Legal

Terms of service

These terms are the agreement for using CLItrail. They cover organisations and accounts, plans and billing, automatic renewal, cancellation and refunds, the limits that apply, the Acceptable Use Policy, what you are responsible for when you measure your visitors and installers, and how to leave with your data.

Operator
Vulture Labs, Inc.
Status
In effect
Effective
24 September 2026
Version
2026-09-24
Applies to
The hosted CLItrail service at clitrail.com
On this page

Summary

Plans
Free, Standard at $99 a month and Enterprise at $499 a month. Paid plans are billed monthly in advance through Stripe and renew every month until an owner cancels in Manage billing. The plan then runs to the end of the month already paid.
Your data
Your organisation controls its visitors’ and installers’ data. We process it only on your instructions, under the Data Processing Addendum.
Accuracy
Attribution is evidence, not proof. Not every install is matched, and Free matches none.
Leaving
Export what you need before a paid plan ends. For 30 days after it ends, an owner can still ask us for the install-event export, at no charge (section 13.6). Deleting a website, an organisation or your account removes its data.

The agreement

1.1 Who we are

CLItrail is a product of Vulture Labs, Inc., a Delaware corporation, of San Francisco, California, USA (“Vulture Labs”, “we”, “us”, “our”). CLItrail is developed by Pilot Protocol, a project that Vulture Labs also operates. You can reach us at founders@pilotprotocol.network.

1.2 The service

These terms apply to the hosted CLItrail service. The service is made up of:

  • the dashboard and its API;
  • the website tag (browser.js);
  • the installer hook and the handoff command;
  • the collection endpoints;
  • logs and log streams;
  • the delivery of events to the destinations you set up;
  • the documentation and the clitrail-setup skill.

1.3 Who “you” means

You use CLItrail through an organisation (section 3). You accept these terms for an organisation when you do any of the following:

  • sign in to CLItrail;
  • create or join an organisation;
  • subscribe to a paid plan.

By doing so you confirm that you are authorised to bind that organisation. “You” means that organisation. Everyone who uses CLItrail for it must follow these terms, and the organisation is responsible for what they do.

If you use CLItrail for a client, for example as an agency, you confirm that the client has authorised you to do so. You must make sure the client meets sections 7 and 8 as if they applied to it directly.

1.4 Business use only

CLItrail is a service for businesses and professionals who publish websites and software. You may use it only for the purposes of your trade, business, craft or profession, and not as a consumer.

1.5 Eligibility

You must be old enough to enter into a binding contract where you live, and legally able to enter into this agreement. You may not use CLItrail if the laws that apply to you or to us bar you from doing so, including the sanctions rules in section 21.7.

1.6 What makes up the agreement

The agreement consists of:

  • these terms, including the Acceptable Use Policy in section 8;
  • the Data Processing Addendum at clitrail.com/dpa (the “DPA”). It applies whenever we process personal data for you, and it needs no separate signature.

The privacy policy describes what the service collects, stores and sends, and how we handle the account data of the people who use CLItrail. The documentation describes how each feature works. For personal data we process for you, the DPA prevails over these terms if the two conflict.

The service

  • Changes. We keep developing CLItrail. Features, interfaces, supported platforms and limits change, and features can be removed. If we remove or materially reduce something a paid plan includes, we give notice under section 19 at least 30 days before the change applies to your organisation, so you can cancel first.
  • No service levels. We make no commitment on availability, uptime, response time or delivery time, and we offer no service credits. The service also depends on providers we do not control, such as our hosting provider and the platforms you send events to.
  • Supported environments. CLItrail supports the browsers, operating systems and install methods listed on the support page and in the documentation. Other environments may work, but we do not support them.
  • Support. Signed-in users can write to us from the support page, and anyone can email founders@pilotprotocol.network. We answer as soon as we can, but we do not guarantee a response time.
  • The Free plan. We may change the Free plan’s features or limits, or stop offering it. We give at least 30 days’ notice under section 19 before doing so.

Accounts and organisations

  • Signing in. You sign in through Firebase Authentication, Google’s sign-in service, using one of the sign-in methods the dashboard offers.
    • Your CLItrail account is tied to the account you sign in with. Use one that you control and keep it secure, for example with Google’s 2-Step Verification.
    • Each CLItrail account is for one person. Do not share a sign-in.
    • You are responsible for activity under your sign-in.
  • Organisations. Websites, destinations, install paths, log streams, the plan and billing belong to an organisation, not to a person.
    • Your first sign-in creates a personal organisation on the Free plan, with you as its owner.
    • You can own up to 5 organisations and belong to up to 20.
    • Each organisation has its own plan.
  • Roles. Each role decides what a member may do:
    • Owners manage billing, delete the organisation and manage everyone.
    • Admins manage members, websites, destinations, install paths and log streams.
    • Members use websites, and create or edit destinations and install paths.
    • Viewers read dashboards.

