TrackCreatives - Creative Research Assistant 的隐私政策
TrackCreatives - Creative Research Assistant 作者: Track Creatives
TrackCreatives Privacy Policy (full, current version: https://trackcreatives.com/privacy)
Last updated: September 25, 2026
1. Introduction
TrackCreatives ("Company," "we," "our," or "us") operates the TrackCreatives web application located at trackcreatives.com (the "Website") and the TrackCreatives browser extension for Google Chrome, Microsoft Edge and Mozilla Firefox (the "Extension"). The Extension works the same way and handles data the same way in every browser. Together, these are referred to as the "Service."
This Privacy Policy explains what information we collect, how we use and share it, how long we keep it, and what rights you have regarding your data. It applies to all users of the Service worldwide.
By installing the Extension or creating an account on the Website, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please uninstall the Extension and discontinue use of the Service.
2. Information We Collect
2.1 Account Information
When you create a TrackCreatives account, we collect:
- Email address (required for account creation, login, and service communications)
- Name (optional, provided during onboarding)
- Role and platform preferences (optional, provided during onboarding)
- Subscription plan and billing status
Payment information (credit card numbers, billing addresses) is collected and processed directly by our payment processor, Stripe. We never receive, transmit, or store your full payment card details on our servers.
2.2 Service Usage Data
- Features accessed, pages viewed, and tools used within the Website
- Search queries and filters applied within our dashboard
- Usage records for plan enforcement: which metered feature you used (for example an import, a save from the Extension, or an AI request), whether it came from the Website or the Extension, and when
- Timestamps of actions performed
When you visit the Website we also record basic visit information: the page viewed, the referring page and campaign tags, your browser and device type, your time zone, a one-way hash of your IP address (we do not store the IP address itself), and your approximate location at country, region and city level as provided by our network provider. If you are signed in, the visit is associated with your account.
2.3 Data Collected via the Extension
The Extension collects publicly available content metadata from supported platforms while you browse them. The complete list of platforms the Extension is able to read is:
- TikTok — the For You feed, search results, creator profiles, TikTok Shop product pages, the TikTok Ad Library and Creative Center
- Instagram — the home feed, Reels, Explore and public profiles
- Facebook / Meta — the public Meta Ad Library
- X (Twitter) — your feed and public profiles
- LinkedIn — your feed, public profiles and search results
- YouTube — Shorts and public channel pages
- Pinterest — public pins and boards
- Substack — public publication feeds
- Amazon — public product pages (.com, .co.uk, .ca, .de, .com.au)
- AliExpress — public product pages
- Google — search results pages and the Google Ads Transparency Center
- Shopify storefronts — publicly published storefront pages, when you explicitly grant permission for that site
The Extension only reads a page when you are on that platform and, for sites outside the fixed list above, only after you explicitly grant permission for that site. On all of these platforms the data collected is:
Content and Creator Metadata:
- Post/video identifiers and URLs
- Captions, descriptions, and hashtags
- Publicly displayed engagement metrics (views, likes, comments, shares, bookmarks)
- Content duration, creation date, and thumbnail/cover image URLs
- Publicly available creator information: usernames, display names, profile images, bios, follower/following counts, and verified status
- TikTok Shop product data when you visit a product page (product title, price, rating, reviews, seller info, and related products)
- TikTok Ad Library and Creative Center data when you visit those pages
- Instagram reels and creator profile data when you browse the Reels feed, Explore, or a public profile (reel identifiers, captions, view and like counts, thumbnails, and public profile stats)
- Meta Ad Library data when you visit the public ad library (ad identifiers, advertiser page name, ad copy, creative image or video, and the date the ad started running)
- Google Ads Transparency Center records and Google search results you view (advertiser, ad text, creative and landing page)
- X, LinkedIn, Pinterest and Substack posts you view (text, author, public engagement counts and links)
- YouTube Shorts and channel pages you view (video links, titles and public view counts; video files are never downloaded)
- Amazon and AliExpress product pages you view (title, price, rating, review count, images and seller)
Contact and Business Information (lead and business capture):
- LinkedIn contacts. When you view a LinkedIn profile with the Extension active, it captures the person's name, profile URL, headline, follower and connection counts, and any email address, phone number or website the person has made visible on that profile. These contacts are saved to your TrackCreatives account automatically so they appear in your Leads list, and can also be exported to CSV by you.
