Privacy Policy

Last Updated: March 27, 2026

Overview

AckTracked, Inc ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard information when you visit our website, use the client portal (web, Sign in with Slack), and use our Slack application service.

This policy has three parts: the Website (https://www.acktracked.com), the Client portal (summary only—details in a dedicated document), and the Service (the ACK Slack application).


Part 1: Website (https://www.acktracked.com)

Information Collected on the Website

Our website collects minimal information necessary for operation and security:

Automatically Collected Information

  • Browser data: IP address, browser type, device type, operating system
  • Usage data: Pages visited, time spent on pages, referral source
  • Technical data: Screen resolution, language preferences

Information You Provide

  • Contact forms: Email address and message content (if you contact support)
  • Payment information: Processed by Stripe (we do not store credit card details)

Website cookies

We use essential cookies (and similar technologies) only as needed for basic website functionality and security. We do not use analytics or advertising cookies on the marketing site today.

No consent management banner

We do not operate a cookie consent management platform on https://www.acktracked.com because we do not use non-essential cookies there. If that changes, we will update this policy.

How Website Data is Used

  • Deliver and improve website functionality
  • Respond to support inquiries
  • Process payments for track purchases
  • Detect and prevent fraud or abuse

Part 2: Client portal (web)

The client portal is a separate site from https://www.acktracked.com. You sign in with Slack (OpenID Connect)—not an AckTracked password. For full detail on authentication, session cookies, and data processed at login, see the Client portal access document (single source of truth). This Privacy Policy does not replace that document.


Part 3: Service (AckTracked Slack Application)

What We Receive from Slack

When you use ACK in Slack, we receive the following data from Slack's API:

Workspace & Channel Information

  • Workspace (team) ID and domain
  • Channel IDs and names where ACK is used
  • Channel membership information

User Information

  • User IDs
  • User display names (received from Slack when needed for the Service; not written to operational or system logs; limited retention in application data only where reasonably necessary, as described in our Data Processing Agreement)
  • User presence status (active/away) - checked in real-time, not stored
  • User availability status from status text (OOO, DND, Busy) — used when needed for reminders; not kept as a durable record of user status
  • DND (Do Not Disturb) schedule status - checked in real-time, cached, not persisted

Message Data

  • Message timestamps (to identify specific messages)
  • Thread timestamps (to identify threads)
  • Message permalinks (URLs to messages)
  • Message text from Slack — Full message content may be received for processing (for example via Slack events) or retrieved via the Slack API when needed for the Service; we persist only a truncated message preview (first ~200 characters)—for display if the message is deleted
  • User IDs mentioned in tracked messages
  • Group IDs mentioned in tracked messages

Events & Interactions

  • Reaction events (which reactions were added by which users)
  • Slash command usage
  • Button clicks and modal submissions
  • App Home tab opens

What We Retain (Stored Data)

We store only what's necessary to provide the service:

Tracking Metadata (DynamoDB: TrackedItems)

  • Workspace ID, channel ID, thread timestamp (message identifiers)
  • Tracking item ID (unique identifier)
  • User IDs being tracked (targets) and who has acknowledged
  • Truncated message preview (persisted) (~200 characters)—for display if message is deleted
  • Custom reminder message template (if provided by user)
  • Reminder cadence settings (e.g., every 15 minutes)
  • Tracking status (pending, completed, cancelled)
  • Timeline of events (created, acknowledged, reminded)
  • Created by user ID and timestamp
  • Message permalink URL
  • Note: Full message content may be received from Slack for processing; only a truncated preview (~200 characters) is stored. Full text may also be retrieved from Slack via the API when needed, not persistently stored in full.

