STSaaS Tracker
PricingInteractive demoProduct tourUse casesResourcesAboutSecurityFAQSign in
Menu
PricingInteractive demoProduct tourUse casesResourcesAboutSecurityFAQSign in
← All terms & policies
02 / 07

Terms & Policies

Terms of ServicePrivacy PolicySecurity and Data-Handling OverviewAI Limitations and Human-Review StatementSubprocessor and Third-Party Service Provider ListSupport and ContactData Export and Deletion Procedure

SaaS Tracker legal document

Privacy Policy

Effective dateSeptember 5, 2026

This Privacy Policy (this “Policy”) explains how SaaS Tracker LLC, a Wyoming limited liability company ("SaaS Tracker," "ST," "we," "us," or "our"), collects, uses, discloses, and protects personal information in connection with saastracker.co, the SaaS Tracker website, platform, communications, and related services (collectively, the "Service").

This Policy applies to business customers, prospective customers, account applicants, authorized users, website visitors, and other adults who interact with the Service. The Service is intended only for businesses and individuals who are at least 18 years old.

1. Our roles

SaaS Tracker is generally the controller or business responsible for account, website, marketing, product support, security, and operational data. When a customer submits monitored URLs, contracts, legal documents, relationship context, or other content for SaaS Tracker to process on the customer's behalf ("Customer Content"), SaaS Tracker acts as the customer's processor or service provider with respect to that Customer Content, except to the extent SaaS Tracker processes it for its own independent purposes specifically identified in this Policy (such as security, service improvement, and compliance). The customer remains responsible for its instructions, notices, permissions, authority, and legal basis for Customer Content, including any personal information contained in monitored public documents or customer-supplied context. For transactions processed through Stripe Managed Payments, Sold through Link, LLC ("Link") and applicable Stripe entities act as merchant of record and/or independent controllers for payment, order-management, fraud, dispute, indirect-tax, transaction-support, and compliance purposes under their own notices and terms. A data processing addendum is available to customers upon request where required by applicable data protection law.

2. Personal information we collect

We may collect the following categories of personal information, depending on how the Service is used:

  • Account and contact information, such as name, business email address, organization, job title, account identifiers, authentication attributes, and communication preferences.
  • Trial, eligibility, and lifecycle information. When an authorized user creates an organization for a free trial, we process the proposed organization name; account, business-email, role, identity, and authority information; the applicant's eligibility and organization-history attestations; available internal organization, trial, paid-subscription, and complimentary-access history results; acceptance and acknowledgement records; authoritative trial start and expiry times; plan and capacity state; invitations and member roles; usage and security events; lifecycle-notice delivery and preference records; checkout initiation; and paid-activation or expired/read-only status. We do not require payment information to create the organization or start the trial. We may review account and organization information after creation to prevent repeat trials, fraud, abuse, security risk, prohibited use, or other ineligibility. If an authorized organization representative later begins checkout, the merchant of record and payment providers process payment, billing, tax, fraud, receipt, dispute, and transaction-support information under their terms, and provide SaaS Tracker the limited transaction and subscription information needed to administer access and records.
  • Organization and workspace information, including organization name, team membership, role, invitations, assignments, settings, and audit activity.
  • Customer Content, including submitted URLs, uploaded or retrieved legal documents, contract or vendor relationships, document versions, comparisons, annotations, review decisions, relationship context, and instructions supplied to the Service.
  • Monitoring and AI output, including retrieval metadata, version histories, document changes, summaries, potential-impact analyses, recommended actions, citations, prompts, responses, model and token metadata, and provider request identifiers.
  • Payment and commercial information, including plan, order and subscription identifiers, invoices, transaction and refund status, billing contact, payment method type, card brand, and limited payment identifiers. Link, Stripe, their affiliates, and participating payment providers receive and process full payment-card details, billing information, fraud and device signals, transaction records, and information associated with a Link account. SaaS Tracker receives limited order, subscription, and transaction-status information needed to provision and support the Service and does not store full card numbers or card security codes.
  • Support and communications, including account-registration information, messages, attachments, feedback, survey responses, and records of our response.
  • Technical, device, and usage information, such as IP address, browser and device information, pages and features used, timestamps, referrer, cookies or similar identifiers, diagnostic information, rate-limit events, security events, and logs.
  • Marketing and communications information, such as contact preferences, outreach records, and communication engagement. SaaS Tracker does not currently use optional website analytics, advertising pixels, conversion APIs, remarketing, or audience matching.
  • Inferences, such as likely product interests, account risk indicators, or potential relevance of a document change to a customer-provided business relationship.