- Business listings. When you use business capture on Google search results, it collects each listing's business name, address, phone number, email, website, category, rating and review count, and sends them to your account when you choose to import them.
- Storefronts. When you inspect a Shopify store, it reads the store's name, public products and prices, and the publicly detectable apps, theme and advertising pixels the store uses.
This information can include location: a business address, or a city or region shown on a public profile or listing. The Extension never reads your device's location or GPS.
Page Addresses and Capture History:
For each item you capture or import, the Extension records the address (URL) of the page or item and the time it was captured, so you can return to the source. It does not read your browser history, bookmarks, or pages you visit that it does not capture.
Text You Give the AI Writing Tools:
When you use AI Reply, Rewrite or Find Supplier, the post or product text you selected and any instruction you type into the Extension are sent to our servers and our AI providers to produce the result.
Sign-In Information:
The Extension stores a TrackCreatives session token so it can act on your account, and sends it with each request to our servers. We never collect your passwords for TikTok, Instagram, LinkedIn or any other site.
How the Extension Collects Data:
- The Extension reads publicly visible content from the web pages you visit on supported platforms ("DOM scraping")
- The Extension observes network responses from the supported platforms' own public-facing APIs while you browse, to capture structured metadata that is already being sent to your browser ("API response observation")
- If you enable the auto-scroll feature, the Extension will programmatically scroll the page to load additional content and collect the data that appears
Activity Records:
The Extension keeps a local activity log on your device that records the type of activity (e.g., "FYP pull," "profile view," "search"), a descriptive label, and a timestamp. That local log is not transmitted to our servers. Separately, our servers record each metered action you take through the Extension (for example a save, an import or an AI request), with the feature used and the time, to enforce your plan's limits and to show your usage in your account.
2.4 Information We Do NOT Collect
- We do not collect your social media passwords, login credentials, or authentication tokens for TikTok, X, or any other platform
- We do not collect private or direct messages
- We do not read your browser history or bookmarks. The only page addresses we keep are those of items you capture or import, as described above
- We do not collect the content of pages you visit outside of supported platforms, except a storefront you choose to inspect
- We do not use the Extension to inject advertisements, modify page content for promotional purposes, or redirect your browsing
- We do not collect keystroke data or anything you type into websites. The only text we receive is what you type into the Extension's own AI writing box
- We do not collect payment card, banking, health or private message data through the Extension
2.5 Summary of Extension Data by Category
This is the same breakdown we give in our Chrome Web Store, Microsoft Edge Add-ons and Firefox Add-ons listings. For each category: what is collected, why, where it is stored, and who it is shared with.
Personally identifiable information
- Collected: Your account email and name. Names, headlines, and any email address, phone number or website that people or businesses have made public, when you capture LinkedIn contacts or business listings.
- Used for: Signing you in, running your account, and building the lead and business lists you asked the Extension to capture.
- Stored: In your TrackCreatives account (Supabase) and, until imported or cleared, in the browser's extension storage on your device. Deleted within 30 days of account deletion.
- Shared with: Supabase and Railway to store and serve it; Resend for your account email address. Never sold.
Authentication information
- Collected: Your TrackCreatives session token. Never your passwords for other websites.
- Used for: Letting the Extension act as your account when it saves, imports or uses AI features.
- Stored: In the browser's extension storage on your device, and as a session in our authentication service (Supabase) until you sign out or it expires.
- Shared with: Supabase, which issues and checks sessions. No one else.
Website content
- Collected: Public posts, ads, videos, products, storefront details and profile information on the supported platforms you view, and the text you give the AI writing tools.
- Used for: Showing and saving research you capture, and generating AI replies, rewrites and supplier matches you request.
- Stored: Items you save are stored in your account (Supabase, with media in Cloudflare R2). AI requests and their results may be kept in your account’s tool history so you can find them again.
- Shared with: Supabase, Railway and Cloudflare to store and serve it; Alibaba Cloud (Qwen) and, only as a backup, DeepSeek for the AI writing features.
Web history
- Collected: The address (URL) of each page or item you capture and when you captured it. Not your browser history.
- Used for: Linking each saved item back to its source and showing your capture history.
- Stored: With the saved item in your account, and in the browser's extension storage on your device.
