Last updated 1 October 2026

Security

Where trckable Cloud keeps your data, how it is protected, and how to tell us about a problem.

In short

  • Cloud runs on servers in Amsterdam, and its backups stay in the EU.
  • No IP address of a visitor is ever stored.
  • Everything travels over HTTPS, and backups are encrypted.
  • Two-step sign-in is open to every account.
  • Found a problem? Write to legal@trckable.com, or report it privately on GitHub. Research in good faith is welcome.

Where your data is#

trckable Cloud runs on servers in Amsterdam, the Netherlands, and its backups are stored in the EU. The privacy policy lists every company that handles data for Cloud, and what for, and the data processing agreement has the terms.

How it is protected#

  • Every page and every API call is served over HTTPS, and browsers are told to insist on it.
  • Cloud's pages carry a strict content security policy. Its session cookies cannot be read by scripts (HttpOnly), travel over HTTPS only (Secure) and are not sent along with requests from other sites (SameSite).
  • No IP address of the people who visit your sites is stored. It is used once, in memory, to work out the country, and then dropped.
  • Card details go straight to Paddle, which sells Cloud to you. We never see or store a card number.
  • Read-only API keys can read your numbers and can never change a setting, a site or a payment.

Signing in#

You sign in with a code sent to your email, or with Google. A code works for ten minutes, and we keep it only as a salted hash.

Every account can add a second step in its account settings: a code from an authenticator app, with recovery codes for a lost phone. Our own admin pages open only to accounts that have it on.

Backups#

Cloud writes an encrypted backup every night and copies it to storage in the EU. Backups are encrypted with AES-256-GCM before they leave the server. A deleted account leaves our backups within 30 days of its deletion.

Reporting a problem#

If you find a security problem, please tell us first and in private. There are two ways:

Say what you found, how to reproduce it and what someone could do with it. You will hear back within three working days, and we keep you updated until it is fixed. Please give us time to fix the problem before you publish it.

There is no paid bounty. If you wish, we credit you when the fix is out. This address is also in our security.txt.

What is in scope#

In scope:

  • trckable.com and docs.trckable.com;
  • trckable Cloud, at cloud.trckable.com;
  • the open-source trckable software: the server, the dashboard, the tracker and the trckable npm package.

Out of scope:

  • denial of service, and anything that sends large amounts of traffic;
  • brute-forcing sign-in codes or passwords, and mass sign-ups;
  • social engineering of our team or customers, and physical attacks;
  • services run by others, such as Paddle, Cloudflare, Railway, Resend, OpenAI and Google: report those to them;
  • reports that only say a header or a setting could be stricter, with no way to use it.

Please test only against your own account and your own data.

Safe harbour#

If you look for problems in good faith, stay within the scope above, do not read, change or keep other people's data beyond what is needed to show the problem, and tell us before you tell anyone else, we will not pursue legal action against you or ask others to.