Privacy Policy
Last updated: September 2, 2025
Overview
CameFrom ("we", "us", "our") provides link attribution software for SaaS businesses. This Privacy Policy explains what information we collect, how we use it, and your choices. By using CameFrom, you agree to this policy.
Information we collect
Account information. When you sign up, we collect your email address, password (stored as a secure hash), and optional name.
Website configuration. Your site name, domain, and a unique site identifier used in your tracking script.
Attribution data. When you install our script on your site, we receive pageview events, anonymous visitor identifiers, campaign parameters from URLs, signup events (when you call identify with a user ID and email), and referrer information.
Payment data via Stripe Connect. When you connect your Stripe account, we receive payment event metadata from Stripe (amounts, currency, status, customer email, and identifiers you pass such as client_reference_id). We do not store full credit card numbers — Stripe handles payment processing.
Billing information. Your CameFrom Pro subscription is processed by Stripe. We store your Stripe customer ID, subscription ID, and subscription status.
Technical data. Standard server logs (IP address, browser type, timestamps) for security and reliability.
Cookies and browser storage
Our tracking script uses browser cookies and similar storage to remember an anonymous visitor identifier and the first marketing campaign a visitor arrived from. These are set on your visitors' browsers when they visit a site where your script is installed, not on the CameFrom application itself.
CameFrom's own application uses session cookies to keep you logged in. These are essential for the service to function.
You are responsible for informing your end users about cookies and tracking on your website and obtaining any consents required by applicable law (e.g. GDPR, ePrivacy).
How we use your information
- Provide, operate, and improve the CameFrom service
- Attribute signups and payments to marketing campaigns
- Process your CameFrom Pro subscription and trial
- Connect to your Stripe account for payment attribution
- Send essential service-related communications
- Detect abuse, fraud, and security issues
- Comply with legal obligations
How we share information
We do not sell your personal data. We share information only with:
- Stripe — for subscription billing and Connect payment events
- Neon (database hosting) — to store service data
- Infrastructure providers — to host and deliver the application
- Legal authorities — when required by law or to protect our rights
Data retention
We retain account and attribution data for as long as your account is active. If you delete your account (when available) or request deletion, we will remove or anonymize your data within a reasonable period, except where retention is required by law.
Security
We use industry-standard measures including encrypted connections (HTTPS), hashed passwords, and secure session handling. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Contact us at support@camefrom.app to exercise these rights. EU/EEA users may also lodge a complaint with their local data protection authority.
International transfers
Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place where required by applicable law.
Changes
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Continued use after changes constitutes acceptance.
Contact
Questions about this Privacy Policy: support@camefrom.app