Company and legal
Privacy Policy
Understand how DataVisitors handles account information, customer analytics, and privacy requests. This notice separates our service operations from the data customers choose to collect.
Policy review copy · Revised 8 September 2026
Document details and contact
Last revised: 8 September 2026. Status: policy review copy. Legal review: not yet recorded. This version has no effective date.
DataVisitors is the name of the analytics service. The legal operator's name, business address, and country require confirmation before this notice takes effect. Contact [[email protected]](mailto:[email protected]) with the subject “Privacy request” for questions about this notice.
Who this notice covers
This notice covers visitors to our website, people who create or use a DataVisitors account, and people who contact us. It also explains how the service processes analytics for its customers.
When you visit a customer's website or use its application, that customer decides what to collect and why. Read that customer's privacy notice for its purposes, lawful basis, and contact details. DataVisitors's software settings do not replace the customer's legal responsibilities.
Our role and the customer's role
For account administration, service security, billing administration, and support, the DataVisitors operator determines the relevant processing purposes. In data protection terms, the operator acts as a controller for those activities.
For analytics that a customer submits under its instructions, the customer normally acts as controller and DataVisitors acts as processor. A customer that processes data for another organization can instead act as a processor. The Data Processing Agreement describes the proposed responsibilities for that relationship.
Account and organization information
Account information can include your email address, display name, password hash, verification status, and account identifiers. Organization records include memberships, roles, invitations, project settings, and usage records.
The service uses authentication tokens and session records to provide account access. It stores password hashes rather than readable passwords. Supported external sign-in methods can supply an account identifier and permitted profile information from your chosen provider.
Account email and authentication information are necessary for the relevant sign-in and recovery functions. Optional profile information is not required to read public marketing pages.
Support, messages, and payment administration
When you contact support, the information you choose to send forms part of your request. Keep passwords, API keys, payment-card details, and unnecessary visitor records out of messages.
Where billing is enabled, the service handles plan choices, usage, subscription references, and billing status. The payment process and current offer identify the relevant payment provider. This notice does not claim that DataVisitors stores complete payment-card numbers.
Optional digest emails, scheduled reports, alerts, and browser notifications use the account or destination information required for delivery. You or your organization control the relevant subscriptions and destinations.
Analytics information submitted by customers
Depending on the integration and settings, customer analytics can include:
- Event names and timestamps, page or screen paths, referring hosts, and campaign fields.
- Browser, device, operating-system, locale, and coarse location categories.
- Session and visitor identifiers, consent state, engagement duration, and scroll depth.
- Custom event properties, goal completion, and purchase amounts with currency.
- Optional click positions and viewport dimensions for enabled heatmaps.
- A customer-supplied user identifier and permitted traits when identified collection is enabled.
The customer supplies this information through its website, application, server, or supported import. An integration can send only the events the customer implements and permits.
Collection limits and optional identity
The analytics pipeline processes network addresses in memory for functions such as coarse location and visitor counting. Analytics storage does not retain raw IP addresses or raw user-agent strings. Infrastructure providers can process connection information separately when delivering the service.
Stored page paths omit the raw query string. Referrers reduce to their host. Campaign fields remain separate report values. Ordinary event properties pass through privacy filtering, but customers must still avoid sending unnecessary personal or sensitive information.
People views are off by default and require administrator enablement. Identified traits require the supported consent state and a valid user identifier. Customers decide which permitted traits to supply. DataVisitors does not buy or discover identities for these profiles.
A rotating or pseudonymous identifier does not automatically make every associated record anonymous under data protection law.
Purposes and proposed lawful bases
The final operator must confirm the applicable lawful bases before this notice takes effect. The proposed account-service purposes are:
- Account access and requested support: perform the service agreement where you are the contracting individual.
- Organization administration: enable authorized users to access an organization's purchased service. The proposed legitimate interest is providing that organization's requested service.
- Security and service reliability: prevent misuse, investigate faults, and protect accounts. The proposed legitimate interest is operating a safe and reliable service.
- Billing and required records: administer payment and meet applicable accounting or legal duties. A legal-obligation basis applies only where an actual duty requires the processing.
- Optional communications or device storage: use consent where the applicable law requires it. A stated purpose alone does not establish a consent exception.
For customer analytics, the customer selects and documents its lawful basis. Selecting Automatic, Strict, or Opt-out mode does not itself establish that basis.
Access, disclosure, and customer sharing
Authorized organization members can access information according to their roles and enabled features. Authorized service personnel can access information where necessary for support, security, or service administration.
Customers can create aggregate share links, export reports, configure webhooks, or connect other applications. A recipient can retain an exported copy. Revoking a link stops later access through that link but cannot recall copies already obtained.