    Only an owner can grant or remove the owner role. An organisation always keeps at least one owner.

  • Invitations. Admins and owners invite people with a single-use link. The link is valid for 7 days and works only for a signed-in account whose verified email address matches the invitation. Owners and admins are responsible for who they invite and for removing people who should no longer have access.
  • Your accounts elsewhere. Only register websites that your organisation controls or is authorised to use. The same applies to the advertising, analytics and storage accounts you set up.
  • If an account is compromised:
    1. Sign out every other session in Account and security.
    2. Secure the account you sign in with.
    3. Revoke any destination credential you are unsure of at the platform that issued it.
    4. Email founders@pilotprotocol.network promptly.

Plans, billing and cancellation

4.1 Plans

PlanPriceWhat it includes
Free$0The website tag and installer hook, install-page visits against reported installs, browser, operating-system and device distributions, and logs. No attribution of any kind and no destinations: installs are counted, never matched.
Standard$99 per monthEverything in Free, plus attribution, channels, campaigns, pages and referrers, journeys, Safari and External reasons, reconstruction, every destination (GA4, Google Ads, Meta, TikTok, X Ads and webhooks), and CSV export with attribution, for 1 install path.
Enterprise$499 per monthEverything in Standard for up to 10 install paths, plus log streams to your own storage and higher limits.

Section 5 lists the limits of each plan.

4.2 Subscriptions and automatic renewal

  • What a subscription is. Standard and Enterprise are monthly subscriptions in US dollars, sold through Stripe, our payment processor. Only an organisation’s owners can subscribe, switch plans or cancel.
  • What you agree to when you subscribe. An owner subscribes in Stripe Checkout. The organisation then agrees to pay the plan’s monthly price in advance, plus any tax under section 4.3: first on the day it subscribes, then each month on the same date.
  • Automatic renewal. The subscription renews automatically every month, and Stripe charges the payment method on file, until an owner cancels (section 4.6). There is no minimum term: you commit to one month at a time.
  • Payment details. You enter card details on Stripe’s pages. They go to Stripe and never to us. Owners update the card and download invoices in Stripe’s billing portal, which opens from Manage billing in the dashboard.
  • When a paid plan starts. A paid plan starts when Stripe confirms that the subscription is active, usually within seconds of payment.

4.3 Taxes

Prices are in US dollars and do not include taxes. You are responsible for any sales tax, VAT, GST or similar tax that applies to your purchase. The exception is tax that we are required by law to collect from you.

4.4 Price and plan changes

We may raise the price of a paid plan or reduce its limits. We give you at least 30 days’ notice under section 19 before the change applies to your subscription. It applies from your first renewal after that notice period. If you do not agree, cancel before that renewal.

4.5 Switching plans

  • Owners switch between Standard and Enterprise in the billing portal. A switch in either direction takes effect immediately.
  • Moving from Enterprise to Standard applies the downgrade rules in section 4.9 at once.
  • To move from Free to a paid plan, an owner opens Billing in the dashboard and chooses Standard or Enterprise.

4.6 Cancellation

  • Cancel online, at any time. An owner opens Billing → Manage billing in the dashboard and cancels the subscription in Stripe’s billing portal. You do not need to contact us, and there is no cancellation fee.
  • When it takes effect. A cancellation takes effect at the end of the month already paid. The plan stays active until then, and no further payment is taken. The organisation then moves to Free under the downgrade rules in section 4.9.
  • What cancelling keeps. Cancelling deletes no websites, install events, destinations, install paths, log streams or members. They stay, under your retention settings, until you delete them (section 13.4).
  • What moving to Free deletes. When the organisation moves to Free:
    • log records older than 7 days are deleted at the next clean-up, which runs about once an hour;
    • the signals kept for reconstruction are deleted.
  • What Free does not include. On Free, attribution and the install-event export are not available, and log streams stop. Export what you need before the paid month ends (section 13.3), or ask us within 30 days afterwards (section 13.6).
  • Deleting needs an ended subscription. An organisation, or an account whose organisations would be deleted with it, can be deleted only once its subscription has ended. After a cancellation, that is at the end of the month already paid. A subscription that has not ended, including one whose renewal payment has failed, keeps blocking deletion.

4.7 Refunds and billing disputes

  • No refunds for part of a month. Each payment covers the month ahead. We do not refund a partly used month when you cancel, move to a smaller plan or delete the organisation. The exceptions are:
    • where the law requires a refund;
    • where section 13.2 provides one.
  • Charged in error? Email founders@pilotprotocol.network with the organisation and the invoice number. If we charged you in error, we refund the amount through Stripe to the original payment method.
  • Contact us before disputing a charge. Please write to us before you dispute a charge with your bank or card issuer. A dispute does not cancel the subscription. To stop future charges, cancel as section 4.6 describes.

