MabrookTrack ← Back to home
Legal

Privacy Policy

Effective date: 1 January 2026  ·  Last updated: 17 September 2026

Contents
  • 1. Introduction
  • 2. Who we are
  • 3. Information we collect
  • 4. How we use information
  • 5. Legal basis
  • 6. Hashing & security
  • 7. Sharing & sub-processors
  • 8. International transfers
  • 9. Data retention
  • 10. Your rights
  • 11. Cookies & tracking
  • 12. Children's data
  • 13. Changes
  • 14. Contact us
  • 15. Country notices

Summary in plain English: MabrookTrack is a server-side conversion tracking service. We process data on behalf of our customers (the brands using our service). We never sell personal data, never use it for advertising other businesses, and never store raw email addresses or phone numbers — only one-way hashed values that ad platforms use to attribute conversions. Customer brands remain the data controllers of their end-customers' data.

1. Introduction

This Privacy Policy explains how VM MEDIA LLC ("we", "us", "our", or "MabrookTrack") collects, uses, processes, and protects personal data in connection with the MabrookTrack service available at mabrooktrack.com and app.mabrooktrack.com (collectively, the "Service").

We are committed to handling personal data in accordance with applicable data protection laws, including the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "UAE PDPL"), the Saudi Arabian Personal Data Protection Law (Royal Decree M/19 of 2021, as amended) (the "KSA PDPL"), and other applicable laws in the Cooperation Council for the Arab States of the Gulf ("GCC").

By using the Service, you acknowledge that you have read and understood this Privacy Policy.

2. Who we are

The data controller of personal data collected directly by us (for example, when you visit our website or apply for access) is:

  • VM MEDIA LLC
  • Registered office: Sharjah Media City, Sharjah, United Arab Emirates
  • Telephone: +971 58 543 9796
  • General contact: hello@mabrooktrack.com
  • Privacy contact: privacy@mabrooktrack.com

When you (as a brand) use the Service to track conversions of your own customers, you are the data controller of your customers' personal data, and we act as your data processor on the instructions you give through your account configuration. The contract between you and us — including our Data Processing Addendum, which every customer signs electronically in the dashboard — governs that processor relationship.

3. Information we collect

3.1 Information you provide directly

  • Account & application data: name, business email, store URL, monthly ad spend range, ad platforms used, e-commerce platform, free-text challenge description, and any other information you submit through forms.
  • Billing data: processed by our payment provider; we receive only the minimum required to fulfil the contract (e.g. last four digits of card, billing country).
  • Communications: emails, messages, and onboarding-call notes.

3.2 Information collected automatically when you visit our website

  • Technical data: IP address, browser type, device, operating system, referrer URL, pages visited, time on page, country (derived from IP at Cloudflare edge).
  • Marketing pixels: on our marketing pages we deploy the TikTok Pixel and the Snapchat Pixel for our own ad measurement. These pixels may set cookies in your browser. See Section 11.

3.3 Information we process on behalf of customers (as Processor)

When a customer integrates MabrookTrack with their e-commerce store and ad accounts, we receive, transform, and forward conversion-related data including:

  • Hashed personal identifiers: email address, phone number, first name, last name — all converted to SHA-256 one-way hashes before any data leaves our edge worker. We do not store raw values in our database.
  • Click identifiers (Click IDs): platform-specific tokens such as ttclid (TikTok), fbclid (Meta), ScCid (Snap), gclid (Google).
  • First-party identifiers: a random visitor/session ID we set in a first-party cookie, plus IP address, user agent, and referrer. We do not use device fingerprinting.
  • Event metadata: event name (e.g. page_view, add_to_cart, purchase), event time, order ID, purchase value, currency.
  • UTM parameters and page URL.

This data is provided to us by the customer's configured systems (their pixel installation, their Salla/Zid/Shopify webhook). The customer is the controller; we process only on documented instructions.

4. How we use information

We use personal data for the following purposes:

  • To provide and operate the Service — including capturing events, deduplicating conversions, stitching cross-device identity, and dispatching server-side conversion signals to advertising platforms configured by the customer.
  • To process applications from prospective customers and respond to enquiries.
  • To improve and secure the Service — debugging, fraud prevention, abuse detection, system health monitoring.
  • To comply with legal obligations — including responding to lawful requests by regulators in the UAE, KSA, and other GCC jurisdictions.
  • For our own marketing — limited to direct marketing of MabrookTrack services to brands and to measuring the effectiveness of our advertising. We will not contact you for marketing if you have opted out.