- Shared with: Supabase and Railway to store and serve it. No one else.
User activity
- Collected: A local log of research actions (kept on your device only), and records of each metered action you take (feature used and time).
- Used for: Enforcing your plan limits, showing your usage, and preventing abuse.
- Stored: The local log stays in the browser's extension storage. Usage records are stored in your account (Supabase) and deleted or de-identified within 30 days of account deletion.
- Shared with: Supabase and Railway to store and serve it. No one else.
Location
- Collected: Locations that appear in content you capture, such as a business address or a city shown on a public profile. The Extension never reads your device location.
- Used for: Part of the business and lead information you asked to capture.
- Stored: With the captured item in your account and in the browser's extension storage.
- Shared with: Supabase and Railway to store and serve it. No one else.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery: To provide, maintain, and improve the TrackCreatives platform, including displaying advertising intelligence data on your dashboard
- Account management: To authenticate your identity, manage your subscription, and enforce usage limits based on your plan
- Payment processing: To process subscription payments through Stripe
- AI features: To generate ad analysis, creative briefs, transcripts, replies and rewrites using third-party AI services. Only the content you choose to analyze or write about, and your instruction, is sent; your account email, contacts you have captured and browsing activity are not
- Service communications: To send transactional emails such as account confirmations, billing receipts, and important service updates
- Security and integrity: To detect and prevent fraud, abuse, and unauthorized access
- Product improvement: To analyze aggregate usage patterns to improve features and user experience
4. Data Transmission and Sharing
4.1 Extension to Server Transmission
Data leaves your browser only in these cases, always over an encrypted HTTPS connection to our servers and authenticated with your session token:
- When you import or save items to your dashboard
- Automatically, when LinkedIn contacts are captured (they are saved to your Leads list as described in section 2.3)
- When you import captured business listings
- When you use an AI feature (the selected text and your instruction)
- When the Extension checks your sign-in, your plan and its configuration, and when it asks our servers to structure a captured page
4.2 Third-Party Service Providers
We share data only with the following service providers, who process it on our behalf under contractual obligations and only to run the Service. This is the complete list of parties that receive user data:
- Supabase — Database hosting and user authentication. Stores your account, sign-in sessions, imported items, captured leads and business listings, usage records and website analytics
- Railway — Application hosting. Runs the servers that receive every request from the Website and the Extension
- Cloudflare — Network, security and media storage (R2). All traffic to trackcreatives.com passes through Cloudflare, which also supplies the approximate country, region and city we record for visits; media you import is stored in R2
- Stripe — Payment processing (PCI-DSS Level 1 compliant). Receives your billing details directly; we never see full card numbers
- Anthropic (Claude AI) — AI ad analysis and creative insights on the Website. Receives the ad or content you ask it to analyze
- OpenAI — Transcription and video analysis tools on the Website. Receives the audio or video content you submit to those tools
- Alibaba Cloud (Qwen / DashScope) — The Extension's AI writing features (AI Reply, Rewrite, Find Supplier) and some Website writing tools. Receives the text you selected and your instruction
- DeepSeek — Backup provider for the same AI writing features, used only if the primary provider fails. Receives the same text and instruction
- Resend — Sends account and service emails. Receives your email address and the content of the email
- Discord — Delivers messages you send through our support form to our team. Receives the name, email address and message you enter
- Google (Sign in with Google) — If you choose to sign in with Google, Google provides us your email address, name and profile image to create your account. We do not receive your Google password, and we do not access any other Google service on your behalf
Each provider receives only what it needs for the task listed, and each maintains its own privacy policy. We do not share user data with any other party except as required by law (section 4.5).
4.3 We Do NOT Sell Your Data
We do not sell, rent, lease, or trade your personal information or collected content metadata to any third party. We do not share data with data brokers or advertising networks.
4.4 Limited Use
TrackCreatives' use and transfer of information received through the Extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements, and we apply the same commitments to the Extension in Microsoft Edge and Mozilla Firefox. We use this data only to provide and improve the Extension's research and writing features you use. We do not sell it, do not use or transfer it for advertising, and do not use or transfer it to determine creditworthiness or for lending purposes. People at TrackCreatives do not read it unless you ask us to for support, it is needed for security or legal reasons, or it has been aggregated and de-identified.
