Privacy Policy
Effective date: May 13, 2026
The short version
- • No account, no sign-up, no email required to use Tracky.
- • We don't ask for your name, address, or payment info.
- • We collect anonymous product analytics through Statsig to improve the app.
- • We never sell your data and we don't run third-party ads.
- • Analytics are essential to operate and improve Tracky and can't be disabled in-app.
1. Who we are
Tracky ("Tracky", "we", "us") is an iOS application that tracks Amazon product prices and notifies you when they drop. This Privacy Policy describes what data the app handles, why, and your rights. It applies to the Tracky iOS app and the marketing site at tracky.app.
2. No account required
Tracky does not require you to create an account. You don't give us an email, phone number, password, or social login. Your tracked products and notification preferences are stored locally on your device and, where needed for price-checking and push delivery, tied only to an anonymous device identifier we generate.
3. Data we process
We keep data collection to the minimum required to run the app:
- Tracked product URLs & targets — the Amazon links you save and your target prices, used to check prices and trigger alerts.
- Anonymous device ID — a random identifier generated on first launch, used to associate your tracked items and push token with a device, not a person.
- Push notification token — an opaque token from Apple, used only to deliver price-drop alerts.
- Product analytics (Statsig) — anonymous events such as screen views, feature usage, button taps, app version, OS version, device model, and country (derived from IP, then discarded). See the Statsig section below.
- Crash & performance diagnostics — standard Apple-provided crash reports if you've opted in via iOS Settings → Privacy & Security → Analytics.
We do not collect: names, email addresses, phone numbers, contacts, photos, precise location, health data, financial data, or browsing history outside the app.
4. Product analytics via Statsig
We use Statsig as our product analytics processor. Statsig helps us understand how people use Tracky so we can fix bugs and prioritize improvements. Events sent to Statsig are tied to the anonymous device ID — never to your name, email, or Apple ID.
Typical events we log:
- App opened, screen viewed, tracker created or removed.
- Notification opt-in state, alert delivered, alert tapped (no product details are sent in plain text).
- App version, OS version, device model, locale, country.
Statsig acts as a data processor on our behalf under a Data Processing Agreement. Because analytics are essential to operate, secure, and improve Tracky, they can't be turned off from inside the app.
5. Why we process this data (legal bases)
- Performance of the service — storing trackers, checking prices, sending you alerts.
- Legitimate interests — measuring product performance and stability with anonymous analytics.
- Consent — for push notifications and, where required by law, for analytics.
7. Data retention
Tracked products and preferences live on your device and on our backend for as long as you keep them. Analytics events are retained by Statsig for up to 24 months. Deleting the app removes local data; to also delete server-side data tied to your anonymous device ID, reach out via our contact form.
8. Your rights
Depending on where you live (EEA/UK GDPR, California CCPA, and similar laws), you have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to processing based on legitimate interests. Because Tracky is account-less, we identify your data via your anonymous device ID — you can find it in Settings → About.
To exercise any right, send a request through our contact form. You also have the right to lodge a complaint with your local data protection authority.
9. Children's privacy
Tracky is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect data from children. If you believe a child has used the app, contact us and we'll delete any related data.
10. Security
Data in transit is encrypted with TLS. Backend data is stored on access-controlled infrastructure. No system is perfect — please report any suspected vulnerability through our contact form.
11. International transfers
Our sub-processors may process data in the United States and other countries. Where required, transfers from the EEA/UK rely on Standard Contractual Clauses or equivalent safeguards.
12. Changes to this policy
We'll update this page when our practices change and revise the effective date above. Material changes will be highlighted in the app.
13. Contact
Privacy questions? Reach us through our contact form.