We do not use personal data for automated decision-making that produces legal or similarly significant effects on data subjects.

5. Legal basis for processing

Depending on the applicable jurisdiction, we rely on one or more of the following bases:

  • Consent — for example, when a website visitor accepts cookies for ad measurement, or when an end-customer of a brand consents (via that brand's privacy notice and cookie banner) to having their data passed to advertising platforms.
  • Performance of a contract — to provide the Service that you have applied for or subscribed to.
  • Legitimate interests — for product improvement, fraud prevention, and security, where these interests are not overridden by data-subject rights.
  • Legal obligation — to comply with applicable laws and regulatory orders.

Where we act as a Processor, the legal basis for processing end-customers' data is determined and documented by our customer (the Controller).

6. Hashing and security measures

We apply the following technical and organisational safeguards:

  • SHA-256 hashing of personally identifiable information at the Cloudflare edge worker — email, phone, first name, last name are hashed before any further processing. Raw values are never written to our database.
  • Transport encryption — TLS 1.2+ for all data in transit between browser, edge worker, our database, and recipient advertising platforms.
  • At-rest encryption — managed PostgreSQL (Supabase) with AES-256 encryption.
  • Tenant isolation — Row-Level Security ("RLS") policies enforce that each customer can access only the data belonging to their own workspace.
  • Least-privilege access controls for our team. Production access is limited to a small number of authorised engineers; we maintain an audit log of all administrative actions.
  • Breach notification — in the event of a personal data breach likely to result in risk to data subjects, we will notify (a) affected customers without undue delay and, where required by law, (b) competent regulators including the UAE Data Office and SDAIA (KSA) within the timeframes prescribed by applicable law (commonly within 72 hours).

7. Data sharing and sub-processors

We share personal data only with the parties listed below, each engaged under a written agreement requiring appropriate confidentiality and data protection commitments.

Sub-processorPurposeData location
Cloudflare, Inc.Edge compute, CDN, DDoS protectionGlobal (with regional routing)
Supabase, Inc.Managed PostgreSQL database, authentication & file storageAWS Asia-Pacific (Mumbai, ap-south-1), India
Vercel, Inc.Hosting of marketing site and dashboardUSA / global edge (server functions in Mumbai)
Resend, Inc.Transactional email deliveryUSA

Additionally, when configured by the customer, we transmit hashed conversion signals to the following advertising platforms, which act as independent controllers with respect to that data:

  • TikTok (Events API)
  • Meta (Conversions API)
  • Snap (Conversions API)
  • Google (Enhanced Conversions / Ads API)

Each platform's use of the data is governed by its own privacy policy. Customers are responsible for ensuring that they have obtained any necessary end-customer consents before configuring the Service to transmit data to these platforms.

The current list of Sub-Processors is published at mabrooktrack.com/subprocessors and forms Annex C of our Data Processing Addendum (DPA). We notify customers by email at least 30 days in advance of any addition or replacement.

We do not sell, rent, or trade personal data to third parties for their independent marketing purposes.

8. International data transfers

Some of our sub-processors operate infrastructure outside the GCC region. Where personal data of UAE or KSA residents is transferred internationally, we rely on one or more of the lawful transfer mechanisms recognised by the UAE PDPL and KSA PDPL, including (as applicable):

  • An adequacy determination by the competent regulator;
  • The data subject's explicit consent to the transfer, after being informed of the risks;
  • Standard contractual clauses or equivalent safeguards in place with the sub-processor;
  • The transfer being necessary for the performance of the contract with the data subject.

Customer data is stored in India (AWS Mumbai) via Supabase; a deployment inside the GCC is not part of the standard service. For customers in the Kingdom of Saudi Arabia our DPA incorporates the SDAIA Standard Contractual Clauses (controller-to-processor), and a transfer risk assessment is available on request. Brands with a strict in-Kingdom residency requirement should raise it before onboarding.