Please do not submit special-category or sensitive personal information unless it is necessary, lawful, and expressly permitted by your agreement with SaaS Tracker. Do not submit passwords, API credentials, payment-card data, government identifiers, or unnecessary confidential, privileged, or sensitive information in free-text fields, monitored documents, URLs, or support messages. If you submit such information despite this guidance, you are responsible for ensuring that you have the legal basis and authority to do so, and SaaS Tracker disclaims, to the extent permitted by applicable law, any additional obligations that may arise from the sensitivity of that information.

3. Sources of information

We collect information directly from users and customer administrators; automatically from browsers, devices, and use of the Service; from publicly accessible websites and the URLs customers direct us to monitor; from a customer's authorized users and integrations; and from service providers such as WorkOS and its approved providers for hosted authentication and associated security and operational telemetry, OpenAI and Cloudflare for hosting and platform infrastructure, OpenAI for AI processing, Resend for email delivery, Oracle Cloud Infrastructure for malware-scanning infrastructure, and Link and Stripe for payment and subscription transactions.

4. How we use personal information

We use personal information to:

  • provide, authenticate, operate, maintain, and improve the Service;
  • retrieve and preserve source documents, compare versions, generate AI-assisted analyses, create permanent records, and deliver alerts or digests;
  • administer workspaces, invitations, roles, API credentials, exports, settings, billing, and support;
  • verify identity and authority; create and administer an organization workspace; provide Essentials trial access; enforce the one-trial and security rules; review organization history and account activity after creation to prevent repeat trials, fraud, abuse, security risk, prohibited use, or other ineligibility; show trial start, expiry, and account state; send necessary service and expiry notices; preserve audit and acceptance evidence; process an authorized paid checkout; and administer read-only, export, deletion, and legal-hold workflows;
  • protect the Service, customers, and others; prevent fraud and abuse; enforce rate limits; investigate incidents; and maintain audit and recovery records;
  • administer plans and subscriptions; reconcile order, payment, refund, and entitlement status; and maintain accounting records, while Link and Stripe perform merchant-of-record, payment, invoicing, indirect-tax, fraud, dispute, and transaction-support functions for Managed Payments transactions;
  • understand product usage, measure performance, troubleshoot, conduct research, and develop features;
  • send eligibility-request, review-status, trial-start, security, authentication, workspace, invitation, expiry, checkout, receipt, billing, export, deletion, privacy-rights, and legally required service communications. We do not use service-message acceptance to enroll a user in optional marketing. Optional marketing choices are separate, recipient-specific, and withdrawable. Expiry stops queued trial-activity messages except for the expiry notice and communications necessary for security, authentication, user-requested billing, privacy rights, export, deletion, legal compliance, and service administration;
  • comply with law, respond to lawful requests, establish or defend legal claims, and enforce our agreements.

5. Legal bases for EEA and UK processing

Where the EU General Data Protection Regulation or UK GDPR applies to our processing, we rely on one or more of these legal bases: performance of a contract or steps requested before entering one; our legitimate interests in operating, securing, supporting, improving, and marketing a business service, balanced against individual rights; consent where required for certain optional marketing communications; and compliance with legal obligations. We may also process information to establish, exercise, or defend legal claims. A person may withdraw consent at any time without affecting earlier lawful processing and may object to processing based on legitimate interests.

6. AI-assisted processing

SaaS Tracker uses artificial intelligence to help summarize retrieved document text and document changes and identify potential business or contractual relevance. At an authorized user’s request, relevant text from a preserved document version, document differences, bounded relationship context, section identifiers, and analysis instructions may be sent to OpenAI to generate a Current Terms Brief or change brief. We use API configurations designed to prevent customer data from being used to train AI models. The response, model and token metadata, associated source version or change record, citation and extraction-coverage data, user or workspace identifiers needed for traceability, and provider request identifier may be stored for traceability, quality, operations, cost monitoring, customer review, and audit history. AI output can be incorrect, incomplete, outdated, misleading, or fabricated; is not legal advice; and does not determine which agreement governs a customer’s relationship. SaaS Tracker is not liable for any decisions made or actions taken in reliance on AI output. SaaS Tracker does not use AI output to make decisions about individuals that produce legal or similarly significant effects. Customers must review the source documents, cited passages, applicable agreements, and obtain qualified advice before acting.