OAuth Tokens (DynamoDB: SlackTokens)

  • Bot OAuth access tokens (stored in DynamoDB with KMS encryption)
  • Workspace ID, team name, team domain
  • Bot user ID, app ID, installation timestamp
  • May be held in process memory during active invocations (ephemeral)

Configuration (DynamoDB: Configs)

  • Workspace-level and channel-level settings
  • Default reminder cadences and preferences

Billing & Usage (DynamoDB: BillingUsage)

  • Workspace ID and month (YYYY-MM)
  • Count of tracks created (incremented per track)
  • Usage timestamps

What We Do NOT Store

  • Full message body in durable storage — We do not persist full Slack message text; only a truncated preview (~200 characters) is stored. Full content may be handled transiently for processing or fetched from Slack when needed.
  • Broad or unnecessary identity holdings - Core messaging features primarily rely on Slack user IDs. Limited Slack-sourced names, email addresses, or similar profile or contact fields may be retained in application data only where reasonably necessary (for example authentication, account administration, or client portal sign-in), as described in our Data Processing Agreement and Client portal access. Such fields are not written to operational or system logs.
  • User profile information - We do not maintain a durable profile beyond what the Service requires; availability may be checked when needed for reminders and is not treated as a long-term record
  • Private messages - We only access channels where ACK is installed
  • Thread replies - Only the tracked message metadata and preview
  • Attachments or files - No file content is accessed or stored

How We Use Service Data

Primary Purposes

  • Track messages: Identify which users need to acknowledge messages
  • Send reminders: Automatically remind users who haven't acknowledged
  • Check availability: Respect OOO/DND status when sending reminders (first reminder always sends, subsequent reminders suppressed for unavailable users)
  • Monitor acknowledgements: Detect reactions and update tracking status
  • Display status: Show tracking progress in home tab and commands

Administrative Purposes

  • Billing: Track usage to calculate charges (count of tracks created)
  • Service reliability: Monitor errors and performance
  • Customer support: Troubleshoot issues when requested
  • Improve service: Analyze usage patterns to enhance functionality

Data Storage and Security

Storage

  • Primary persistent storage for Service data we host is in AWS US East (N. Virginia). During normal use, data transits globally between users, Slack, our systems, and subprocessors; subprocessors may store or process data in additional regions. See Security Practices (data location) and Subprocessors.
  • DynamoDB tables: TrackedItems, SlackTokens, Configs, BillingUsage
  • All tables encrypted at rest with AWS KMS
  • Lambda runtime: OAuth tokens may exist in process memory during active invocations (ephemeral)

Security Measures

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest (AWS KMS)
  • Access controls and authentication via OAuth 2.0
  • Regular security audits and monitoring

Data Retention

We retain personal data only as needed for the purposes described in this policy. Retention periods for Service data, website data, operational and audit logs, billing records, uninstall and account deletion, and related procedures (including multi-tenant log limitations) are set out in our Data Retention Policy. High-level security measures for logs and infrastructure are summarized under Security Practices.


Your Rights

You have the right to:

  • Access: Request a copy of your data
  • Deletion: Request deletion of your data (uninstall removes access)
  • Export: Request an export of your tracking history
  • Correction: Request correction of inaccurate data

Data Sharing

We do not sell your data. We may share data only in these circumstances:

  • Service Providers (Subprocessors): We use third-party service providers to help deliver our service. The authoritative list, including role, data categories, and locations, is in our Subprocessors document (also published at https://www.acktracked.com/subprocessors/).
  • Legal Requirements: If required by law or to protect rights and safety
  • Business Transfer: In the event of a merger or acquisition

Subprocessor safeguards: Subprocessors are engaged under written terms that require appropriate security and data protection. The Subprocessors List describes how the list is maintained.


Data Deletion

Uninstalling the AckTracked App

When you uninstall ACK from your Slack workspace, we revoke access and delete or retain data on the schedule and subject to the exceptions described in our Data Retention Policy (including OAuth token removal, cancellation of active tracking items, application data deletion timelines, log retention, and aggregate billing records where required by law).

Requesting Complete Data Deletion

To request immediate deletion of all data (except billing records required by law):


GDPR Compliance

For users in the European Economic Area (EEA):

  • We process data based on legitimate business interests and user consent
  • You have rights under GDPR including access, deletion, and portability
  • Primary hosting for data we store is in AWS US East; international transfers and safeguards are in our Data Processing Agreement and Security Practices. We apply technical and organizational measures aligned with GDPR expectations for our processing.
  • You may file a complaint with your local data protection authority

Children's Privacy

ACK is not intended for use by children under 16. We do not knowingly collect information from children.


Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via Slack or email.


Contact Us

For privacy-related questions or requests, contact us at:

Email: privacy@acktracked.com

Mailing address:
AckTracked, Inc.
99 Wall St, Suite 4556
New York, NY 10005
United States