4.5 Legal and Safety Disclosures
We may disclose your information if required to do so by law, or if we believe in good faith that such action is necessary to:
- Comply with a legal obligation, subpoena, court order, or government request
- Protect and defend our rights, property, or safety
- Prevent fraud or investigate potential violations of our Terms of Service
- Protect the personal safety of users or the public
5. Extension Permissions Explained
The Extension requests certain browser permissions to function. Below is a complete list of each permission and why it is needed:
- sidePanel — Displays the TrackCreatives research panel alongside the pages you browse on supported platforms
- storage — Stores collected content metadata, your preferences and your signed-in session locally on your device, using the browser's standard extension storage
- activeTab — Allows the Extension to read the publicly visible content of the single tab you chose, when you click the toolbar icon
- tabs — Allows the Extension to detect when you navigate to a supported platform, to open your dashboard in a new tab, and to close the temporary redirect tab after sign-in
- identity — Used for authenticating your TrackCreatives account within the Extension
- downloads — Used only when you explicitly choose to save a file you are researching, such as a reference image or a screenshot, to your own downloads folder. Nothing is ever downloaded automatically
- scripting — Loads the research reader onto a storefront page after you have granted permission for that specific site (see optional permissions below)
Host Permissions
The Extension requests access to the following domains:
- tiktok.com, ads.tiktok.com, library.tiktok.com — To collect publicly available TikTok content, ad library data, and creative center data
- x.com, twitter.com — To collect publicly available posts and profile data from X/Twitter
- instagram.com — To collect publicly available reels and creator profile data while you browse the Reels feed, Explore, and public profiles
- facebook.com/ads/library, web.facebook.com/ads/library — To collect publicly available ad data from the Meta Ad Library. Access is scoped to the ad library path only; the Extension does not run on the main Facebook feed, messages, or account pages
- linkedin.com — To collect publicly available feed posts and public profile data
- adstransparency.google.com, google.com/search — To collect publicly available advertisement records from the Google ads transparency center, and public search results
- displayads-formats.googleusercontent.com — The host the Google transparency center itself uses to serve the images and video of the advertisements being viewed
- youtube.com — To read publicly available channel pages and Shorts while you browse them. Videos are recorded as links with their public view counts; video files are never downloaded, and playback happens through YouTube's own embed. This runs as a content script and the Extension requests no host permission for YouTube
- pinterest.com, substack.com — To collect publicly available pins, boards and publication pages
- amazon.com, amazon.co.uk, amazon.ca, amazon.de, amazon.com.au, aliexpress.com, aliexpress.us — To collect publicly available product page data
- trackcreatives.com — To communicate with our own servers for authentication and data import
Optional Permissions
Storefront inspection can run on the current tab after you click the toolbar, using temporary activeTab access. Automatic storefront detection is a separate, optional setting. If you enable it, your browser asks for access to HTTPS websites so a packaged detection script can identify stores as you browse.
- Automatic storefront detection — This requests broad HTTPS site access, not access to just one store. It is not requested at installation. You can decline the prompt or disable the setting in the extension popup to unregister the script and revoke this optional access.
If you leave automatic detection off, storefront inspection remains available through an explicit toolbar action on the current tab.
6. Local Data Storage on Your Device
The Extension stores collected data locally on your device using the browser's extension storage API. This local data includes:
- Cached content metadata from your browsing sessions (video data, profile data, search results)
- Captured LinkedIn contacts and business listings, until they are exported, imported or cleared
- Your authentication session tokens (encrypted)
- Extension configuration and preferences
- A local activity log of your research actions
To manage storage, the Extension automatically limits the number of cached entries (e.g., recent feed pulls, search results, and profile visits). Older entries are automatically removed when limits are reached. You can clear all locally stored Extension data at any time by right-clicking the Extension icon and selecting "Remove from Chrome" (or "Remove Extension" in Edge and Firefox), or through your browser's extension management settings.
Local data is stored only on your device and is not accessible to other extensions, websites, or users of your computer (unless they have access to your browser profile).
