Privacy statement
Last updated: 20 August, 2026
Welcome to Sidetracker. We value the trust you place in us and are committed to protecting and respecting your privacy. This privacy statement explains how we collect, use, share and protect personal data in our tracking and attribution platform.
Who we are
Sidetracker is operated by Jiyu Ninja B.V., a company registered in the Netherlands.
| Legal entity | Jiyu Ninja B.V. |
| Trading name | Sidetracker |
| Registered address | Wilgenlaan 28, 7642 EX Wierden, Netherlands |
| Chamber of Commerce (KvK) | 83679723 |
| VAT number | NL862955919B01 |
| support@sidetracker.io | |
| Website | https://sidetracker.io |
Our role
Sidetracker provides tracking and marketing attribution technology to businesses. In almost all cases we act as a data processor on behalf of our clients, who are the data controllers. We collect and process data as instructed by our clients, for the purposes they have determined, under a data processing agreement.
We act as a data controller only for data about our own clients, such as account details, billing information and support correspondence.
If you are an end user who visited a website using Sidetracker, the business operating that website is the controller of your data. Contact them to exercise your rights. We will assist them in responding to you.
Information we collect
The data we collect through our platform is determined by our clients’ instructions. This may include:
- Pages visited on a client website, and actions taken on those pages such as form submissions
- Technical data such as browser type, device type, approximate location derived from IP address, and referring URL
- Advertising click identifiers present in the landing page URL, including the Google Click Identifier (gclid), used to link a visit back to the advertising campaign that produced it
- Contact or lead details submitted by a visitor to a client website, where the client instructs us to associate those with a tracked visit
We do not collect special categories of personal data as defined in Article 9 GDPR, and our collection methods are designed to minimise privacy risk.
How we store data on your device
Sidetracker does not use third-party tracking cookies and does not build cross-site advertising profiles. Where a click identifier or session reference needs to persist across pages of a client website, it is stored in first-party storage on that website’s own domain, under the client’s control, and is not readable by any other website.
How we use information
We use the collected data to give our clients insight into visitor behaviour, campaign performance and the path from advertising click to sale. This includes attributing offline outcomes, such as a qualified lead or a closed deal recorded in the client’s own CRM, back to the advertising campaign that produced the original click.
Google Ads integration
Clients may connect their own Google Ads account to Sidetracker. This connection is optional and is made by the client.
How the connection is made. The client authorises access through Google’s OAuth 2.0 consent screen using their own Google account. We never ask for, receive or store Google passwords. Access tokens are encrypted at rest, are scoped to that client only, and can be revoked by the client from within Sidetracker at any time.
What we read. With the client’s authorisation we read data from the client’s own Google Ads account only, for reporting purposes. This includes the accounts accessible to the authorising user, campaign names and performance metrics, click data used to resolve a gclid to the campaign that generated it, and the client’s existing conversion actions.
What we write. When a tracked click later becomes a qualified lead or a paying customer in the client’s CRM, and the client has configured this, we upload that conversion back into the client’s own Google Ads account against a conversion action the client has selected. The upload contains the click identifier, the time of the conversion and, where the client provides it, the conversion value. It does not contain names, email addresses or other direct identifiers.
Limits on this access. We access only accounts the owner has explicitly authorised, and only on their behalf. We do not create, edit, pause or manage campaigns, ad groups, ads, keywords, budgets or bids, and we make no changes to account structure. We never combine Google Ads data across clients and never use one client’s data for the benefit of another.
Compliance with Google API Services
Sidetracker’s use and transfer of information received from Google APIs, including the Google Ads API, to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We use data received from Google APIs solely to provide and improve the features described in this statement for the client who authorised the access. We do not transfer that data to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition. We do not use it for advertising purposes, and we do not allow humans to read it except with the client’s explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised.
Sharing of information
We do not sell personal data and we do not share it for the commercial purposes of others. We share data only in these situations:
- With Google, when a client has connected their Google Ads account and instructed us to upload offline conversions into that account. Data goes only into the client’s own account.
- With sub-processors that host and operate our platform, listed below.
- Where legally required, for example in response to a valid legal request from a competent authority.
- In a business transfer, if Jiyu Ninja B.V. is involved in a merger, acquisition or sale of assets, in which case we will notify clients before their data becomes subject to a different privacy statement.
Sub-processors
We use the following sub-processors to deliver the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Application hosting, databases and backups | Amsterdam, Netherlands |
| Google LLC / Google Ireland Limited | Google Ads API, offline conversion import | EU and United States |
| Mailgun Technologies, Inc. (Sinch) | Transactional and support email | European Union |
We maintain a current list of sub-processors and will inform clients of material changes in accordance with their data processing agreement.
International transfers
Our infrastructure is located in the European Union. Some sub-processors, including Google, may process data outside the European Economic Area. Where that happens, transfers are covered by an adequacy decision or by the European Commission’s Standard Contractual Clauses together with appropriate supplementary measures.
Retention
We retain tracking and attribution data for as long as the client instructs, and by default for 26 months from collection. When a client account is closed we delete or return the client’s data within 90 days, except where we are required to retain records to meet a legal obligation. Our own client and billing records are retained for the periods required by Dutch law.
Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or deleted, to restrict or object to processing, and to data portability. You also have the right to lodge a complaint with a supervisory authority, which in the Netherlands is the Autoriteit Persoonsgegevens.
Because we act as a processor for data collected through client websites, please direct these requests to the business whose website you visited. If you contact us instead, we will pass the request on to that client and support them in responding.
For data where we are the controller, such as your Sidetracker account, contact us at support@sidetracker.io.
Data security
We protect personal data with technical and organisational measures appropriate to the risk. These include encryption in transit using TLS, encryption at rest for credentials and access tokens, per-client data isolation, role-based access control, and logging of access to production systems.
Changes to this statement
We may update this statement to reflect changes in our practices or in the legal landscape. We publish any changes on this page and update the date at the top. Where changes are material, we notify clients directly.
Contact
Questions or complaints about privacy can be sent to support@sidetracker.io, or by post to Jiyu Ninja B.V., Wilgenlaan 28, 7642 EX Wierden, Netherlands.