The service can use approved providers for hosting, network delivery, email, payment processing, or other configured functions. The subprocessor disclosure states the current verification status. A lawful disclosure to a public authority requires a valid legal basis and an appropriate response to the request.
International processing
The production provider list and processing countries remain unconfirmed in this review copy. This document makes no claim that all data stays within a particular country or region.
Before processing that requires a transfer safeguard, the operator must identify the destination and applicable mechanism. Depending on the circumstances, this can involve an adequacy decision or approved contractual safeguards. Ask for the relevant transfer information before relying on a residency requirement.
Retention of account and operational records
The following periods describe implemented application rules. Scheduled cleanup and database maintenance perform removal after the relevant threshold. These periods are not a promise of deletion at an exact second.
- Login sessions expire after 30 days unless revoked earlier. Expired or revoked session records become eligible for cleanup after a further 30 days.
- Email verification links expire after 48 hours. Password reset links expire after 1 hour. Used or expired token records become eligible for cleanup after 7 days.
- Invitations expire after 14 days. Their cleanup rule retains spent or expired records for a further 30 days.
- Eligible unverified registrations become subject to cleanup after 48 hours. Accounts with a membership or a protected administrative reference are outside this automatic cleanup rule.
- Delivered or terminally failed service-mail records become eligible for cleanup 90 days after creation. Pending delivery can require further handling.
- Revoked browser-push subscriptions become eligible for cleanup after 30 days.
Account and organization records otherwise follow the account lifecycle and applicable recordkeeping needs. Accounting, legal, audit, and backup retention periods need a confirmed operator schedule before this notice takes effect.
Retention of analytics and identified traits
Analytics retention follows the project's configured plan and data-retention rules. Check the current offer and project configuration for the applicable period. Imported records do not gain a new retention period merely because they arrive later.
Identified traits become eligible for automatic removal 365 days after their last update. Authorized administrators can request trait deletion sooner.
Deleting traits and erasing associated events are separate operations. An event-erasure request creates a receipt without retaining the erased event content. Independently managed backups, replicas, and exported copies require their own deletion handling. No verified backup-removal deadline is stated in this version.
Account closure and retained records
Account closure replaces the account's identifying profile fields and revokes access. It removes memberships and the account records covered by the closure workflow. A sole remaining organization owner must resolve ownership before closure.
Some records of earlier actions retain an opaque account reference after identifying profile fields are removed. This preserves records such as audit entries, sent messages, and relevant administrative actions. Closing one person's account does not automatically erase an organization's analytics or another member's records.
Privacy exports, deletion controls, and account closure are not restricted because of the selected plan or payment status.
Your privacy choices and rights
Depending on the applicable law and processing basis, you can request access, correction, erasure, restriction, or a portable copy of eligible personal data.
Right to object: you can object to processing based on legitimate interests where the applicable law provides that right. You can also object to direct marketing where that right applies.
Where processing relies on consent, you can withdraw consent for future processing. Withdrawal does not change the lawfulness of earlier processing. Use the relevant website's consent controls or contact its operator.
For DataVisitors account information, contact [[email protected]](mailto:[email protected]). For analytics collected by a customer, contact that website or application's operator first. DataVisitors can assist the responsible customer with a request under its instructions.
How we handle a request
Describe the right you want to use and provide enough information to identify the relevant account or customer website. Do not send identity documents or sensitive records unless a necessary and proportionate verification step requires them.
The responsible controller must respond within the period set by the applicable law. The response can explain any permitted extension, identity check, or legal reason that limits a request. This review copy does not replace those statutory duties with a separate support deadline.
You can complain to the competent data protection authority. For UK matters, see the Information Commissioner's Office. For EEA matters, consult the EDPB authority directory.
Security, children, and automated decisions
The product uses authorization checks, revocable credentials, privacy filtering, and controls over individual views and sharing. Read Security for the implemented controls. No online service can promise absolute security.
DataVisitors is intended for organizations and their authorized users. Customers must assess any collection involving children and any additional restrictions that apply. Do not submit sensitive categories of data without an appropriate, separately agreed processing arrangement.
Reports, segments, and automated findings help customers interpret activity. The product does not itself make employment, credit, healthcare, or similar legal decisions about visitors. Customers remain responsible for their own decisions and uses of reports.
Changes to this notice
A published revision will show its revision date. Material changes to processing require appropriate notice before the changed purpose takes effect, and new consent where required.
Read the Cookie Policy, Data Processing Agreement, and subprocessor disclosure with this notice. The operator details, provider record, transfer arrangements, and remaining retention schedule must be completed before legal approval.