Privacy Policy
Effective September 5, 2026
Tracepoint is operated directly by Fadi Abuhafed. This page covers what the product collects, where it lives, and what happens to the credentials you connect. It does not cover FanBasis, Commas, or Whop — they are not involved in this product in any way.
1. What we collect
- Account data — your name, company, and email, and a password stored only as a salted hash, never in plain text.
- Lead data — the property lists you upload, and the phone numbers, emails, and proof labels the skip tracer returns for them.
- Activity data — calls, texts, and emails logged against a lead so your pipeline has a history, and the opt-out list described below.
2. Where skip-trace results come from
The numbers and emails the skip tracer returns are compiled from publicly available sources — county parcel and assessor records, and public people-search pages. Nothing is pulled from breached data, private databases, or any source that requires a login to view.
3. Where it’s stored
Application data lives in Cloudflare D1; the site itself runs on Vercel. Both are US-based infrastructure, and neither is shared with FanBasis, Commas, or Whop.
4. Your connected credentials
Tracepoint doesn’t run its own Twilio, GoHighLevel, Resend, or Brevo account for you — you bring your own, and how each is handled differs:
- Twilio and GoHighLevel — held in your own browser, and sent along with the one call, text, or sync request that needs them. They are never written to our database.
- Resend or Brevo (email) — because a scheduled or follow-up email needs to go out whether or not you’re at your computer, this key is stored against your organization in our database so sends can go out on your behalf. It is the one credential of the four we hold on our end, and it is only ever used to send mail as you, never read or shared.
5. The opt-out list
When someone unsubscribes from a call, text, or email, their number or address goes on one permanent, cross-channel suppression list. It applies across every channel and every customer — an opt-out recorded through one Tracepoint account blocks future outreach to that same number or address from every other account on the product, and it is not removed.
6. Deactivation and deletion
Accounts can be deactivated, and the data behind them deleted, on request. This is handled directly rather than through a self-service button — ask whoever set up your account, or book a call through the same Calendly link on the site.
7. Changes to this policy
This policy may be updated as the product changes. The effective date at the top reflects the last update.
8. Governing law
This policy is governed by the laws of [Jurisdiction].