4.8 Failed payments

A paid plan is active while its Stripe subscription is active. If a renewal payment fails, the subscription stops being active. The organisation is then treated as Free, under the downgrade rules in section 4.9, until a payment succeeds and the subscription is active again.

Stripe may retry the payment, and an owner can update the card in the billing portal. While the organisation is treated as Free, section 4.9 applies: websites, install events, destinations, install paths, log streams and members are kept, but log records older than 7 days and the signals kept for reconstruction are deleted.

4.9 Downgrades

Moving to a smaller plan deletes no websites, install events, destinations, install paths, log streams or members. This includes the move to Free after a cancellation or a failed payment. The following rules apply:

  • Install paths, destinations and log streams over the new plan’s limits are paused until an owner chooses which to keep. Paused install paths still count installs, but without attribution or delivery. Paused destinations and log streams send nothing.
  • Websites over the limit keep collecting, but no new website can be added.
  • Members stay, but no new invitations can be sent until the organisation is under its member limit.
  • Log retention is reduced to the plan’s maximum, and log records older than that are deleted at the next clean-up, which runs about once an hour. On Free the maximum is 7 days.
  • On Free, attribution is not shown or exported, and the signals kept for reconstruction are deleted.

4.10 No backfill

Attribution starts with installs reported after an upgrade. Installs reported while on Free, or on a paused install path, are never matched or sent to a destination later.

4.11 No overage charges

A plan’s price is the whole price. We never charge for usage above a plan’s monthly quota (section 5).

Limits and fair use

Fair use of CLItrail means staying within these limits. The service enforces them and answers with a stable error code when a limit is reached. The dashboard’s Usage card shows where your organisation stands, and the limits reference lists every limit with its error code.

Plan limits, per organisationFreeStandardEnterprise
Install paths1110
Websites1325
Domains per website, primary included51025
Members, pending invitations included1320
Destinations per websiteNone1020
Log streamsNoneNone10
Log retention, maximum7 days30 days90 days
Tracked events per month10,0001,000,00010,000,000
  • Monthly quota. Tracked events are install-page visits plus hook reports in a calendar month (UTC). Each hook report counts: install started, install completed and first run, each once per installation. One install that reports all three uses three tracked events.
    • On Free, once the quota is reached, further visits and hook reports that month are counted but not stored or matched. The tag and the hook still get their normal answers, and the dashboard shows when the quota resets.
    • Standard and Enterprise are never cut off for reaching the quota. At 80 % and 100 % of it the dashboard tells you, and data keeps flowing at no extra charge.
  • Service limits. These limits protect every customer and apply on all plans:
    • collection: requests of at most 16 KB; 240 requests a minute per client; 6,000 visits and 1,200 install reports a minute per website; 30 install reports a minute and 500 a day per website and client;
    • dashboard and API: 30 changes a minute per client; 600 reads a minute per session;
    • invitations: 20 a day per organisation;
    • support: 5 requests a day per user and 20 per organisation; messages of up to 4,000 characters; diagnostics of up to 16 KB;
    • billing: 10 Checkout or billing-portal sessions an hour per organisation;
    • logs: pages of 200 records; 10 exports an hour per organisation, each of at most 100,000 records or 25 MB; 10 log-stream tests an hour. A log stream that cannot deliver keeps a backlog of at most 1,000,000 records or 7 days.
  • Changes to service limits. We may adjust service limits to protect the service. Changes to a paid plan’s limits follow section 4.4.
  • No workarounds. Do not try to get around a limit. For example, do not split one website or organisation into several, share sign-ins, or create extra organisations to add members.

Your data and our roles

6.1 Your data

“Customer data” means:

  • the data the tag, the hook and the handoff command send for your websites and install paths;
  • what the service derives from that data (matches, journeys and deliveries);
  • your settings;
  • your organisation’s logs.

You keep all rights in customer data. You allow us to host, copy, process and send it only as needed to provide the service to you under these terms and the DPA.

6.2 Roles

  • Your visitors and installers. Customer data includes personal data about the visitors to your websites and the people who install your software. For that data, you are the controller, or you act for the controller (for example as an agency for a client). We are your processor and service provider. The DPA sets out our obligations.
  • Deliveries to advertising and analytics platforms. When a destination you set up sends data to an advertising or analytics platform, that is your disclosure to the platform, made on your instruction; the platform receives it as your recipient under its own terms (section 9). You are responsible for any notice, opt-out of sale or sharing, or consent that disclosure requires (section 7).
  • People who use CLItrail. For the data of the people who use CLItrail through your organisation (sign-in details, memberships, billing and support), we are the controller, as the privacy policy explains.

