This Privacy Policy explains how Everyday Track, a sole proprietorship that provides the Service under the Everyday brand (“Everyday Track,” “Everyday,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when you use:
- the Everyday website at https://everydaytrack.org;
- Everyday account and saved-package features;
- public tracking links generated by Everyday; and
- Everyday’s Model Context Protocol (“MCP”) connector and related integrations with artificial-intelligence assistants.
Together, these are the “Service.” This Privacy Policy does not govern a carrier, retailer, marketplace, email provider, AI-assistant provider, identity provider, or other third party that operates under its own privacy policy.
1. What Everyday does
Everyday is a package-tracking information service. A user can enter a shipment tracking number without creating an account. Everyday analyzes the number’s format to identify a likely carrier, requests available tracking information from carriers or tracking-data providers, and presents the current status and available shipment history in a consistent format. Depending on what the relevant source provides, the result may include carrier identity, shipment status, scan descriptions, scan locations, event dates and times, carrier handoffs, delivery attempts, and an estimated delivery date.
Users may create an account to save tracking numbers, add a personal nickname such as “New headphones,” refresh saved shipments, and remove saved shipments. A user may also create or copy a link containing a tracking number or use the MCP connector so a compatible AI assistant can request tracking information from Everyday.
Everyday is an independent information service. It is not a shipping carrier, postal operator, retailer, seller, marketplace, freight forwarder, customs broker, or insurer, and it does not possess, transport, deliver, redirect, or control packages.
2. Information we collect
The information we collect depends on how you use the Service.
A. Tracking and shipment information
When you request tracking information, we collect and process:
- the tracking number you submit;
- the carrier detected or selected by the Service;
- the tracking result returned by a carrier or tracking-data provider, which may include current status, status details, scan history, scan locations, timestamps, delivery attempts, carrier handoffs, and estimated or actual delivery information;
- a package nickname that you choose to add;
- whether you save, refresh, remove, copy, or share a shipment; and
- technical request information associated with the lookup.
A tracking number can sometimes be linked to a person, household, purchase, sender, recipient, or location when combined with other information. Please treat tracking numbers and tracking links as potentially private.
B. Account and authentication information
If you create or use an account, we collect or receive:
- your email address;
- an account identifier;
- authentication status and session information;
- account creation, confirmation, sign-in, sign-out, and security-event information; and
- if you use Google sign-in, information that Google makes available under the permissions shown during sign-in, such as your Google account identifier, email address, and basic profile information.
Email-and-password authentication is provided through Supabase. Everyday does not intentionally store a readable copy of your password in its shipment records. Authentication credentials, password hashes, confirmation messages, access tokens, and refresh tokens are handled by the authentication provider according to its systems and policies.
C. Information collected automatically
When you access the Service, we and our infrastructure providers may automatically collect:
- Internet Protocol (“IP”) address and related network information;
- browser type, operating system, device type, user-agent string, and language or locale;
- an approximate country or region;
- referring page or website;
- pages visited, navigation events, and dates and times of requests;
- the page path and full page URL;
- a randomly generated analytics session identifier;
- diagnostic, performance, error, fraud-prevention, and security information; and
- cookie, local-storage, and similar-technology information.
The full URL may contain a tracking number when you open a link in the form https://everydaytrack.org/?tracking=.... As a result, URL analytics and ordinary server or security logs may contain that tracking number. Do not publish or send a tracking link to someone unless you want that person to have the number and be able to request its tracking details.
D. MCP connector and AI-assistant information
If you configure or use Everyday through ChatGPT, Claude, or another compatible assistant, the assistant or its provider sends Everyday the tool input needed for the request. This ordinarily includes a tracking number or a search/fetch identifier, along with technical request metadata. Everyday returns tracking information, a link to the Everyday tracking page, and, when supported, a formatted tracking card.
Everyday does not need the rest of your conversation to perform a basic tracking request unless the assistant provider includes additional content in its request. The assistant provider may separately collect your conversation, account information, tool-use records, and returned tracking data under its own terms and privacy policy. Review that provider’s privacy settings before using the connector.
E. Communications
If you contact us, we may collect your name, email address, the content of your message, attachments you choose to send, and information needed to investigate or respond. Do not send passwords or unnecessary sensitive information in a support message.
F. Information we do not currently request
The current Service does not ask users to provide a payment card, bank-account information, or a delivery street address to perform a standard tracking lookup. Tracking data received from a carrier or tracking-data provider may nevertheless reveal route, facility, or approximate destination information.