9. Data retention

Data categoryRetention period
Account & billing dataDuration of the contract + 7 years (for tax and audit purposes)
Raw IP addresses on event records30 days, then removed automatically (a salted hash remains)
Store webhook logs (identifiers redacted at receipt)90 days
Event, click and conversion records (attribution & reporting)Duration of the contract, up to 25 months
Hashed identity linksDuration of the workspace, deleted within 30 days of termination
Executed legal documents (DPA) and acceptance recordsDuration of the contract + 7 years (evidence)
Marketing-application form submissions24 months from last contact
System and audit logs12 months

Upon termination of a customer contract, we will delete or anonymise all data we hold as Processor within 30 days, unless a longer retention period is required by applicable law.

10. Your rights as a data subject

Subject to applicable law, you have the following rights:

  • Right of access — to know whether we hold personal data about you and to obtain a copy.
  • Right of rectification — to correct inaccurate or incomplete data.
  • Right of erasure — to request deletion of your personal data, subject to legal retention requirements.
  • Right to restrict processing — to limit how we use your data in specified circumstances.
  • Right to data portability — to receive a machine-readable copy of data you have provided.
  • Right to object — to processing based on legitimate interests, including direct marketing.
  • Right to withdraw consent — at any time, without affecting the lawfulness of prior processing.
  • Right to lodge a complaint — with the competent supervisory authority (see Section 15).

To exercise any of these rights, contact privacy@mabrooktrack.com. We will respond within the timeframe required by applicable law (commonly 30 days; extendable in complex cases as permitted by law).

If you are an end-customer of a brand that uses MabrookTrack to track conversions, please contact that brand directly to exercise your rights; we will assist them as their Processor.

11. Cookies and similar technologies

Our marketing website (mabrooktrack.com) uses a small number of cookies and similar technologies:

Cookie / tagPurposeSet by
TikTok PixelMeasurement of our own TikTok ad campaignsTikTok
Snapchat PixelMeasurement of our own Snapchat ad campaignsSnap
Functional / preferencesRemember session, language preferenceMabrookTrack

Strictly necessary cookies are used to operate the site and do not require consent. Where required by applicable law, marketing pixels are loaded only after consent is obtained through our cookie banner. You can withdraw consent at any time by adjusting cookie preferences in your browser.

12. Children's data

The Service is intended for use by business customers and is not directed to children under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. For material changes, we will provide reasonable advance notice by email to account holders and / or a prominent notice on the Service. Continued use of the Service after a change constitutes acceptance of the updated policy.

14. Contact us

For any question about this Privacy Policy, to exercise your rights, or to submit a complaint:

  • Privacy contact: privacy@mabrooktrack.com
  • General contact: hello@mabrooktrack.com
  • Telephone: +971 58 543 9796
  • Postal address: VM MEDIA LLC, Sharjah Media City, Sharjah, United Arab Emirates

15. Country-specific notices

15.1 United Arab Emirates (UAE PDPL)

You have the rights set out in Articles 13–18 of the UAE PDPL, exercisable as described above. The competent supervisory authority is the UAE Data Office. If you believe your rights have been infringed, you may file a complaint with the UAE Data Office at u.ae. Free-zone-specific regimes may apply additional protections: residents in the Dubai International Financial Centre (DIFC) have rights under the DIFC Data Protection Law No. 5 of 2020 enforced by the DIFC Commissioner of Data Protection.

15.2 Kingdom of Saudi Arabia (KSA PDPL)

You have the rights provided under Articles 4–8 of the KSA PDPL (Royal Decree M/19 of 2021, as amended). The competent supervisory authority is the Saudi Data and Artificial Intelligence Authority (SDAIA). You may file complaints at sdaia.gov.sa. Sensitive personal data of KSA residents is processed in accordance with the additional protections required by KSA law, and we obtain explicit consent before processing such data where required.

15.3 Other GCC jurisdictions

Residents of Bahrain, Qatar, Oman, and Kuwait may exercise rights under their respective national data protection laws by contacting privacy@mabrooktrack.com. Where applicable, we cooperate with the competent supervisory authority in each jurisdiction.

Authoritative language: This Privacy Policy is drafted in English. Any translated version is provided for convenience only. In the event of a conflict, the English version prevails to the maximum extent permitted by applicable law.

© 2025 MabrookTrack · A brand of VM MEDIA LLC · All rights reserved
Home Privacy Policy Terms of Service DPA Sub-processors Contact