DATRACE
Datrace Privacy Policy
How Datrace collects, uses, retains, and protects information when you use Datrace Platform and Datrace MCP.
Last updated: September 23, 2026
1. Scope
This Datrace Privacy Policy (the “Notice”) applies when you visit Datrace Platform, use its console, authorize an OAuth client, create a manual token, call Datrace MCP tools, or contact Datrace about the Platform Services. In this Policy, “Platform Services” means the Datrace website, console, MCP and related services; “Agreement” means the Datrace Terms of Service.
2. Information we collect
Depending on how you use the Platform Services, Datrace may collect the following categories of information:
- Account and identity information, such as your Datrace account identifier, email address, display name, locale, entitlement status, and session or authentication status.
- OAuth and connection information, such as interaction identifiers, client identifiers and names, redirect hosts, requested resources and scopes, authorization status and time, token metadata, and revocation status. Datrace does not display OAuth access or refresh tokens to you.
- MCP Usage Data, such as inferred or derived intent, MCP tool name, timestamps, client type, Amazon marketplace, sanitized request parameters including ASINs, keywords, and time ranges, response status, performance information, errors, Credits consumption, and request or response data after credentials and direct identifiers have been removed.
- Technical and security information, such as IP address, browser and device information, necessary cookies, request logs, fraud signals, and diagnostic events.
- Support information that you choose to provide when requesting help or reporting a problem.
3. Information we do not use for AI training
Datrace does not use your MCP prompts, conversations, MCP Usage Data, or Platform outputs to train AI models. We do not intentionally retain complete prompts or full conversation content from your AI client. Datrace may process the minimum request and response data needed to perform a requested tool call, protect the service, investigate an error, and provide support.
4. How we use information
Datrace uses the information described above to:
- authenticate your account and complete OAuth authorization;
- provide MCP tools, return requested outputs, and manage connections and tokens;
- measure Credits, enforce plan and connection limits, and display usage;
- secure the Platform Services, prevent abuse, investigate incidents, and troubleshoot errors;
- provide support and communicate service or policy changes;
- perform internal product analytics and improve tool reliability, latency, data quality, and user experience without training AI models; and
- comply with legal obligations and enforce the Agreement.
5. Legal bases
Where applicable law requires a legal basis, Datrace processes information as necessary to perform these Terms, based on your consent for OAuth authorization and optional activities, to comply with law, and for legitimate interests such as securing, operating, supporting, and improving the Platform Services. You may withdraw consent where processing relies on consent, but withdrawal does not affect earlier lawful processing and may prevent the related feature from working.
6. How we disclose information
Datrace does not sell Platform personal information or disclose it for third-party advertising or third-party AI model training. Datrace may disclose information only as reasonably necessary:
- to hosting, cloud infrastructure, database, logging, security, communications, and support providers that process information for Datrace under appropriate obligations;
- to the AI client or other application you authorize, to complete the connection and deliver requested Platform outputs;
- to comply with law, legal process, or a valid government request, or to protect rights, safety, and security;
- in connection with a merger, financing, acquisition, reorganization, or transfer of assets, subject to appropriate protections; or
- with your direction or consent.
7. Retention
Datrace retains account-linked or otherwise linkable sanitized MCP Usage Data for no longer than 180 days after collection, unless a longer period is required by law or is reasonably necessary to resolve a security, fraud, billing, or legal matter. At the end of the applicable period, the data is deleted or transformed into aggregated, de-identified information that is not reasonably linkable to an account or individual.
Fully aggregated and de-identified statistics may be retained for longer to understand service adoption, reliability, and capacity. Account and authorization records are retained while your account or connection is active and for a reasonable period afterward for security, audit, dispute, and legal purposes. Credentials and security secrets are retained only for the operational period required to provide and protect the relevant feature.
8. International transfers and security
Datrace and its service providers may process information in countries other than your country of residence. Where required, Datrace uses appropriate safeguards for international transfers.
Datrace uses reasonable administrative, technical, and organizational safeguards designed to protect Platform information. No method of transmission or storage is completely secure, so you should also protect your account, clients, and tokens and promptly report suspected unauthorized access.
9. Your choices and rights
You can decline an OAuth request, revoke a connection, delete a manual token, and stop using the Platform Services. Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal information, or to withdraw consent. Requests may be sent to support@datrace.com. Datrace may verify your identity before completing a request and may retain information where permitted or required by law.
10. Children
The Services are intended for business users aged 18 or older. They are not directed to children, and Datrace does not knowingly collect personal information from children in violation of applicable law.
