the app requires an email address for sign-in. If you prefer not to share this or disagree with the data practices described above, you may choose not to use the app. If you already have an account, you can delete it at any time (see Section 6).


3) How we use your data

Account & authentication
We use your email, Firebase UID, and session tokens (JWT) to create and operate your account, sign you in, and keep your session secure (e.g., preventing unauthorized access).
Legal basis: Contract performance (Art. 6(1)(b)).

Parcel tracking
We process the tracking numbers you add to query shipping providers and show you the latest shipment status. We keep your list available so you can restore it when moving to a new device.
Legal basis: Contract performance.

Preferences & personalization (non-sensitive)
We apply your language, notification opt-in/out, and country/currency settings to tailor the UI and display regional prices where applicable.
Legal basis: Contract performance / Legitimate interests (Art. 6(1)(f)).

Notifications (FCM)
If you opt in, we use your FCM device token to send the categories you enabled (e.g., parcel progress, deals). You can turn notifications off at any time in the app or device settings; when you do, we stop sending notifications and delete the FCM token. We do not link notifications to the Android Advertising ID.
Legal basis: Consent.

Diagnostics & performance (Firebase Crashlytics & Firebase Analytics)
We use crash reports, stack traces, app version/build, device model/OS version, and aggregated usage metrics solely to detect/fix issues and improve stability and security. These diagnostics are essential to the service and cannot be disabled from within the app. We do not use them for behavioral advertising and we do not collect precise location.
Where processed: exclusively in Firebase (we do not export raw analytics/crash events to our own database; we view aggregated dashboards only).
Legal basis: Legitimate interests (Art. 6(1)(f)). If you do not agree with these diagnostics, please refrain from using the app; if you already have an account, you may delete it (see Section 6).

Affiliate links & external content
We may show affiliate banners/links and product details fetched from external providers. Clicking a link opens the third party’s site/app, where their terms and privacy policy apply. We do not sell your data.

What we do not do

Limited operational logs (server-side)

Our backend may generate temporary operational logs (e.g., error traces, request IDs, abuse/rate-limit events) only to troubleshoot incidents, ensure security, and operate the service. These logs are rotated and minimized, are not used to build profiles, and are kept separate from Firebase analytics/crash data.


4) Sharing with trusted parties (processors / recipients)

Terminology: Processors act on our behalf to provide app functionality. Recipients (independent controllers) are third parties you visit or whose content you access; their own policies apply.

We do not sell your data and we do not share it for behavioral advertising or with data brokers.


5) Ads & affiliate links

No ad SDKs / no behavioral ads.
The app does not integrate third-party ad SDKs (e.g., AdMob) and does not show personalized/behavioral advertising.

Affiliate disclosures.
We may display affiliate banners/links to third-party products or stores. If you purchase through these links, we may earn a commission at no additional cost to you. Prices and availability are set by the third party; please verify the final price and terms at checkout.

Data sharing for affiliates.
We do not share your personal data (e.g., email, UID) with affiliate partners. Links may include standard referral parameters so the partner can attribute a purchase. We do not track your browsing on third-party sites/apps.

Third-party policies.
When you open an affiliate link, you are subject to the third party’s terms and privacy policy. Please review them before purchasing.

Android Advertising ID.
We do not use the Android Advertising ID and do not link it to notifications or affiliate content.

Changes.
If we later introduce an ad SDK or personalized ads, we will update this policy and our Google Play Data Safety declarations before enabling such features.


6) Retention & deletion

General principle.
We retain personal data only for as long as necessary to provide the service and fulfill the purposes set out in this policy. When data is no longer needed, we delete it from our operational systems or anonymize it.

Account, tracking numbers, preferences, and FCM token.
Kept while your account is active. When you delete your account, we delete:

Support messages.
Retained for up to 12 months from your last contact (or deleted earlier upon request).

Diagnostics & performance (Firebase Crashlytics / Firebase Analytics).
Crash reports, stack traces, app/device metadata, and aggregated usage metrics are stored by Firebase for a limited operational period under Firebase’s own retention policies. These diagnostics are used solely for stability and performance and are not exported to our own database. We do not control or extend Firebase’s retention periods. Data already collected may remain until Firebase’s retention period expires.

Operational logs (server-side).
Our backend may create temporary, minimized logs (e.g., timestamps, error codes, request IDs) strictly for troubleshooting, security, and abuse prevention. These logs are rotated on a short cycle, kept separate from analytics/crash data, and are not used to build behavioral profiles.

Backups.
If system backups exist, deleted items are removed through the routine backup rotation cycle. Backups are not used to restore individually deleted data.

Account & data deletion


7) Your choices & controls


8) Your rights (especially in the EEA/UK)

If you are located in the EEA or the UK, you have the following rights under the GDPR/UK GDPR, subject to legal limits and exemptions:

How to exercise your rights. Email [email protected]. We normally respond within one month (extendable by up to two months for complex/multiple requests).