7. Cookies, analytics, advertising, and browser opt-out signals

SaaS Tracker does not currently use optional website analytics or advertising technologies. Google Analytics 4, Google Ads, Meta Ads, advertising pixels, conversion APIs, remarketing, audience matching, and signup-event measurement are not active on the Service. We do not present an analytics-consent control because there is no optional analytics or advertising tag to enable. The Service and its necessary providers may still process limited cookies or local storage and IP/network, browser/device, authentication, security, fraud-prevention, diagnostic, and operational information needed to deliver and protect the Service. WorkOS Hosted AuthKit and its approved providers separately perform necessary hosted-authentication, reliability, fraud and bot-prevention, and security and operational processing; that processing is not optional website analytics. We recognize qualifying browser opt-out preference signals, including Global Privacy Control, as requests to opt out of sale or sharing where required by applicable law. SaaS Tracker does not currently sell personal information for monetary consideration, share personal information for cross-context behavioral advertising, or use targeted advertising. Because those activities and optional analytics are not active, a qualifying signal does not need to disable an active analytics or advertising tag. The absence or later removal of a signal does not constitute consent. Google may continue to retain or make available historical analytics information collected before GA4 was removed, in accordance with Google’s applicable terms, settings, and deletion practices; this update does not represent that historical Google data has been deleted. You may email hello@saastracker.co with the subject “Privacy Opt-Out.”

8. How we disclose personal information

We may disclose personal information to:

  • OpenAI for ChatGPT Sites hosting, maintenance, deployment and hosting-control-plane services, and AI-assisted document analysis;
  • Cloudflare for application execution, content delivery, databases, object storage, network security, and related infrastructure supporting the hosted Service;
  • WorkOS and its approved providers for hosted account authentication, sign-in, organization identity, invitations, sessions, access management, fraud and bot prevention, and associated security and operational telemetry;
  • Resend for invitations, alerts, digests, support, service communications, and other operational or marketing email delivery;
  • Oracle Cloud Infrastructure for the private malware-scanning service and associated infrastructure, security, and operational logs;
  • Sold through Link, LLC, Stripe entities, and participating payment providers for merchant-of-record services, checkout, payment processing, billing, subscriptions, invoices and receipts, indirect-tax administration, fraud prevention, disputes, transaction-level support, refunds, order management, and regulatory compliance;
  • Google for retention and administration of historical public-site analytics collected before GA4 was removed; SaaS Tracker does not send Google new website analytics data after removal;
  • GoDaddy for domain registration and DNS services; and
  • professional advisers, auditors, insurers, government authorities, parties needed to protect rights, safety, or security, potential transaction counterparties, and a successor or participant in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, in each case subject to applicable law and appropriate duties.

Within a customer workspace, information may be visible to other authorized members according to their roles. Customers control whom they invite and are responsible for those access decisions. Our current providers and their roles are described in the Subprocessor and Third-Party Service Provider List, which we may update as the Service changes.

9. International transfers

SaaS Tracker is based in the United States, and information may be processed in the United States and other countries where we or our providers operate. Where required for transfers from the EEA, United Kingdom, or Switzerland, we rely on recognized safeguards such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism. You may contact us for information about applicable safeguards.