3. Sources of information
We obtain information:
- directly from you when you enter a tracking number, create an account, name or save a shipment, use a sharing feature, or contact us;
- from carriers and tracking-data providers when we request shipment information;
- from Google if you choose Google sign-in;
- from an AI-assistant provider when you use the Everyday MCP connector through that provider;
- automatically from your browser, device, cookies, local storage, servers, and security or analytics systems; and
- from service providers that help us operate, secure, and troubleshoot the Service.
4. How we use information
We use personal information to:
- accept a tracking number and identify a likely carrier;
- request, retrieve, normalize, and display available tracking results;
- handle carrier handoffs and refresh shipment information;
- create and operate accounts, authenticate users, and keep users signed in;
- save, name, organize, refresh, and remove packages at a user’s direction;
- generate tracking links and respond to MCP connector requests;
- provide customer support and respond to privacy or security requests;
- measure basic use of the Service, diagnose errors, and improve reliability and usability;
- protect users, investigate abuse, enforce our Terms of Service, and prevent fraud or unauthorized access;
- comply with law, lawful process, and enforceable governmental requests; and
- establish, exercise, or defend legal claims.
We will not use a tracking number or saved-package history to build an advertising profile or to target advertisements unless we first update this Privacy Policy and obtain any consent required by law.
5. Legal bases for processing
Where the law requires us to identify a legal basis, we rely on one or more of the following:
- Performance of a contract: to provide a tracking lookup, account, saved-package feature, connector response, or support you request.
- Legitimate interests: to secure, maintain, troubleshoot, and improve the Service; understand basic usage; prevent abuse; and protect our legal rights, where those interests are not overridden by your rights and interests.
- Consent: when you affirmatively choose an optional integration or technology for which consent is required. You may withdraw consent at any time, without affecting processing that occurred before withdrawal.
- Legal obligation: to comply with applicable law, court orders, lawful requests, recordkeeping duties, and regulatory requirements.
We do not make decisions that produce legal or similarly significant effects about you using solely automated processing. Automatic carrier detection only determines which tracking source the Service should query and may be corrected by later carrier or handoff information.
6. When we disclose information
We do not sell personal information or saved-package data, and we do not disclose personal information for cross-context behavioral advertising or targeted advertising. We may disclose information in the following limited circumstances.
A. Carriers and tracking-data providers
We transmit a tracking number and necessary request information to one or more carriers or tracking-data providers so they can identify the shipment and return status information. Those providers may log the request and process it under their own terms or privacy notices.
B. Service providers
We use vendors to host, deliver, secure, authenticate, analyze, maintain, and support the Service. Based on the current implementation, these may include:
- Supabase for authentication and related account infrastructure;
- Google for optional Google sign-in and web-font delivery;
- Lovable-related infrastructure for application hosting, OAuth routing, and basic site analytics; and
- Cloudflare for network delivery, security, and bot-management services.
These providers may process account, device, network, usage, security, or tracking-request information only as permitted by our arrangements with them and applicable law. Their own privacy notices also apply when they act independently, such as when you sign in through Google.
C. AI-assistant providers at your direction
When you invoke Everyday from a third-party assistant, Everyday exchanges the tracking-number input and tracking result with that assistant provider so the requested tool can work. The assistant provider’s handling of that information is governed by its policies and your settings with that provider.
D. Legal, safety, and rights protection
We may disclose information if we reasonably believe disclosure is necessary to comply with applicable law or valid legal process; respond to an emergency; prevent fraud, abuse, or security incidents; protect the safety, rights, or property of users or others; or enforce agreements.
E. Business transactions
If Everyday is involved in a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, information may be reviewed or transferred as part of that transaction, subject to appropriate confidentiality protections and applicable law.
F. With your direction or consent
We may disclose information in another way when you direct us to do so or give valid consent. For example, using the device share sheet may send a tracking number, status summary, and tracking link to an app or person you select.
7. Cookies, local storage, and similar technologies
The current Service uses or may use the following technologies:
| Technology | Purpose | Typical duration or control |
|---|---|---|
session-id cookie |
Assigns a random identifier to a short analytics session so page events can be grouped. | Approximately 30 minutes in the current implementation. |
Supabase authentication local storage, generally using an sb-…-auth-token name |
Stores authentication and refresh information to keep a signed-in user’s session active. | Until sign-out, token expiration or revocation, or removal through browser controls, subject to provider behavior. |
Cloudflare security cookies, such as __cf_bm |
Helps distinguish legitimate requests from automated or abusive traffic and protect the Service. | Often approximately 30 minutes, subject to Cloudflare’s configuration. |
| Google sign-in technologies | Completes an optional Google authentication flow. | Controlled by Google and your Google account or browser settings. |
The Service’s basic analytics currently records a page hit and related technical details when a page loads. Depending on applicable law, analytics cookies or similar technologies may require consent or an easy opt-out. Browser settings can block or remove cookies and local storage, but doing so may prevent sign-in or other features from working correctly.