7. Server-Side Data Storage and Security
Data imported to your TrackCreatives account is stored securely using industry-standard practices:
- All data is stored in a PostgreSQL database hosted on Supabase with encrypted connections and row-level security
- Media files (images, video thumbnails) are stored on Cloudflare R2 with access controls
- All data in transit is encrypted using HTTPS/TLS (minimum TLS 1.2)
- Data at rest is encrypted using AES-256 encryption provided by our infrastructure providers
- Authentication tokens are securely generated and rotated by Supabase Auth
- Payment processing is handled entirely by Stripe, which is PCI-DSS Level 1 certified
- Access to production systems is restricted to authorized personnel only
While we implement commercially reasonable security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
8. Data Retention
Account Data
We retain your account information and imported data for as long as your account remains active. If you request account deletion:
- Your personal information (email, name, preferences) will be permanently deleted within 30 days
- Your imported content data, captured leads and business listings, and associated analyses will be permanently deleted within 30 days
- Your usage records and the visit records associated with your account will be deleted or de-identified within 30 days
- Support messages are kept only as long as needed to resolve your request
- Stripe may retain billing records as required by financial regulations
- Data required for legal compliance, dispute resolution, or enforcement of our agreements may be retained as permitted by law
Extension Local Data
Data cached locally by the Extension is stored on your device and persists until you clear it manually or uninstall the Extension. We have no ability to access or delete data stored locally on your device.
Aggregate Data
We may retain aggregated, de-identified data that cannot reasonably be used to identify you for analytics and product improvement purposes. This data is not subject to deletion requests.
9. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Rights Available to All Users
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data and account
- Data portability: Request your data in a structured, machine-readable format
- Withdrawal of consent: Withdraw your consent to data processing at any time by discontinuing use of the Service
Additional Rights for EEA/UK Residents (GDPR)
If you are located in the European Economic Area or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), including:
- Restriction of processing: Request that we limit how we process your data
- Objection: Object to processing based on our legitimate interests
- Lodge a complaint: File a complaint with your local data protection authority
Our legal basis for processing personal data under the GDPR includes: (a) performance of a contract (providing the Service), (b) legitimate interests (improving the Service, preventing abuse), and (c) your consent (where applicable).
Additional Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:
- Right to know: Request disclosure of the categories and specific pieces of personal information we have collected
- Right to delete: Request deletion of your personal information
- Right to opt-out of sale: We do not sell personal information, so this right is already honored
- Non-discrimination: We will not discriminate against you for exercising your privacy rights
To exercise any of these rights, please contact us at support@trackcreatives.com. We will respond to verified requests within 30 days (or sooner if required by applicable law).
10. International Data Transfers
Our servers and third-party service providers may be located in countries other than your own. By using the Service, you consent to the transfer of your information to the United States and other jurisdictions where our service providers operate. We ensure that appropriate safeguards are in place for international transfers in compliance with applicable data protection laws.
11. Third-Party Platforms and Content
The Extension operates on third-party platforms (TikTok, Instagram, Facebook's Ad Library, X/Twitter, LinkedIn, YouTube, Pinterest, Substack, Amazon, AliExpress, Google and Shopify storefronts) that have their own terms of service and privacy policies. We encourage you to review those policies. TrackCreatives is an independent service and is not affiliated with, endorsed by, or sponsored by any of these platforms or their parent companies.
The data collected by the Extension consists of publicly available content that is already visible to any user browsing those platforms. We do not access private, restricted, or authenticated-only content beyond what is publicly displayed on the page you are viewing.
Your responsibility and account safety. You use the Extension and all data-collection features at your own risk, and every action taken through the Service is yours alone. Third-party platforms may suspend, ban, shadow-ban, rate-limit, or restrict accounts they consider to be acting automatically. TrackCreatives does not control those platforms and is not responsible or liable for any action taken against your accounts. We recommend using a separate or dedicated account for live-site capture. See our Terms of Service for the full assumption-of-risk and liability terms.
12. Children's Privacy
The Service is not directed to individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at support@trackcreatives.com.
13. Do Not Track Signals
Some browsers transmit "Do Not Track" (DNT) signals to websites. Because there is no common industry standard for interpreting DNT signals, our Service does not currently respond to DNT signals. However, you can control data collection by uninstalling the Extension or adjusting your account settings.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Post a notice on our Website or within the Extension for significant changes
- Send an email notification for changes that materially affect how we handle your personal data
Your continued use of the Service after changes are posted constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, please discontinue use and delete your account.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
TrackCreatives
Email: support@trackcreatives.com
For GDPR-related inquiries, you may also contact your local data protection authority.