Skip to content
novatrack.io
  • How it works
  • Click data
  • Fraud detection
  • Pricing
  • Blog
Sign in Request a demo
  • How it works
  • Click data
  • Fraud detection
  • Pricing
  • Blog
Sign in Request a demo

Legal

Privacy policy

NovaTrack is a click tracking service, so we take a clear position on data: we collect what the service needs, we store it in the European Union, we name every party that receives any of it, and we never sell it.

Last updated on 1 September 2026

On this page

  • Who is responsible
  • Two different situations
  • What we collect
  • Why we use it, and on what basis
  • How long we keep it
  • Who has access
  • Transfers outside the European Union
  • Security
  • Your rights
  • Changes to this policy

Who is responsible

The controller of the personal data described in this policy is:

LEO BUSINESS, SASU, registered office at 14 bis boulevard Senard, 92210 Saint-Cloud, France, registered with the RCS of Nanterre under number 995 027 455, trading as NovaTrack.

For any question about this policy or about your data, write to contact@novatrack.io.

Two different situations

This policy covers two situations that are legally distinct and should not be confused.

1. You visit this website or contact us

Here we act as controller. We decide what is collected and why. This concerns anyone browsing novatrack.io or sending the demo request form.

2. You click a NovaTrack tracking link

Here we act as processor on behalf of our customer, the advertiser who created the link. That customer decides why the data is collected and remains responsible for informing you and for having a valid legal basis. We process the data only on their documented instructions, under a data processing agreement. If you clicked a NovaTrack link and want to exercise your rights, contact the advertiser whose page you landed on. If you cannot identify them, write to us and we will forward your request.

What we collect

Website visitors

Our hosting provider keeps standard server logs of every request to these pages, including IP address, date, requested page and user agent, for security and troubleshooting.

The public pages also load Google Tag Manager, container GTM-N2BZT7SH, which we use to deploy audience measurement tags. Those tags may place cookies on your device and send Google your IP address, the page viewed, the referring page and your user agent. Measurement is not strictly necessary to serve these pages, so it runs on the basis of your consent and you can withdraw that consent at any time. What it produces is aggregate readership of this website. It is never combined with the click data we process for customers, and it never feeds an advertising profile. The cookie policy describes this in detail.

The pages also load a web font stylesheet from Google Fonts, which places no cookie but does mean your browser connects to that service.

Demo requests

When you send the request form we collect your first name, last name, work email, company name, website, indicative click volume and advertising budget, any message you write, plus the date, your IP address and your browser user agent, which are kept to guard against automated submissions.

Customer accounts

For account holders we hold the identity and contact details of the users we create, the tracking links they configure and the data needed for billing and support exchanges.

Click data processed for customers

When a visitor clicks a tracking link, the following is recorded server side: date and time, IP address, internet provider and network operator, network number, connection type, approximate location derived from the IP address at country, region and city level, device type and model, screen size, operating system, browser, browser language, time zone, referrer, the destination URL served and the campaign parameters carried by the link.

No cookie and no identifier are written to the visitor's device by the redirect. Nothing is read from the device beyond what the browser sends with any ordinary web request.

Why we use it, and on what basis

PurposeDataLegal basis
Answering a demo request and assessing whether the service fits Form fields Steps taken at your request before entering into a contract, and our legitimate interest in developing the business
Providing the service to account holders Account and configuration data Performance of the contract
Recording clicks and detecting invalid traffic Click data On behalf of our customer, on the basis they have determined, generally their legitimate interest in measuring their advertising and protecting their budget from fraud
Measuring how this website is used Tag manager and measurement data: IP address, pages viewed, referrer, user agent, measurement cookies Your consent, given before any non-essential cookie is placed and withdrawable at any time
Adding network, location and hosting information to a recorded click The visitor's IP address, sent to our lookup provider On behalf of our customer, as part of recording the click and detecting invalid traffic
Keeping the service secure and available Server logs, redirect journal, anti-spam signals Our legitimate interest in protecting the service from abuse
Invoicing and accounting Billing data Legal obligation