6.3 What we do as your processor

This is a summary; the DPA governs.

  • We process customer data only on your documented instructions. Your instructions are these terms and the settings you choose in the service: tracking providers, destinations, reconstruction, attribution policy, retention and log streams. We also process customer data as needed to keep the service secure and to comply with the law.
  • We never use customer data for our own purposes, never sell it and never combine it across customers.
  • We keep it confidential and limit access to people who need it to run the service.
  • We protect it with the measures described in the privacy policy, including a separate encrypted store for every credential you give us.
  • We use only the subprocessors listed at clitrail.com/subprocessors. We tell you in advance about a new or replacement subprocessor, and you may object, as the DPA describes.
  • We help you answer requests from the people the data is about.
  • We tell you without undue delay after we become aware of a personal data breach affecting customer data.
  • We delete customer data when you delete it, and automatically at the end of the retention periods you choose, subject to section 13.4 (logs and the operator copy).

6.4 Credentials you give us

This covers destination and log-stream credentials, such as API secrets, service account keys, access tokens and access keys.

  • How we store them. They are encrypted in a separate store and never shown again after you save them.
  • How we use them. Only to send your events, run the tests you ask for and deliver your log streams.
  • What you control. You decide what access each credential grants, and you can replace or delete it at any time. Deleting a credential erases it from that store.
  • When you stop. When you stop using a destination or CLItrail, revoke the credential at the platform that issued it.

CLItrail gives you controls, and using them lawfully is your responsibility. You must do the following.

7.1 Tell people

  • On your website. Every website where the tag runs needs a privacy notice, linked clearly from each page the tag runs on. That notice must:
    • describe CLItrail and the data it collects;
    • name each analytics and advertising platform that receives data through CLItrail (for example Google, Meta, TikTok and X);
    • explain how people can opt out of interest-based advertising, and where to do so;
    • if you send data to Google Analytics, disclose that you use Google Analytics and how it collects and processes data.
  • For X Ads. Give legally sufficient instructions on how to opt out of interest-based advertising through a mechanism X describes on its page Your privacy controls for personalized ads.
  • For Meta and TikTok. Include what their terms require, including a link to an opt-out mechanism such as www.aboutads.info/choices or www.youronlinechoices.eu.
  • Where people install your software. Mention the installer hook wherever people install your software, for example in your README or on your install page. Say what the hook reports and how to turn it off: DO_NOT_TRACK=1 or CLITRAIL_DISABLE=1.
  • Reconstruction. Say that installs can be matched to visits from the same network when reconstruction is on. Reconstruction is on by default on paid plans.
  • Before the tag runs. Get consent where the law requires it before the tag reads cookies, writes to browser storage or sends identifiers, for example under the ePrivacy rules in the EEA and the UK. Keep the tag inactive (enabled: false or data-enabled="false") until then.
  • Before the hook runs. Get consent before the installer hook runs where the law requires consent for software that reads information on a person’s computer. You can ask in your installer, or install without the hook for those people.
  • Before an ad platform receives data. Where the law requires it, get consent for the data use each advertising platform describes before its destination receives data.
  • Consent records. Keep records that show consent was given, where the law or a platform’s terms require them.

7.3 Respect opt-outs

CLItrail keeps visits that carry a Global Privacy Control signal away from advertising destinations. Honouring every other opt-out or withdrawal of consent is your responsibility, including choices made in your consent banner. For those people:

  • keep the tag inactive;
  • do not send data about anyone who has opted out of targeted advertising, or of the sale or sharing of their data.

7.4 Follow each platform’s terms

Accept the terms of every platform you send data to (section 9) before you send it data, and follow them.

Set the Google Ads consent values (ad_user_data and ad_personalization) truthfully. They must reflect the consent you actually hold.

7.5 Confirm before going live

A Google Ads, Meta, TikTok or X Ads destination can go live only when both of these are true:

  • your domain is verified;
  • the person switching it to live has confirmed the platform’s terms and your notice and consent duties.

We record when the confirmation was given and by which account. We rely on that confirmation.

7.6 Keep the hook’s opt-outs

Do not remove or suppress the hook’s DO_NOT_TRACK, CLITRAIL_DISABLE or CI checks, and do not set CLITRAIL_QUIET for your users.

Acceptable Use Policy

This policy is part of these terms. It applies to everyone who uses CLItrail through your organisation, and to the tag and the hook wherever you deploy them. You must not do any of the following, or help or allow anyone else to do so.