11. Changes, language, and contact
Datrace may update this Notice to reflect changes to the Platform Services, processing practices, or law. The updated version will identify its effective date, and material changes will be notified where required.
The English version is the controlling version. Translations are provided for reference. Questions or privacy requests may be sent to support@datrace.com, marked “Platform Privacy”.
12. Google sign-in
If you choose Google sign-in, Datrace processes the identity information that Google shares with your authorization, such as your account identifier, email address and display name, to authenticate you and manage your Datrace account. The Google consent screen identifies the permissions requested.
Google sign-in information is handled under the use, disclosure, retention and security provisions of this Privacy Policy. You can remove Datrace access in your Google Account and request deletion of your Datrace account information by emailing support@datrace.com. Removing Google access does not itself delete previously stored account information.
13. Collection sources, cookies and communications
We collect information when you register, sign in, authorize a connection, use a tool or contact support; from the identity provider or client you authorize; and automatically from requests and interactions with the Services. Personal information includes identifiers and technical information that can be linked to you, even if it does not include your name.
Necessary cookies and similar storage support sign-in sessions, security and preferences such as language. You can control cookies in your browser; blocking necessary cookies may prevent sign-in or other features from working. Where optional analytics require consent, you may refuse or withdraw that consent. We do not use Platform personal information for third-party advertising.
We send operational messages concerning your account, security, support and service changes. You may opt out of promotional communications by emailing support@datrace.com or following an unsubscribe option in the message. Essential service notices may still be sent.
14. Customer data, service providers and external websites
Where you lawfully provide customer data through an available feature, we process it to provide the requested functionality under the Terms. We do not sell customer data or use it for marketing. Anonymous aggregate statistics must not identify you or your customers. You are responsible for the lawful collection and disclosure of data you submit.
Providers receive only information reasonably necessary to perform their contracted functions and must handle it under applicable confidentiality, security and data-protection obligations. An affiliated entity receiving information for those functions is subject to the same purpose limitations. Corporate transfers remain subject to the protections described in this Policy.
Third-party websites, Google and your chosen AI clients apply their own privacy policies to information they collect. A link or integration does not establish our control over their practices. Revoking a connection does not automatically erase information already received by a third party.
15. EEA, United Kingdom and Switzerland
If applicable data-protection law covers you, you may request access, correction, erasure, restriction or portability, object to processing based on legitimate interests, and withdraw consent without affecting prior lawful processing. You may complain to your competent data-protection authority. Send requests to support@datrace.com, marked “GDPR Data”.
For account and service administration, Datrace determines the purposes of processing. Where we process customer data on your instructions, the applicable data-processing arrangements govern our responsibilities. The legal bases are described above. International transfers will use a legally applicable mechanism, such as an adequacy decision or appropriate contractual safeguards, where required; use of the service alone does not replace those safeguards.
16. California privacy rights
Where California privacy law applies, you may request the categories and specific pieces of personal information collected about you, their sources, purposes and recipients; request deletion or correction; and exercise applicable rights to opt out of sale or sharing and limit use of sensitive personal information. We do not sell Platform personal information or share it for cross-context behavioral advertising. Exercising your rights will not result in unlawful discrimination.
Email support@datrace.com to submit a request, or use an authorized agent where permitted. We verify identity and authority using information reasonably necessary to match our records. Do not send passwords, complete payment-card numbers or government identification numbers. If a request is incomplete or cannot be verified, we will explain the issue; we may withhold information where disclosure would create a security risk.
For requests to know or delete, we acknowledge receipt within 10 business days and generally respond within 45 calendar days, with any lawful extension and its reason communicated to you. Applicable exceptions, including legal obligations and security needs, may limit deletion or disclosure.
17. Requests, deletion and contact address
You may request account closure and deletion by emailing support@datrace.com. We may ask you to confirm the request from your account email. Revocation of Google access and deletion of a Datrace account are separate actions. Records needed for legal obligations, security or disputes may be retained only for the relevant purpose and period; backup deletion follows applicable retention cycles. De-identified aggregate information may remain where it cannot reasonably be linked back to you.
We do not knowingly collect personal information from children under 13. A parent or guardian who believes a child has provided information should contact us so that we can investigate and delete it as appropriate. Do not send the child’s password.
Postal privacy requests: Datrace, Attn: Privacy Policy Officer, UNIT 616, 6/F KAM TEEM IND BLDG 135 CONNAUGHT RD WEST SAI WAN HK. Email: support@datrace.com.