Operator and contact
TrackAny.Click is operated by MarkenGroup SAS · Calle 5SUR #25-233 · Medellín, Antioquia · Colombia · NIT 902 003 798-4. Questions, access requests and deletion requests can be sent to office@marken-group.com.
Data we process
Account data includes the signed-in user's email address, name, organization, project, roles and security metadata needed to provide the service.
When a user connects Meta Ads or Google Ads, TrackAny.Click receives an OAuth grant and reads the advertising accounts that user may access. For a selected account, it mirrors account ID, name, currency and time zone plus campaign, ad set or ad group, and ad IDs and names. Daily reporting data includes impressions, clicks, spend and provider conversion fields. TrackAny.Click does not create, edit or publish campaigns.
With a customer's consent implementation, the first-party tracker can receive pseudonymous visitor and session identifiers, event name and time, page path without query or fragment, allowlisted UTM and click identifiers, and optional event value and currency. Customers must not send names, email addresses, phone numbers, secrets or other unnecessary personal data in paths or custom properties.
Why we use the data
We use account data to authenticate users, enforce organization and project permissions, secure integrations and provide support. We use advertising and first-party measurement data to display authorized reports, compare campaign cost and traffic with observed customer journeys, calculate metrics such as CTR, CPC and CPM, and—only where the measurement basis is complete—support ROAS and CAC reporting.
OAuth tokens and provider boundaries
Meta and Google credentials are stored server-side in encrypted form and are never exposed to customer websites. Provider secrets are kept separately. Meta is requested with ads_read only. The integration uses fixed read operations and does not offer a generic provider proxy or advertising mutation endpoint.
Google user data obtained through Google APIs is used only to provide the user-facing TrackAny.Click reporting functions described here. Its use and transfer are intended to comply with the Google API Services User Data Policy, including the Limited Use requirements.
Sharing and infrastructure
Data is processed by infrastructure and subprocessors needed to operate the service, including Google Cloud and Firebase. The current backend is hosted in the United States. Meta and Google receive OAuth and API requests when a connected user authorizes or synchronizes an account. We do not sell connected advertising data or use it for unrelated advertising.
Consent, retention and security
The TrackAny.Click browser SDK starts with consent denied and does not create tracking identifiers, access its storage or send measurement events until the host website grants consent. Withdrawing SDK consent stops future SDK collection and clears the SDK's local identifiers; it does not by itself delete data already stored on the server.
Raw first-party events have a default retention target of 395 days. Connection and mirrored advertising data are retained while needed to provide the connected service and for a limited period required for security, backup or legal obligations. Access is tenant- and project-bound; tokens are encrypted and raw event and integration collections are not directly readable by web clients.
Your choices and rights
A user can disconnect an advertising integration in TrackAny.Click and can also revoke the grant in the connected Meta or Google account. For access, correction, export, objection or deletion, contact office@marken-group.com from the account email and identify the organization and project. We verify authority before disclosing or deleting tenant data. The data-deletion page describes the exact request process.