1. Who we are and what this covers
Statsy (https://statsy.co) is a web analytics service (“Statsy”, “we”). This policy explains how we handle personal data in two different situations, because our role is different in each:
- Our own customers and visitors to statsy.co. When you join the beta, create an account or use our website, we decide how that data is used. We are the controller.
- Visitors to our customers’ websites. When a customer installs the Statsy script, we process data about their visitors only on that customer’s instructions. The customer is the controller and we are their processor. Our Data Processing Addendum sets out those terms.
Questions about privacy: [email protected].
2. Data we collect about customers
| Data | Why we use it | Legal basis |
|---|---|---|
| Beta applications: email, and optionally name, website, role and a note | To choose who to invite and to email you about the beta | Your consent, which you can withdraw |
| Account details: name, email, password (stored only as a salted hash) | To create and secure your account | Performing our contract with you |
| Workspace data: sites, goals, team members, settings, integration secrets (encrypted) | To provide the service you asked for | Performing our contract |
| Security logs: IP address, browser and time of sign-ins and sensitive actions | To protect accounts, investigate abuse and rate-limit attacks | Our legitimate interest in keeping Statsy secure |
| Emails you send us and support conversations | To answer you and improve Statsy | Legitimate interest |
| Billing details, once paid plans launch | To charge you and keep required records | Contract and legal obligation |
3. Data the script collects on customer websites
On a website that uses Statsy, the script sends us:
- The page address and time, the referrer, and campaign parameters (UTM tags and ad click identifiers). Other query parameters only if the site owner turns that on.
- Browser, operating system and device type derived from the user agent, plus screen size, language and time zone.
- Country, region and city, plus the city’s approximate coordinates (rounded to about 1 km), looked up from the IP address with an offline database or our CDN’s location headers. The IP address itself is not stored. IP Geolocation by DB-IP.
- Events the site owner sets up, such as signups, clicks, scroll depth, and payment amounts linked to a visit.
- If the site owner turns them on: session replays, click positions for heatmaps, and page performance timings. Replays mask what visitors type into form fields; other text shown on the page is recorded, so site owners should not enable replays on pages that display sensitive information.
How a visitor is recognised depends on the site’s tracking mode:
- Cookieless (lightweight). No cookies and no identifier stored in the visitor’s browser. Visits are grouped on our servers with a key made from a secret that changes every day, the site, the IP address and the browser. The daily secret is deleted after two days, after which no key can be linked back to an IP address or across days. The script caches which mode applies in the tab’s session storage.
- Full. A first-party cookie,
statsy_vid, holds a random identifier for up to one year so returning visits, journeys and revenue can be connected. A session identifier is kept in the tab’s session storage. - Auto. Cookieless for visitors from the EU, EEA, UK and Switzerland and for anyone whose browser sends a Global Privacy Control signal; full for everyone else.
By default the script sends nothing when the browser sends Do Not Track or Global Privacy Control; a site owner can switch that off for their site, in which case Global Privacy Control still forces cookieless mode unless the site is set to Full. Visitors can also be offered an opt-out. If a site owner uses the identify feature to attach an email or user id to a visitor, that is their decision and their responsibility as controller. Visitors who want to exercise their rights should contact the website they visited; we will help that customer respond.
4. How long we keep data
- Raw events and visit sessions: 90 days. Hourly and daily totals, which do not identify visitors, are kept while the site exists.
- Session replays: 90 days. Heatmap click and scroll totals: up to 400 days.
- Visitor identities a site owner attached with the identify feature: until the site owner deletes the site.
- When a site is deleted, its analytics, replays and heatmaps are deleted too. Deleting your account (Account settings) deletes your workspaces where you are the only owner. Deleted data leaves our encrypted backups within 35 days.
- Sign-in records (IP address and browser, kept with each session): until the session expires or you sign out.
- Beta applications that do not become accounts: until the beta ends, or sooner if you ask.
6. International transfers
Some providers above operate outside your country. Where data about people in the EEA, UK or Switzerland leaves those regions, we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses (with the UK addendum where needed), together with the security measures described below.
7. How we protect data
Traffic is encrypted with TLS. Passwords are hashed, integration secrets are encrypted at rest with AES-256-GCM, API tokens are stored only as hashes, and databases are not reachable from the internet. Sign-in and email endpoints are rate limited, and access inside the product is limited by workspace and role. Backups are encrypted before they leave the server.
No system is perfectly secure. If a breach affects your personal data we will tell you without undue delay. To report a vulnerability, see our security page.
8. Your rights
Depending on where you live you can ask to access, correct, export or delete your personal data, to restrict or object to how we use it, and to withdraw consent. Email [email protected] and we will reply within 30 days. We may need to confirm it is you first.
If you are in India, you have the rights of a Data Principal under the Digital Personal Data Protection Act, 2023, including to access, correct and erase your data and to have grievances addressed; send grievances to the same address and we will respond within the time the law sets. You can also complain to your data protection authority. We would appreciate the chance to fix things first. Residents of California have the right to know, delete and correct, and we do not sell or share personal information as those laws define it.
10. Children
Statsy is a business tool and is not directed at children under 16. We do not knowingly collect their data as a controller.
11. Changes to this policy
If we make a material change we will email account holders at least 14 days before it takes effect and update the date at the top of this page. Earlier versions are available on request.