Data

  • Send any of the following through page addresses, UTM values, custom adapters, value fields or any other field:
    • names, email addresses, phone numbers, postal addresses, precise locations or government identifiers;
    • payment card, bank or other financial account details;
    • health information;
    • any special category of personal data, such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, or a person’s sex life or sexual orientation.
  • Name a conversion event, conversion action or pixel at a platform in a way that reveals or implies any of that information.
  • Use CLItrail on websites or software directed at children.
  • Send data that you know, or should know, is about children under 13, or under a higher age where local law sets one.
  • Try to identify people from receipts, installation IDs, hashes or any other CLItrail data.
  • Combine CLItrail data with other data to identify people or to build profiles of individuals.
  • Paste secrets, passwords or other people’s personal data into support requests or their diagnostics.

Instrumentation

  • Install the tag on a website, or the hook in software, that you do not own or control, or that you are not authorised to instrument. An agency may do so for a client that has authorised it.
  • Modify the hook to read anything other than CLItrail receipts and the machine facts it documents.
  • Distribute the hook in a way that hides what it does.
  • Send visits, installs or conversions that did not happen.
  • Use CLItrail to mislead or defraud an advertising platform, an advertiser or anyone else.

The service

  • Overload, probe or scan the service without our written permission.
  • Bypass its limits or security controls.
  • Try to access another organisation’s data.
  • Point webhooks or log streams at systems you are not authorised to send data to, or use them to attack or overload anyone.
  • Use the service in a way that breaks any law, including privacy, consumer-protection and sanctions laws, or that infringes anyone’s rights.

Reporting and enforcement

If you believe CLItrail is being used against this policy, for example through a hook in software where you did not expect one, email founders@pilotprotocol.network. We may act on a breach of this policy under section 12 (suspension) and section 13.2 (ending the agreement).

Third-party platforms

9.1 Destinations and their terms

Destinations and log-stream storage are run by third parties under their own terms. You accept those terms with each platform directly.

DestinationTerms you must accept and follow
GA4Google Analytics Terms of Service; Google’s EU user consent policy
Google Ads (Data Manager API)Google APIs Terms of Service; the Data Manager API terms, including the advertising and customer data policies they refer to; Google’s EU user consent policy
Meta (Conversions API)Meta Business Tools Terms
TikTok (Events API)TikTok Business Products (Data) Terms and, where they apply, TikTok’s Jurisdiction Specific Terms
X Ads (Conversions API)X’s Conversion Tracking Program terms, which are part of X’s advertising terms: for the United States or for other countries. Also X’s Policies for conversion tracking and custom audiences. For your X developer app, the X Developer Agreement and Developer Policy.
Webhooks and log streamsYour own agreements with whoever operates each endpoint or storage service

9.2 We act on your behalf

You authorise us to act on your behalf, as your agent for this purpose only. That means sending the events your live destinations select to those platforms and endpoints, on your instructions, with the credentials you give us or, for a Google Ads data partner link, with our own (section 9.3). You confirm that:

  • you have accepted each platform’s terms yourself;
  • you are authorised to have us send this data for you;
  • you remain responsible to each platform for the data sent in your name.

9.3 Your credentials and accounts

You set up each destination with credentials from your own account at that platform. There are two exceptions:

  • Google Ads data partner link. Where the Google Ads form offers it, you can instead create a data partner link in your Google Ads account. We then send with our own credentials, as the data partner.
  • Webhooks. CLItrail generates each webhook’s signing secret. You copy it to your endpoint.

You are responsible for:

  • the credentials you give us and the access they grant;
  • making sure each platform’s terms allow you to use them with CLItrail;
  • revoking them at the platform when you stop using CLItrail.

X Ads. The X Ads destination uses your X developer app’s keys and your access token. X’s Developer Agreement and Developer Policy restrict sharing these credentials with third parties. Before you set up the destination, check with X that your use is permitted, for example by getting X’s written permission. You set it up at your own risk.

9.4 What we do not control

  • Platform decisions. We do not control whether a platform accepts, attributes, reports or optimises for an event.
  • Platform changes. We are not responsible for changes to a platform’s interfaces, policies or decisions, or for your accounts with it.
  • Delivery status. A delivery status of “submitted” means the platform answered with success. It does not confirm that the platform used the event.
  • Time limits. Events outside a platform’s time limits are not sent.

9.5 Complaints

We tell you promptly about any complaint we receive about data sent in your name. You tell us promptly about any complaint that concerns how CLItrail collected or sent data.

9.6 Our own providers

  • Hosting. Cloudflare® hosts CLItrail.
  • Sign-in. Google provides sign-in through Firebase Authentication, under its own terms.
  • Payments. Stripe processes payments, under its own terms.

The providers that process customer data are listed at clitrail.com/subprocessors.

