Legal
Privacy Policy
Last updated September 21, 2026. This policy explains what data VisitTrack collects, from whom, and why — for both account holders and the visitors of the sites our customers track.
1.Who this applies to
This policy covers two kinds of people: account holders — people who sign up for VisitTrack to track their own site(s) — and site visitors — the (mostly anonymous) people whose traffic an account holder's site tracks. For a detailed breakdown of what we collect about site visitors specifically and why, see our GDPR page — this document is the general policy; that one is the detailed technical companion.
2.Data we collect from account holders
When you create a VisitTrack account, we collect:
- your email address and, if you sign up with a password, a securely hashed password — never the plaintext;
- your name and profile picture, if you sign up or log in with Google;
- the domain(s) and site name(s) you register for tracking;
- billing details, handled entirely by Stripe — we store your plan and subscription status, never your card number;
- support/contact messages you send us.
We use this to operate your account, send transactional email (password resets, billing receipts), and provide support.
3.Data we collect from your site's visitors
The tracking script sets no cookies and builds no cross-site profile. Per pageview or custom event, we record: the page path, referrer and UTM/ad-click parameters, approximate country/region/city derived from IP (the IP itself is used transiently and not stored), device/browser/OS, and a visitor identifier generated locally in localStorage, scoped to that one site. See /gdpr for the full list and retention details.
4.How we use data
- to provide the analytics dashboard and the features you enable (goals, funnels, revenue attribution);
- to send account-related email — verification, password reset, billing, and, if you opt in, product updates;
- to detect and prevent abuse of the service (rate limiting, bot filtering);
- to improve the product — in aggregate, never by reading an individual visitor's activity for purposes unrelated to your dashboard.
6.Data retention
Account data is retained for as long as your account is active, plus a limited period after closure to comply with legal/billing obligations. Analytics event data is retained per your plan's data-retention window; deleting a site or closing your account removes its associated event data. You can request earlier deletion at any time — see Your rights below.
7.Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights — for your own account, or on behalf of a site visitor who has contacted you — email privacy@visitrack.app. We respond within 30 days.
8.Security
We use industry-standard measures to protect data in transit (TLS) and at rest, restrict internal access on a need-to-know basis, and store passwords hashed, never in plaintext. No method of transmission or storage is 100% secure; we can't guarantee absolute security, but we treat data protection as a core product requirement, not an afterthought.
9.Children's privacy
VisitTrack is a B2B analytics tool not directed at children, and we don't knowingly collect personal data from children under 16.
10.Changes to this policy
If we make material changes to this policy, we'll notify account holders by email and update the “last updated” date below before the change takes effect.
11.Contact
Questions about this policy or how your data is handled: email privacy@visitrack.app.
Looking for the technical details?
Our GDPR page and DPA template go deeper into exactly what tracking data is collected and how it's processed on your customers' behalf.