Privacy Policy
Traqio is a Mobile Measurement Partner (MMP) operated by Khufu FZCO. This policy explains what data the Traqio SDK and API collect, why, who receives it, and how to exercise your rights. It applies to traqio.app, the Traqio console, and the Traqio SDKs embedded in our customers' mobile apps.
1. Who we are
Traqio is a product of Khufu FZCO, IFZA Business Park, A2, Dubai Silicon Oasis, Dubai 341041, United Arab Emirates. For questions about this policy or to exercise any right described below, write to hello@traqio.app. We answer data requests at that address and do not operate a separate privacy portal.
2. Two roles, and which one applies to you
Traqio processes personal data in two distinct capacities, and the rights available to you depend on which one applies.
If you are an end user of a mobile app that embeds the Traqio SDK, the app's publisher is the data controller: they decide to measure, they obtain consent, and they set the retention. Traqio is their data processor, acting on their documented instructions. Direct your requests to that app's publisher first — we will forward a request we receive directly, but we usually cannot identify you across a publisher's data without their help.
If you are a Traqio customer — you signed up for an account, you use the console — we are the controller for your account data, billing records and product usage.
3. What the SDK collects
The Traqio SDK sends a deliberately small set of fields, listed here in full. Attribution needs a signal that links an ad click to an install; it does not need a profile.
- Google Play Install Referrer (Android): the referrer string Google Play attaches to an install, which carries the campaign identifiers of the click that led to it.
- SKAdNetwork postbacks (iOS): aggregated, delayed conversion data sent by Apple. Apple decides what is in them; they contain no device identifier.
- Advertising identifier (GAID on Android, IDFA on iOS) — only when the operating system and the user's choice make it available. On iOS this requires App Tracking Transparency consent obtained by the app publisher; without it, no IDFA is collected and iOS measurement falls back to SKAdNetwork.
- A Traqio-generated install identifier, scoped to a single app. It is not shared between apps and does not form a cross-app identity graph.
- Device and context: OS and version, device model, language, country, and the app's bundle identifier and version.
- IP address, used to derive an approximate country and to fight fraud. It is not stored in the attribution record beyond the matching window.
- Post-install events the app publisher chooses to measure (for example a signup, a purchase, a level completed), with the parameters they attach to them.
- Subscription and in-app purchase revenue, when the publisher connects RevenueCat, matched to the install through an identifier the publisher already controls.
4. What we do not do
Some of the techniques common in this industry are not implemented in Traqio, and this section is a commitment rather than a description of current defaults.
- No device fingerprinting or probabilistic matching. Android attribution is deterministic via the Install Referrer; iOS uses SKAdNetwork.
- No pasteboard or clipboard reading.
- No cross-app identity graph: an install identifier issued for one app is never linked to another app's.
- We do not sell personal data, and we do not share it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA.
- We do not build or sell audience segments, and we do not enrich your data with third-party data brokers.
5. Who receives the data
Attribution only works if measured events reach the ad networks that optimise on them. Those transfers happen because the app publisher configured them, and they are limited to the destinations below.
- Meta (Conversions API) and TikTok (Events API): conversion events forwarded server-side, with the matching parameters the publisher enables, for campaign optimisation and deduplication against the networks' own SDKs.
- Google: AdMob and Google Play data read on the publisher's behalf using credentials they connect.
- RevenueCat: subscription and purchase webhooks, when the publisher connects it.
- Google Cloud Platform (region us-central1, United States): hosting, database and infrastructure.
- Vercel: hosting for traqio.app and the Traqio console.
- PostHog: product analytics on our own website and console — not on customer apps.
- Stripe: payment processing, once paid billing is switched on. Traqio never stores card numbers.
6. Legal bases (GDPR / UK GDPR)
Where the GDPR applies, the app publisher is responsible for establishing a legal basis for the measurement they instruct us to perform — in practice, consent collected through their consent management platform and, on iOS, through App Tracking Transparency.
For the data we control ourselves — your Traqio account, billing records and console usage — we rely on the performance of our contract with you, on our legitimate interest in securing and improving the service, and on consent for the optional analytics cookies described below.
7. International transfers
Traqio is operated from the United Arab Emirates and its infrastructure runs in the United States (Google Cloud, us-central1). Data originating in the European Economic Area or the United Kingdom is therefore transferred outside it.
Those transfers rely on the European Commission's Standard Contractual Clauses, which are included in the data processing agreement we enter into with customers on request at hello@traqio.app.
8. How long we keep it
Raw attribution records, including any advertising identifier, are retained for 90 days — long enough to cover the attribution matching window and to investigate a dispute — and are then deleted.
Aggregated metrics that identify no individual (installs, cohorts, ROAS per campaign) are retained for the life of the account, because deleting them would erase the customer's historical reporting.
Account and billing records are retained for as long as the account exists, and afterwards for the period applicable accounting rules require.
9. Your rights
Subject to the role distinction described above, you may request access to your personal data, its correction, its deletion, a portable copy, or a restriction of or objection to its processing. Where processing rests on consent, you may withdraw that consent at any time, without affecting processing already carried out.
Write to hello@traqio.app. We respond within 30 days. If you are an end user of a customer's app, include the app's name — without it we cannot locate the records, because we hold no identifier that spans publishers.
You also have the right to lodge a complaint with your local supervisory authority.
10. California residents
Traqio does not sell personal information and does not share it for cross-context behavioural advertising, so no "Do Not Sell or Share My Personal Information" mechanism is required. California residents may still exercise the rights to know, delete and correct described above, and we will not discriminate against you for exercising them.
11. Children
Traqio is a business tool sold to app publishers and is not directed at children. Publishers who address their app to children must configure their integration accordingly and must not instruct us to collect advertising identifiers from them.
13. Security
Data is encrypted in transit (TLS) and at rest. Third-party credentials that customers connect — ad network tokens, API keys — are encrypted at the application layer with a key held in a managed secret store, separately from the database.
Access to production data is restricted to what operating the service requires.
14. Changes to this policy
This policy is versioned by date. The current version is dated 2026-09-13. A change that materially widens what we collect or who receives it will be announced to account holders by email before it takes effect.