GCT
GetClientTracker

Privacy Policy

Last updated:

Our Privacy Commitment

GetClientTracker is built on a privacy-first architecture. We believe your client data belongs to you — not us, not advertisers, not third parties. This policy explains how we handle information when you use our application.

Data We Collect

Short answer: We collect zero personal data on our servers.

GetClientTracker runs entirely in your browser. All client records, financial data (retainer values), notes, categories, and settings are stored exclusively in your browser's localStorage. Nothing is transmitted to our servers, cloud databases, or analytics platforms.

What stays in your browser:

  • Client records (names, emails, phones, categories, statuses, notes)
  • Monthly retainer values and currency preferences
  • Application settings (theme, currency, Pro status)
  • Local backup/restore files (only when you explicitly export/import)

Data We Do NOT Collect

  • No IP address logging
  • No user accounts or authentication
  • No analytics, tracking pixels, or fingerprinting
  • No cookies (except essential session storage for app functionality)
  • No third-party scripts that could access your data
  • No server-side databases storing your client information

How Your Data Is Used

Your data is used solely to provide the GetClientTracker functionality within your browser:

  • Displaying, searching, and filtering your client list
  • Calculating retainer totals and statistics
  • Generating PDF reports and CSV exports locally
  • Enabling offline access via Service Worker caching

Data Storage & Security

LocalStorage Encryption: All data is stored in your browser's localStorage API. While localStorage is not encrypted by the browser itself, it is scoped to your origin (https://getclienttracker.com) and inaccessible to other websites.

No Network Transmission: The application makes zero network requests to send your client data anywhere. The only network requests are for loading the application assets (HTML, CSS, JS, fonts) and checking for Pro license validation (which only sends a license key, never client data).

Offline-First: Once loaded, the app works completely offline. Your data never leaves your device.

Backup Control: You have full control over backups. Export JSON/CSV/PDF anytime. Import restores data locally. We never see your backup files.

Pro License Validation

If you upgrade to Pro, a license key is stored in localStorage. On app load, we make a single HTTPS request to our license server to validate the key. This request includes only the license key — no client records, no personal information, no usage analytics.

Third-Party Services

GetClientTracker does not integrate with any third-party analytics, advertising, or tracking services. The only external requests are:

  • Google Fonts (Inter, JetBrains Mono) — loaded via preconnect for performance, no user data sent
  • License validation endpoint (Pro users only) — license key only

Your Rights & Control

Access: All your data is visible in the app interface at all times.

Export: Download your complete dataset as JSON, CSV, or PDF anytime via the footer backup buttons or dashboard export buttons.

Delete: Clear all data instantly via browser dev tools (Application → LocalStorage → Clear) or by uninstalling the PWA.

Portability: Exported JSON/CSV files are standard formats compatible with Excel, Google Sheets, and other tools.

Children's Privacy

GetClientTracker is not directed at children under 13. We do not knowingly collect any information from children. Since we collect no personal data on our servers, there is no risk of children's data being stored by us.

Changes to This Policy

We may update this policy to reflect changes in the application or legal requirements. Updates will be posted on this page with a revised "Last updated" date. Continued use of the application after changes constitutes acceptance.

Contact Us

Questions about this Privacy Policy? Contact us at:

Contact Us Page
Email: privacy@getclienttracker.com

Compliance Notes

GDPR: As a data processor that never receives personal data, GetClientTracker operates outside typical GDPR controller/processor relationships. You are the sole controller of your data.

CCPA: We do not sell personal information. We do not collect personal information on our servers.

HIPAA: GetClientTracker can be used as part of a HIPAA-compliant workflow because no PHI leaves your device. However, we do not sign BAAs as we never access your data.

SOC 2: Not applicable — we have no systems that process customer data.