Updated August 24, 2026
Privacy Policy
RemoveMyTracks is a privacy service. We collect only what we need to send deletion and opt-out requests on your behalf, prove those requests happened, and run your account. This page describes that, in plain language. It is not legal advice.
Operator: RemoveMyTracks. Contact: privacy@removemytracks.com.
What we collect
- Account email and password (password is stored by our auth provider, hashed, not readable by us).
- Identity you give us: legal name, aliases, date of birth, phone, current and past addresses, past emails, family and employer names.
- A photo of your driver's license or state ID, plus the fields we extract from it.
- Your signature and the Limited Power of Attorney PDF generated from it.
- The companies we contact for you, the emails we send, and the replies we receive.
- Optional: a breach-exposure report built from Have I Been Pwned for the emails you list. That is a published-breach lookup, not dark-web monitoring.
- Billing identifiers if you subscribe (Stripe customer and subscription IDs). We do not store full card numbers.
Why we collect it
To act as your authorized agent: draft and send privacy requests, attach proof of authority, match vendor replies to the right request, show you what happened, and (if you pay) bill the correct plan. We do not sell your personal information. We do not use it for advertising.
Who sees it
- Vendors we write to — the minimum identifiers needed to find your records. Data brokers receive an alias reply address, not your real email. Consumer companies receive your real email because that is how they look you up.
- Supabase — database, login, and private file storage.
- Vercel — hosts the app.
- Postmark — sends and receives the request emails.
- Anthropic — reads a license photo to fill the form; researches unknown companies; classifies some catalog work. License images are sent for extraction only and are not used to train our product.
- Have I Been Pwned — if you run a breach scan, we look up your emails in their breach corpus.
- Stripe — if billing is on, they process payment.
- NeverBounce — used on catalog emails (vendor inboxes), not on your personal inbox, when we verify that a privacy mailbox exists.
How long we keep it
For as long as your account is open, because the service is ongoing removal and proof. If you delete your account, we delete your profile, company list, email log, license photo, and signature files from our systems. Backups fall off on the host's normal cycle. Emails already sitting in a vendor's inbox cannot be unsent.
Your rights
You can view and edit what we have in Profile and Settings. You can export by asking privacy@removemytracks.com. You can delete your RemoveMyTracks account from Profile — that is a one-click deletion of our copy of your data. Depending on where you live, you may also have rights under CCPA/CPRA, other US state laws, or GDPR. Email us and we will honor them.
Children
This service is for adults. We do not knowingly collect information from children under 16.
Security
Data is stored with row-level access so one customer cannot read another's records. License photos and signatures live in private buckets. We still cannot promise perfect security; no one can. If we learn of a breach that affects you, we will notify you.
Changes
If this policy changes in a way that matters, we will update the date above and, for material changes, email the address on your account.