Privacy

What is collected, and what never is.

Both lists in full, on the page, before you ask. The second list is the longer one.

Processed

  • A session hash, computed in memory from connection data with a salt that rotates daily, then discarded. It cannot be reversed and it cannot be matched to yesterday’s.
  • Page paths on your own site, with click ID values stripped before anything is written.
  • UTM parameters: source, medium, campaign, term, content.
  • Referrer, as sent by the browser.
  • Coarse device and locale: browser, operating system, screen size bucket, language, country.
  • Events you define, with whatever properties you choose to attach to them. You control this one entirely, which is why the docs say not to put personal data in it.
  • Daily campaign spend from your ad accounts: money, impressions, clicks. Aggregate, at campaign level, never per person.

Never processed

  • Cookies, of any kind, first or third party.
  • localStorage, sessionStorage, IndexedDB, or anything else written to the device.
  • Stored IP addresses. The address is used in memory to compute the session hash and is never written down.
  • Names, email addresses, phone numbers, or account identifiers.
  • Device fingerprints, canvas fingerprints, or any probabilistic identifier.
  • Persistent visitor IDs. There is no key that connects a session today to a session tomorrow.
  • Click IDs. Their values are replaced before the first write.
  • Anything cross-site. There is no network, no shared identity graph, and no second customer’s data in your database.
  • User-level data from any ad platform. Only campaign totals are requested.

If you operate in the EU

The banner-free version of knowing your numbers.

A consent banner exists because of what gets stored on the visitor’s device. Nothing is stored on the visitor’s device here, so for analytics there is nothing to ask permission for. Your banner, if you still need one for advertising pixels, gets shorter.

The data sits in our own database rather than in an ad company’s warehouse, and none of it is passed on. That database runs in the United States today. There is no cookie, no fingerprint, no stored IP address and no identifier that survives the day, so there is no record of an individual in it to move anywhere. The DPA sets out the detail.

The paperwork arrives done. At onboarding you get:

If you operate in the US

Nothing here breaks when the next browser update or state law lands.

Pixel and session-recording wiretapping suits are landing on ordinary brands, not just on adtech. Those claims attach to interception of a visitor’s communications and to sharing them with a third party. There is no session recording here, no keystroke capture, no third party receiving anything, and no identifier that survives the day.

The accuracy argument is the one that usually lands harder. Safari caps client-side cookies at seven days, so GA4’s returning users and multi-visit paths are partly reconstruction. Ad blockers remove a further slice before it is ever recorded. Counting sessions first-party, from your own subdomain, without sampling, gets you a number you can put in front of a board.

State privacy laws keep multiplying and mostly turn on sale, sharing, and targeted advertising built from personal information. This stack collects none, so each new one is a non-event.

The whole sub-processor list.

Published in full, not on request. There are fewer entries than you are expecting.

Read the list