How long we keep it

Demo requests that do not lead to a contractThree years from the last contact with you
Click dataThirteen months, unless the customer contract sets a shorter or longer period
Account dataFor the duration of the contract, then archived where a legal time limit requires it
Invoices and accounting recordsTen years, as required by French commercial law
Server logsTwelve months at most
Redirect journal (every request to a tracking link, forwarded or refused: IP address, user agent, request headers, the destination asked for and the answer given)Thirty days, for security and to investigate a link that misbehaves

At the end of these periods the data is deleted or irreversibly anonymised.

Who has access

Personal data is accessible to the staff of LEO BUSINESS who need it to run the service, and to the following categories of recipient:

  • our hosting provider, IONOS SARL, on servers located in the European Union
  • our address lookup provider, ip-api.com, operated by Fraudlogix, which receives the IP address of a click and returns the network, the operator and the approximate location. The address is sent over TLS, alone, with nothing attached to it: no link, no customer, no destination and no identifier, so the provider has no way to reconstruct a visit. Results are cached on our side so the same address is not sent twice
  • Google Ireland Limited, for the tag manager and the measurement described above, and for the web fonts loaded by these pages. This concerns visitors to this website only. It never applies to click data
  • where applicable, our accountant and our payment provider, for invoicing
  • public authorities, where a legal obligation requires disclosure

We do not sell personal data, we do not rent it, and we do not share it with advertising networks or data brokers. Click data belonging to one customer is never shown to another.

Transfers outside the European Union

Click data and account data are stored on servers located in the European Union, and the visit log never leaves them.

Two processing operations may involve a transfer outside the European Economic Area, and both are listed rather than buried in a general clause.

  • Website measurement and web fonts. Google may process data relating to visitors to this website in the United States. The transfer relies on the standard contractual clauses adopted by the European Commission, and on Google's adherence to the EU-US Data Privacy Framework. This affects people browsing novatrack.io, not people clicking a tracking link.
  • Address lookups. An IP address recorded on a click is sent over TLS to our lookup provider, which may process it outside the European Economic Area. The transfer relies on the standard contractual clauses. Nothing accompanies the address, and no result is sent back to anyone but us.

Any other transfer would be described here before it started, and covered by an appropriate safeguard under chapter V of the General Data Protection Regulation.

Security

The service is served over HTTPS only, with strict transport security enforced across the whole domain. Access to accounts is protected by individual credentials, access to production data is limited to the people who need it, and destination addresses on every tracking link are restricted to a list registered by the customer so that a link cannot be turned into a route to a third party page.

No system is completely immune. If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority and, where required, the people concerned, within the deadlines set by the regulation.

Your rights

Under the General Data Protection Regulation you may ask for access to your data, correction of inaccurate data, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. You may also give instructions on what happens to your data after your death.

Send your request to contact@novatrack.io. We reply within one month. We may ask for proof of identity if there is reasonable doubt about who is making the request.

If you believe your rights are not respected, you may lodge a complaint with the French data protection authority, the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or through www.cnil.fr.

Changes to this policy

This policy may change as the service evolves or as the law requires. The date at the top of this page always shows the current version. If a change materially affects how we use your data, account holders are informed by email before it takes effect.

novatrack.io

Click tracking infrastructure for advertisers who want to see where every click came from, and where it went.

Product

  • How it works
  • Click data
  • Fraud detection
  • Pricing
  • Blog
  • Sign in

Company

  • Request a demo
  • Contact and company
  • contact@novatrack.io

Legal

  • Terms of service
  • Privacy policy
  • Legal notice
  • Cookie policy

© 2026 LEO BUSINESS SASU. All rights reserved.

LEO BUSINESS, SASU registered with the RCS of Nanterre under number 995 027 455, 14 bis boulevard Senard, 92210 Saint-Cloud, France.