Skip to content

Security

Security and privacy at every layer

ArcTrack handles click and conversion data for performance-marketing businesses. Here is how we protect accounts, keep every workspace separate and limit what we keep.

Profile security settings: two-factor sign-in is enabled, the password was changed a month ago and two sessions are active.
Three API keys for an analyst, a partner and an admin; only a short prefix of each key is displayed.

How we protect your data

Safeguards built into every request

From the tracking edge to the panel and the API, the same rules apply to every workspace, user and key.

Encryption in transit

  • HTTPS on every website, panel and tracking hostname, with certificates issued automatically per domain.
  • HTTP Strict Transport Security on the panel.
  • Database, cache and analytics services are only reachable on the private network.

Credentials

  • Passwords hashed with argon2id; a minimum of 10 characters.
  • Session tokens and API keys are stored only as SHA-256 hashes.
  • Optional TOTP two-factor sign-in; secrets encrypted with AES-256-GCM.
  • Sign-in attempts are rate limited per IP address and account.

Access control

  • Role-based access in every workspace: owner, admin, manager and analyst.
  • Partners and advertisers see only their own records, enforced on the server for every request and API call.
  • API keys carry the same roles and restrictions as people.

Data isolation

  • Every record belongs to one workspace and every query is scoped to the signed-in workspace.
  • Reporting runs with a read-only analytics account with query time and size limits.
  • Postback and conversion tokens are per workspace and per advertiser.

Audit trail

  • Changes to offers, partners, conversions, users, keys and settings are written to an audit log.
  • IP addresses in security logs are stored as keyed hashes, not in clear text.

Retention & backups

  • Click and impression logs are deleted automatically after 13 months.
  • Regular database backups for disaster recovery.
  • Expired sessions and one-time links are purged automatically.

Abuse prevention

  • Transparent links only redirect to allowlisted destinations; anything else receives an error page.
  • No cloaking or conditional-destination features exist in the product.
  • Bot and data-centre traffic is flagged on every click.

Privacy commitments

  • Tracking endpoints work without cookies unless a customer enables the pixel cookie.
  • A Data Processing Addendum with Standard Contractual Clauses for every customer.
  • We do not sell personal data or use tracking data for our own advertising.

Audit trail

Every change, on the record

Workspace admins can see who changed an offer, approved a conversion, created a key or invited a user — and when.

  • Offers, partners, conversions, users, API keys and settings are all logged.
  • Filter by person, action or object, and export the log as CSV.
  • Sign-ins, password changes and two-factor changes are recorded too.
Audit log with five recent changes: an offer update, approved conversions, a new API key, an approved partner and a user invitation.

The specifics behind our safeguards

Password hashing, minimum 10 characters
argon2id
Session tokens and API keys stored only as hashes
SHA-256
GCM encryption for two-factor secrets
AES-256
Click and impression logs, then deleted automatically
13 months

Reporting a vulnerability

If you believe you have found a security issue, send the details and steps to reproduce through the contact form.

  • Give us reasonable time to fix the issue before disclosing it.
  • Do not access or modify other customers' data.
  • Test only against accounts and links you own.

Security questionnaire? Send it over.

We're happy to answer security and data-protection reviews for your procurement process.