Verification & fees. We may verify your identity before acting. Requests are free unless manifestly unfounded or excessive.

Scope & limitations. Rights are not absolute. Diagnostics sent to Firebase may persist until Firebase’s retention period ends. Where feasible, we will inform relevant processors of deletions or corrections.


9) Security

Incident response. If we become aware of a breach affecting personal data, we will notify affected users and regulators without undue delay where required by law.

No absolute security. No method is 100% secure; we continually improve controls.


10) International transfers

Your data may be processed outside your country (including outside the EEA/UK) via our processors (e.g., Google Firebase).

Transfer mechanisms (EEA/UK). Where required, we rely on Standard Contractual Clauses (SCCs) (and UK Addendum/IDTA) plus additional safeguards. Adequacy decisions may apply for specific destinations.

Firebase as processor. Firebase processes authentication, messaging, diagnostics, and analytics; we do not export raw analytics/crash events to our own databases.

Third-party recipients (independent controllers). When you follow links to carriers or stores, those third parties act under their own policies and jurisdictions.

Copies and further information. You may contact [email protected] to request information about transfer safeguards (including SCCs) subject to confidentiality/legal limits.


11) Children

Service intent. Trackili is intended for individuals who have the legal capacity to shop online and manage shipments. The service is not directed to children.

Age thresholds. Users under 13 (or below the local age of digital consent, 13–16 in some countries) must not create an account without verifiable parental/guardian consent.

No knowing collection. We do not knowingly collect personal data from children and we do not show behavioral ads.

Parental/guardian requests. Contact [email protected] to request account/data deletion (see Section 6).

Enforcement. Where we determine an account is used by a child without required consent, we may restrict or delete it consistent with legal obligations.

Legal references. We endeavor to comply with COPPA (where applicable) and GDPR/UK GDPR Article 8.


12) Cookies (website)

Scope. Cookies apply to our website only. The mobile app does not use web cookies.

What we use today. Strictly necessary cookies (short-lived session/security and language/preference). No cross-site tracking.

What we do not use. No behavioral advertising cookies or third-party ad SDKs on the website.

Analytics (not currently enabled in the EEA/UK). If introduced, we will obtain prior consent where required, use privacy-preserving configurations, and update this policy and Data Safety declarations.

Typical lifetimes. Session-based or short-lived; preference cookies may persist up to 12 months.

Your controls. You can block/delete cookies via your browser; blocking strictly necessary cookies may affect site functionality.

Third-party content. We avoid third-party embeds; when you follow links to carriers or stores, their cookie practices apply.


14) Disclaimer (important)

Nature of the service. Trackili is not a shipping carrier, logistics provider, payment processor, or online store. We do not generate tracking data and we do not fulfill, ship, or sell products. The app aggregates and displays information obtained from external providers for your convenience.

Source & accuracy of information. Shipment statuses, product details, prices, and deals are provided by third-party services and may be delayed, incomplete, or inconsistent across systems. Information is shown “as is / as available.” We do not guarantee accuracy, completeness, or timeliness, and we may cache data briefly for performance.

Prices, availability, and terms. Prices, taxes, shipping costs, availability, delivery estimates, and seller terms are set by the third party and may change at any time without notice. Before purchasing, verify the final price, taxes/fees, shipping, and seller terms at checkout.

No endorsement / no party to transactions. Links (including affiliate links) are for convenience only. We do not endorse sellers/products and we are not a party to your transactions. For order/refund/warranty/shipping issues, contact the merchant/seller or carrier directly.

Service availability & dependencies. Our service depends on third-party APIs and infrastructure (e.g., carriers, marketplaces, Firebase). We do not warrant uninterrupted availability and may modify, suspend, or discontinue features at any time.

Limitation of liability. To the maximum extent permitted by law, we are not liable for indirect, incidental, special, consequential, or punitive damages, or for loss arising from reliance on third-party information, service interruptions, delays, customs/duty assessments, or issues outside our reasonable control. Nothing limits liability where it cannot be limited under applicable law (e.g., fraud).

Your responsibility. Always verify shipment status with your carrier and final price/terms with the merchant before purchasing.

Consumer rights. This disclaimer does not affect any non-excludable consumer rights you may have under applicable law.


15) Changes to this policy

We may update this policy. We will show the “Last updated” date at the top and may send an in-app notice for material changes. Your continued use of Trackili means you accept the updated version.


16) Contact

Email: [email protected]
Policy page: https://www.trackili.app/terms/privacy.html


Appendix — Google Play Data Safety summary (for transparency)

Data collected

Purposes

Data sharing & selling

Security

User control & deletion

Additional disclosures