Attribution accuracy

CLItrail reports the evidence it has. It does not warrant that its attribution is complete or correct.

  • Matched receipts. A matched receipt shows that a recorded visit happened in a browser on the same computer. It does not prove that the person who installed saw that page or copied the command from it.
  • Handoff tokens. A handoff token shows which visit prepared a command, not who ran it.
  • Reconstructed matches. These are labelled probable. They are based on a shared public network and other coarse signals, and can be wrong.
  • Unattributed installs. Safari and External are the likeliest explanations for an unattributed install, not findings about a person.
  • Unmatched installs. Installs can go unmatched:
    • in private browsing;
    • after browser data is cleared;
    • on another device or user account;
    • in remote or containerised environments;
    • in browsers the hook does not support;
    • when the installer runs without the hook.

    On Free, no install is matched.

Do not use CLItrail data as the sole basis for payments, billing or decisions about individuals.

Logs and telemetry

  • What we record. CLItrail records every request it receives for your organisation and every request it sends on your behalf, with the exact bodies, as the privacy policy and the documentation describe. This recording cannot be switched off. Some values are never stored in the clear:
    • credentials are redacted;
    • receipts and handoff tokens are kept only as keyed hashes with their last 6 characters;
    • IP addresses are kept only as keyed hashes.
  • Who can see them. Everyone in your organisation can read its logs in the dashboard, and members and above can export them. On Enterprise, admins and owners can also stream them to storage you control. You are responsible for who in your organisation can read the logs, and for the copies you export or stream.
  • How long they are kept. Your organisation’s logs are kept for its log retention period. This is 30 days by default, or the plan’s maximum when that is shorter: 7 days on Free, 30 on Standard and 90 on Enterprise.
  • Our operator copy. To operate, debug and secure the service, a copy of every record from every organisation also goes to our own log storage.

Suspension

  • When we may suspend. We may suspend an account, an organisation or a website, pause a destination or log stream, or refuse traffic in any of these cases:
    • you break these terms, including the Acceptable Use Policy;
    • a law, court, authority or platform requires it;
    • it is needed to protect the service, its users, the people whose data it processes or the public, for example during an attack or when an account seems compromised.
  • Scope. We limit a suspension to what the reason requires, and lift it once the reason is resolved.
  • Notice. Where we reasonably can and the law allows, we tell your organisation’s owners before we suspend, with the reason and what would resolve it. Otherwise we tell them promptly afterwards.
  • Data during a suspension. A suspension deletes no data, and your retention settings keep applying.
  • Fees. If we suspend because you broke these terms, we do not refund fees already paid.

Termination, export and deletion

13.1 Ending by you

You can stop using CLItrail at any time:

  1. Export what you need (section 13.3).
  2. Cancel any paid plan (section 4.6). It runs to the end of the month already paid.
  3. Delete websites at any time. Delete organisations, or your account, once their subscriptions have ended (sections 4.6 and 13.4). If you want our help retrieving data after the plan ends (section 13.6), delete them after you have it.
  4. Remove the tag from your websites and the hook from new releases of your software.

13.2 Ending by us

  • For a breach. We may end this agreement for your organisation, and close it, if you materially break these terms and do not fix the breach after notice and a reasonable chance to do so. We may do so immediately if:
    • the breach cannot be fixed;
    • the breach is serious, such as abuse under section 8 that puts people, platforms or the service at risk;
    • a law, court or authority requires it.
  • Ending the service or a plan. We may stop offering CLItrail, or a paid plan, with at least 30 days’ notice under section 19. Until the date in that notice, you can still sign in and export your data.
  • Refunds. If we stop offering CLItrail or your paid plan, or close your organisation for any reason other than your breach, we refund the unused part of the month you have already paid for.
  • Export after closure. After we close an organisation, we keep its data for 30 days. During that time an owner can ask us at founders@pilotprotocol.network for an export of its install events and logs. This does not apply where a law, court or authority prevents it. After the 30 days we delete the data as section 13.4 describes.

13.3 Exporting your data

These are the data you can export, and how:

DataHowPlansWho
Install eventsSettings → Data retention and export → Download CSV. Each file holds up to the 100,000 most recent install events, one row each, with the columns received_at, event_type, resolution, method, confidence, channel, campaign, page_url, referrer, touches, destinations (with each delivery status), install_path and unattributed_reason.Standard, EnterpriseMembers, admins and owners
Logs: inbound, outbound, audit, error and alert recordsLogs → Export the filtered range as CSV or NDJSON, up to 100,000 records or 25 MB per file and 10 exports an hour.All plans (on Free, without attribution fields)Members, admins and owners
A continuing copy of the logsLog streams to Amazon S3, S3-compatible storage or a webhook, as batches in the clitrail.telemetry.v1 record schema.EnterpriseAdmins and owners
  • Formats. The CSV columns are described under Retention and deletion, and the log records under Logs and Record schema.
  • What cannot be exported:
    • Credentials. They are write-only; keep the originals, or issue new ones at the platform.
    • Settings. They are shown in the dashboard but not exported as a file.
    • Your own account data. Ask for a copy as the privacy policy describes.
  • Export before a paid plan ends. On Free:
    • the install-event export and attribution are not available in the dashboard;
    • log records older than 7 days are deleted at the next clean-up;
    • log streams are paused.