10. Retention

Pending or Denied eligibility requests do not create a workspace or trial. We retain minimized request, evidence-reference, decision, sanctions, security, audit, and dispute records only for their approved purposes and retention periods; we do not retain unnecessary identity-document copies, free-form narratives, or unrelated personal data merely because a review occurred. After trial expiry, active processing stops and the workspace may remain available in a limited read-only state under the Terms. Read-only access is not a backup, archival, or perpetual-storage service. We retain account, workspace, acceptance, security, billing, support, audit, export, deletion, and legal-hold records only for the applicable purposes and periods described in this Policy and the Data Export and Deletion Procedure. An authorized organization owner may export available organization data or request deletion. Deletion timing, provider propagation, backup aging, security records, legal holds, disputes, and other permitted exceptions remain governed by the Data Export and Deletion Procedure; trial expiry alone is not represented as deletion. Link, Stripe, and other independent controllers determine retention for payment, order, tax, fraud, dispute, and Link-account records under their own legal obligations and privacy notices; a qualifying deletion request to Link may result in cancellation of an associated Managed Payments subscription. Public-source documents may remain available from their original publishers, and de-identified or aggregated information may be retained where it cannot reasonably identify a person.

11. Security

We use administrative, technical, and organizational measures designed to protect information, including access controls, tenant-scoped authorization, transport encryption, private evidence storage, audit records, rate limits, backup verification, and restrictions on retrieval of unsafe network locations. No method of transmission or storage is completely secure. In the event of a security incident involving personal information, we will provide notification as required by applicable law. The Security and Data-Handling Overview provides additional information.

12. Privacy rights

Depending on location and subject to exceptions, a person may have rights to access, correct, delete, restrict, or obtain a portable copy of personal information; object to certain processing; withdraw consent; opt out of sale, sharing, or targeted advertising; limit certain sensitive-data uses; and appeal a denied request. A person may also complain to a data protection authority. EEA authorities are listed through the European Data Protection Board, and UK complaints may be made to the Information Commissioner's Office. To exercise a right, email hello@saastracker.co with the subject “Privacy Request” and describe the request, jurisdiction, account email, and organization. To appeal a denied request, email hello@saastracker.co with the subject “Privacy Appeal.” We may verify identity and authority, ask for information reasonably necessary to locate records, or direct a customer end user to the relevant customer when we process the information only on that customer's behalf. Requests concerning payment, order, tax, fraud, dispute, or Link-account data controlled by Link, Stripe, or another payment provider may need to be submitted directly to that provider. Authorized agents may submit requests where permitted, subject to proof of authority. We will respond within the time required by applicable law and will not discriminate for exercising applicable privacy rights.

13. US state privacy disclosures

The categories described in Section 2 correspond generally to identifiers, customer records, commercial information, internet or electronic activity, professional information, and inferences. We collect, use, retain, and disclose them for the business and commercial purposes described above. We do not knowingly sell personal information for monetary consideration or share personal information for cross-context behavioral advertising. We do not currently use optional website analytics, Google Ads, Meta advertising tools, or targeted advertising. Section 7 explains how we treat qualifying opt-out preference signals. We do not knowingly sell or share the personal information of anyone under 18.

14. Customer-controlled information

If your information appears in Customer Content, the customer that controls the workspace is generally responsible for responding to your request. Contact that customer first when practicable. We will assist the customer as required by contract and law. SaaS Tracker does not control changes made by third-party publishers to documents that customers monitor.

15. Children

The Service is for businesses and adults aged 18 or older. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can investigate and delete it where appropriate.

16. EEA and UK representatives

EEA Representative: SaaS Tracker has not appointed an EEA representative because it does not believe its processing activities currently require one under Article 27 of the GDPR. SaaS Tracker will appoint an EEA representative and update this Policy if and when required. UK Representative: SaaS Tracker has not appointed a UK representative because it does not believe its processing activities currently require one under Article 27 of the UK GDPR. SaaS Tracker will appoint a UK representative and update this Policy if and when required. SaaS Tracker has not designated a data protection officer. Privacy questions may be sent to hello@saastracker.co.

17. Changes to this Policy

We may update this Policy as the Service, providers, or law changes. We will post the revised version and change the effective date. Where required, we will provide additional notice or obtain consent before a material change applies.

18. Contact

SaaS Tracker LLC 30 N. Gould St., Ste R, Sheridan, WY 82801, United States Email: hello@saastracker.co

← Return to all terms & policiesQuestions? hello@saastracker.co →
STSaaS Tracker

Legal change intelligence, built one reliable record at a time.

Interactive demoProduct tourPricingUse casesResourcesAboutSecurityFAQContactTerms & Policies
© 2026 SaaS Tracker LLC.
Privacy Policy — SaaS Tracker