Compliance & Data Protection

Privacy Policy

Last Updated: August 30, 2026 · Effective across all Carbaat Trace platforms.

1. Commitment to Privacy-First Telemetry

Carbaat Trace operates on a strict zero-cookie, privacy-preserving telemetry model. We process web traffic telemetry solely for the purpose of conversion attribution, network security, and ad fraud detection. We do not sell, rent, or monetize end-user browsing data to third-party data brokers.

2. Information We Collect

When utilizing Carbaat Trace tracking SDKs (e.g. https://analytics.carbaat.com/sdk/v2/analytics.js), we collect:

  • Anonymized IP addresses (truncated and salted via cryptographic hash).
  • Referrer URLs, UTM parameters, and campaign IDs.
  • Device user-agent strings and browser viewport dimensions.
  • Conversion milestones and timestamped DOM interactions required to verify affiliate legitimacy.

3. GDPR, CCPA, and Global Compliance

Our infrastructure complies with EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and PECR guidelines. Data is processed locally across global edge nodes without transferring un-anonymized personal information across borders.

4. Contact Our Data Protection Officer

For privacy inquiries or compliance requests, please email privacy@carbaat.com.