    For 30 days after the plan ends, an owner can still ask us for the install-event export (section 13.6).

  • Data already sent elsewhere. Data already delivered to a destination or streamed to your storage stays there, under that service’s retention.

13.4 Deletion

  • Deleting a website. Admins and owners use Settings → Delete this website and confirm with the website’s name and a fresh sign-in. This removes the website’s visits, handoff tokens, install events, journeys, deliveries, destinations with their credentials, and the website’s audit log. The organisation’s activity keeps one line recording the deletion.
  • Deleting an organisation. Owners can delete an organisation once its subscription has ended, but not their last organisation. After a cancellation, the subscription ends at the end of the month already paid (section 4.6). Deleting the organisation removes its websites as above, its install paths, its log streams with their credentials, its Logs, its billing record and its settings.
  • Deleting your account. Use Account and security → Delete account. This removes your sessions, your support requests and your account.
    • Organisations that only you belong to are deleted with your account. Their subscriptions must have ended first.
    • You leave organisations you share with others. If you are the last owner of one, first make someone else an owner.
    • Your past actions in shared organisations stay in their activity. Your account is unlinked from them, but records of membership changes keep your email address.
  • When deletion happens. Deletion takes effect immediately in the live database and in the secret store, and cannot be undone. Some copies last longer:
    • a deleted website’s records stay in the organisation’s Logs until the log retention period ends; deleting an organisation deletes its Logs at once;
    • our hosting provider keeps point-in-time recovery data for up to 30 days;
    • our operator copy is kept as section 11 describes.
  • Automatic deletion. Visits, install events and deliveries are deleted automatically after each website’s retention period: 30 to 1,095 days, with 395 days as the default. Logs are deleted after the log retention period.
  • What deletion cannot reach:
    • Stripe keeps its own records of payments and invoices under its own terms;
    • deletion cannot recall data already sent to a destination or streamed to your storage.

13.5 What continues after the agreement ends

The following continue after the agreement ends:

  • section 4.7 (refunds and billing disputes);
  • section 6, until customer data is deleted;
  • section 13.6 (switching and exit), until its retrieval period ends;
  • sections 10, 13, 14, 15, 16, 17, 20 and 21;
  • any amount due before the end.

13.6 Switching and exit

This section applies when you move your data to another provider, or to your own systems, or simply leave.

  • Starting an exit or a switch. An owner can start it at any time, with no notice period, in either of two ways:
    • by cancelling the paid plan in Manage billing (section 4.6);
    • by writing to founders@pilotprotocol.network that the organisation is leaving (an “exit request”).

    A cancellation takes effect under section 4.6. Until the paid month ends, every export in section 13.3 stays available in the dashboard.

  • Retrieval period. For 30 days after a paid plan ends, or after an owner’s exit request if that is later, an owner can ask us at founders@pilotprotocol.network for:
    • an export of the organisation’s install events, in the CSV format of section 13.3;
    • an export of the logs the organisation still holds, in CSV or NDJSON.

    We send them to the owner who asked. On Free, members and above can also still export the logs themselves (section 13.3). Log records older than 7 days are deleted at the next clean-up after the move to Free (section 4.9), so export or stream older logs before the paid month ends.

  • No charges. We charge nothing for switching, for exports or for retrieval.
  • Formats. The data formats are described in the documentation, which is kept up to date: Record schema for log records, and Retention and deletion for the install-event CSV.
  • Erasure. When you no longer need our help, delete the organisation, or your account, as section 13.4 describes. That erases all exportable data at once, apart from the copies section 13.4 lists as lasting longer. As section 4.6 says, deletion is possible once the subscription has ended.

Ownership, licence and feedback

  • Our rights. We and our licensors own the service, including the tag, the hook, the handoff command, the documentation and the clitrail-setup skill. These terms give you no rights in them beyond this section.
  • Your licence. While your organisation uses CLItrail, you may use the service. You may also copy and distribute the tag and the hook in your websites and software, unchanged except for the settings the documentation describes.
  • When you stop. When you stop using CLItrail, remove the tag from your websites and the hook from new releases of your software. You do not need to change releases you have already published.
  • Your data. You keep all rights in your data and content (section 6.1).
  • Feedback. If you send us feedback, we may use it without any obligation to you.