The Service does not currently respond differently to the legacy browser “Do Not Track” signal because there is no uniform standard for that signal. Where a legally recognized universal opt-out signal applies, we will treat it as required by law. Because Everyday does not currently sell personal information or use it for targeted advertising, there is no sale or targeted-advertising activity to opt out of.
8. Data retention
We retain each category of information only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Service, maintain security and backups, resolve disputes, enforce agreements, and comply with law. Retention depends on the category:
| Category | Retention approach |
|---|---|
| Unsaved tracking requests and results | Processed to return the requested result. Some data may remain temporarily in application caches, analytics, security records, and server logs for reliability, abuse prevention, and troubleshooting. |
| Saved packages and nicknames | Retained while saved to the user’s account. A user can remove an individual saved package through the Service. Copies may remain for a limited period in backups or security records before routine deletion. |
| Account and authentication information | Retained while the account remains active and afterward only as necessary for security, legal compliance, dispute resolution, and deletion or backup cycles. |
| Analytics and diagnostic information | Retained for the period configured in our analytics, hosting, and security systems and reviewed periodically against operational need. |
| Support communications and legal records | Retained as needed to answer the request and maintain appropriate business or legal records. |
Everyday periodically reviews deletion schedules for unsaved lookups, logs, analytics, inactive accounts, and backups. We will not keep personal information indefinitely merely because storage is available.
9. Your choices and privacy rights
A. Service controls
- You can use a standard tracking lookup without creating an account.
- You can remove an individual saved package from your account.
- You can sign out to end the active account session on the Service.
- You can block or clear cookies and local storage through browser settings, although account features may stop working.
- You can stop using the MCP connector or remove it from your assistant’s settings at any time.
B. Privacy requests
Depending on where you live and subject to legal exceptions, you may have the right to:
- know whether we process your personal information and receive information about that processing;
- access or obtain a copy of personal information associated with you;
- correct inaccurate personal information;
- delete personal information;
- receive certain information in a portable format;
- restrict or object to certain processing;
- withdraw consent;
- opt out of a sale, targeted advertising, or certain profiling, if we ever engage in those activities;
- appeal a decision concerning a privacy request; and
- receive equal service and pricing without unlawful discrimination for exercising a privacy right.
To make a request, use any privacy or support contact method published by Everyday Track on the Service. State the right you wish to exercise and provide enough information for us to locate the relevant account or records. To protect users, we may need to verify your identity and authority before completing a request. An authorized agent may submit a request where permitted by law, but we may request proof of authority and direct identity verification from the user.
If you are in the European Economic Area, United Kingdom, or another jurisdiction that provides this right, you may complain to your local data-protection authority. We encourage you to contact us first so we can try to address the concern.
10. Security
We use reasonable administrative, technical, and organizational measures designed to protect information. The Service uses HTTPS/TLS for data in transit, authentication sessions for account access, and infrastructure security controls. Access to saved-package features is designed to be limited to the authenticated account that saved the package.
No storage or transmission system can be guaranteed completely secure. You are responsible for protecting your login credentials, devices, tracking numbers, and tracking links. Promptly report suspected compromise through any security or support contact method published by Everyday Track on the Service.
11. International processing
Everyday and its providers may process information in the United States and other countries where they operate. Those countries may have privacy laws different from the laws where you live. When applicable law requires a transfer mechanism or additional safeguards, we will use an appropriate legal mechanism.
12. Children’s privacy
The Service is a general-audience package-tracking utility and is not directed to children under 13. Children under 13 may not create an Everyday account or submit personal information to us. If we learn that we collected personal information from a child under 13 without legally valid parental authorization, we will take reasonable steps to delete it. A parent or guardian who believes a child provided information may notify Everyday Track through any privacy or support contact method published on the Service.
If you are under the age of legal majority where you live, use the Service only with permission and supervision from a parent or legal guardian.
13. Third-party services and links
The Service displays or interacts with information from third parties and may contain links to other websites. Everyday does not control the privacy, security, accuracy, or availability practices of carriers, merchants, assistant providers, identity providers, or linked websites. Review their policies before providing information to them.
14. Changes to this Privacy Policy
We may update this Privacy Policy as the Service, vendors, or legal requirements change. We will post the revised policy and identify when it becomes effective. If a change materially affects how we use information already collected, we will provide additional notice or obtain consent when required by law.
15. Contact us
The controller or business responsible for this Privacy Policy is:
Everyday Track
Sole proprietorship; operating under the Everyday brand
Website: https://everydaytrack.org
Mailing address: Not applicable at this time
Privacy, security, and legal requests may be submitted through any contact method that Everyday Track publishes on the Service.
