Privacy

GDPR & Privacy

We explain in plain language what data we collect about your sites' visitors, how we use IP addresses for geolocation, how long we retain data, and why Analytics doesn't need a cookie banner.

What data we collect

On every pageview or custom event, we collect:

  • the path of the visited page, the referrer, and UTM parameters (if present in the URL);
  • approximate country, region, and city, derived from IP (see below — the raw IP is not retained);
  • device type, browser, and operating system, extracted from the user agent;
  • a locally generated visitor identifier (not direct personal data such as a name or email).

We don't collect names, visitor email addresses, form input content, or any other field containing direct personal data about your site's visitors. The only email addresses we store belong to authenticated accounts (the site owners who use the dashboard).

IP address and geolocation

The visitor's IP address is used strictly transiently, in a single call to the geolocation service, to determine the approximate country, region, and city of the request. The raw IP is never written to the database — there's no IP column in any of the visitor, session, or event tables. What gets saved is only the derived result (country / region / city), never the exact coordinates and never the IP address itself.

For requests from private/local IPs (for example, during testing), the geolocation lookup doesn't resolve anything — the result stays empty, just like for any other unresolvable address.

How long we retain data

We keep aggregated events for as long as the site and its associated account remain active, so you can see the complete history of your traffic in the dashboard. A site's data is permanently deleted when the owner deletes the site or closes their account, or at the owner's explicit request to us.

Because we don't retain raw IPs and don't build cross-site identifiers, the stored data doesn't allow a visitor to be re-identified outside the site they visited.

Why you don't need a cookie banner

The consent requirement under the ePrivacy Directive (also transposed into national law) and GDPR applies when information is stored or read from a user's device that isn't strictly necessary for the site to function — typically the case with cross-site tracking cookies used for advertising or profiling.

Analytics doesn't set cookies, doesn't read existing cookies, and doesn't build an identifier that tracks the same person across multiple sites. Measurement is strictly “first-party” and aggregated per site, similar to a server access log. For this type of first-party traffic analysis, the GDPR/ePrivacy framework doesn't require a separate consent banner for your site's visitors.

This is our compliance position, not legal advice — if your site has additional requirements (other third-party scripts, forms, advertising), assessing your consent obligations remains your responsibility.

Subprocessors

We use a limited number of vendors to operate the service:

  • a hosting and database provider, for the collection infrastructure and dashboard;
  • Resend, for sending transactional emails (account confirmation, password reset);
  • Stripe, for processing subscription payments (when you connect billing).

None of these vendors has access to your visitors' raw traffic data beyond their technical role in operating the infrastructure. A complete, up-to-date list of subprocessors is available on request.

Need a DPA?

If we act as a data processor for the data you collect through your site, you can use our Data Processing Agreement template as a starting point.

View the DPA template