Disclaimer

TO THE EXTENT THE LAW ALLOWS, THE SERVICE, THE TAG, THE HOOK AND THE DOCUMENTATION ARE PROVIDED “AS IS” AND “AS AVAILABLE”, WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED OR STATUTORY. THIS INCLUDES ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE OR NON-INFRINGEMENT. IT ALSO INCLUDES ANY WARRANTY THAT ATTRIBUTION WILL BE COMPLETE OR ACCURATE, THAT A PLATFORM WILL ACCEPT OR USE AN EVENT, OR THAT THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE.

Limitation of liability

TO THE EXTENT THE LAW ALLOWS, VULTURE LABS IS NOT LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, DATA OR ADVERTISING SPEND, EVEN IF IT WAS TOLD THEY WERE POSSIBLE.

VULTURE LABS’ TOTAL LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS IS LIMITED TO THE AMOUNT YOUR ORGANISATION PAID US FOR THE SERVICE IN THE 12 MONTHS BEFORE THE EVENT THAT GAVE RISE TO THE LIABILITY.

Nothing in these terms limits liability that cannot be limited by law.

Indemnity

You will defend and indemnify Vulture Labs against third-party claims arising from any of the following, and against the resulting losses, costs and reasonable legal fees:

  • your websites and software;
  • your notices and consents;
  • the data you choose to collect or send;
  • your use of third-party platforms and the credentials you give us;
  • your breach of these terms, including section 8.

Third-party claims include claims by platforms, by authorities and by the people whose data you collect.

Changes to these terms

  • Notice of changes. We may update these terms. We publish the new version on this page, with its effective date, at least 30 days before it takes effect, and we notify owners of material changes under section 19. A shorter period applies only when the law or security requires a change sooner.
  • If you do not agree. Stop using CLItrail and cancel before the new version takes effect. If you keep using CLItrail after that date, you accept the new version.
  • The DPA. Changes to the DPA follow the DPA.

Notices

  • To you. Notices under these terms are written and sent by us, by email from founders@pilotprotocol.network to every owner of the organisation concerned, at the email address of the account the owner signs in with. Notices about changes to these terms are also published on this page. An emailed notice is given when it is sent. Keep your owners’ accounts current. To have notices also sent to another address, such as your privacy team, write to founders@pilotprotocol.network. Apart from sign-in link emails sent through Firebase, the CLItrail service sends no automated email.
  • To us. Send notices to founders@pilotprotocol.network. Notices to us take effect when we receive them.

Governing law and disputes

  • Governing law. These terms are governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
  • Informal resolution first. Before starting formal proceedings, contact us at founders@pilotprotocol.network. We will both try in good faith to resolve the dispute informally for at least 30 days.
  • Courts. Any dispute arising under these terms is decided exclusively by the state or federal courts located in Delaware, and both of us submit to their jurisdiction. Either of us may still ask any competent court for urgent injunctive relief.
  • The DPA. The DPA, and any Standard Contractual Clauses it includes, keep the governing law and forum they state.

General

21.1 Entire agreement

These terms and the DPA are the entire agreement between you and us about the service, and they replace any earlier agreement about it. Terms in your purchase orders or other documents do not apply.

21.2 Assignment

You may not transfer this agreement without our written consent, except to a successor to your business, with notice to us. We may transfer it to an affiliate or to a successor to our business, with notice to you.

21.3 Events beyond control

Neither of us is liable for a delay or failure caused by events beyond our reasonable control. Examples include:

  • outages of hosting providers, networks or platforms;
  • attacks;
  • natural events;
  • government action.

This does not excuse payment of amounts due.

21.4 Severability

If a court holds part of these terms unenforceable, that part is enforced as far as the law allows, and the rest stays in effect.

21.5 No waiver

A failure or delay in enforcing any part of these terms is not a waiver of it.

21.6 Relationship

We are independent parties. We act as your agent only for the limited purpose in section 9.2. Nothing in these terms creates a partnership, joint venture or employment relationship, and no one else has rights under these terms.

21.7 Export controls and sanctions

You must comply with the export-control and economic-sanctions laws that apply to you and to us, including those of the United States. You may not use CLItrail in, or for the benefit of, a country, region, person or organisation that those laws restrict.

21.8 Language

These terms are written in English. If they are translated, the English version prevails.

Contact

Operator
Vulture Labs, Inc., a Delaware corporation
Address
San Francisco, California, USA
Email
founders@pilotprotocol.network: support, billing, privacy, security and legal notices
Governing law
The State of Delaware, USA
Courts
The state and federal courts located in Delaware