What to Say When a Client Asks If You’re Tracking Them

Q
Quixli Team
October 4, 20268 min read

What to Say When a Client Asks If You’re Tracking Them

It usually arrives as one line, with no preamble, in the middle of an otherwise normal thread. "Does this link tell you when I open it?"

The next thing you write decides more than the answer does. Not because the client is testing your ethics — they are almost never testing your ethics — but because the shape of your reply tells them whether you are a person who says true things quickly.

The first sentence is the whole thing

Start with the word yes. On its own, before any explanation.

“Yes — the link tells me when it’s been opened and roughly how long for. That’s all it does, and it’s why I stop chasing people who’ve already read something.”

Three properties make this work. It concedes immediately, which removes any suggestion that you were hoping not to be asked. It states the limit in the same breath, which is what makes it credible. And it gives the reason without apologising for it, because there is nothing to apologise for.

What loses the room is the qualified opening: "Well, most tools do this…", "It’s just standard analytics…", "Not really, it only…". Every one of them reads as a person choosing their words carefully, which is precisely the thing the client is checking for.

Then answer the question they were actually asking

Under one sentence there are usually one of four real concerns. Match the one you are being asked.

  • “Are you going to chase me?” The most common, by a distance. Answer it directly: “It doesn’t trigger anything automatic at your end — no one gets called because you opened something at 11pm. I use it to know when it’s reasonable to follow up rather than guessing.”

  • “What do you know about me?” Give the inventory, and give the limits with it: “When it was opened, how long each visit lasted, and how many times. Not which part you read — there’s no such thing in it. Where you are is a rough guess from your connection and it is often wrong.”

  • “Can my colleagues be seen?” Honest answer: visits from a forwarded link do appear, and they appear as unnamed visits unless somebody signs in or types an address. If that is uncomfortable for their organisation, offer to send a copy instead. Do not oversell your ignorance — you can see that a second reader exists.

  • “Is this legal?” The safest true answer is about your posture, not about the law: “I have a privacy notice that covers it, I keep it for weeks rather than years, and I’ll delete everything for this document if you’d rather.” Do not offer a legal opinion, including a reassuring one — the instruments that actually apply are worth understanding for yourself, and that article is careful not to be advice either.

Five things not to say

  • “Everyone does this.” True and worthless. It answers a question about norms with a question about ethics still open.

  • “It’s just for my own records.” Vague in a way that sounds evasive, and it is the phrasing people use when they are hiding something.

  • Anything specific about their behaviour. Not now of all moments. “I saw you looked at it twice on Thursday” answers the question by demonstrating exactly what they were worried about.

  • “I can turn it off”, if you cannot or will not. Offering and then not doing it is worse than not offering.

  • A long paragraph. Length reads as defensiveness. Two sentences and an offer to go further beats six sentences that pre-empt objections nobody made.

If they ask you to stop

Do it, say you have done it, and delete what you already collected. In Quixli that is one action on the document’s analytics screen and it removes every visit, event and captured address held for that document across all of its links. It is not recoverable, and it cannot pull back a notification email that already went out — do not claim that it can.

Then send the document another way if they want one: a PDF, or a link with tracking off. The number of deals lost by complying quickly with this request is approximately zero. The number damaged by arguing about it is not.

When the question comes from someone other than your contact

Occasionally the asker is not the person you have been talking to. A security or IT function has looked at the link and someone has been asked to find out what it is.

That is a different conversation with different content — token strength, expiry, revocation, where the data sits, what certifications exist — and answering it with reassurance rather than specifics will fail. The security questions a client’s IT team will ask has the answers, including the ones where the honest answer is “we don’t have that”.




The thing worth remembering

Nobody has ever lost work by saying yes to this question quickly. People lose work by being caught in the gap between what they said and what the tool does.

If you would rather raise it before they do, should you tell a client you can see they opened it works through when that is the better move. And the notice every shared document carries means the honest answer was already on their screen before they asked.