The product is built on the premise that you can analyze what drives revenue without tracking individuals. This page explains exactly what we collect and what we do not, based on how it is actually implemented.
Every visitor is measured by our own snippet and nothing else, so the cookieless description below has no exceptions. Separately, and only when you ask for it, we can import historical data and order data. Neither writes anything to a visitor’s device.
A ~29KB script you add to your site with one line. It uses no cookies and no localStorage. Every data point measured from visitors comes through this path.
To fill in the period before the snippet was installed, we can import daily aggregates — sessions, revenue, breakdowns by source — from a Google Analytics 4 property you connect. We never read visitor-level data, the import runs once, and you can disconnect at any time.
If you connect your ecommerce platform, we read order amounts, products and quantities. We do not read buyer names, addresses or contact details.
The snippet writes nothing to the visitor’s device, and reads nothing from it.
They are used only to derive the visitor key described below. The raw values are never written to the database.
Only a five-key UTM allowlist is extracted. Everything else in the URL is discarded, so an email address or customer name in a URL never reaches us.
The visitor key includes the site ID, so it cannot match the same person on another site. We build no individual profiles.
Per event, we record the following — all of it in service of “which page, from which source, produced how much revenue”.
Timestamp, page path and page title. Query strings are not included.
Referrer host, UTM parameters, and the channel we derive from them.
Device type (desktop / mobile / tablet), screen-width class, country and region.
Ecommerce event value, quantity, currency, product ID and name, and order ID. No customer names, addresses or email addresses.
The visitor key is the first 32 characters of a hash of a salt that rotates daily, the site ID, the IP address and the user agent. That gives it three properties.
The same person gets a different key tomorrow, so nobody can be followed over time.
The same person browsing another site produces a different key. Cross-site tracking is not possible.
Because the IP and user agent are never stored, the key cannot be traced back to a person.
We do not sell your data and do not share it with third parties for advertising.
Tables and charts each have a CSV button, so you can export that view’s data whenever you want. Deletion on account closure follows our Terms and Privacy Policy.
Payments are handled by Paddle as Merchant of Record; card data never reaches our servers.
The statistics we keep to improve our detection quality are limited to aggregates that identify no store, visitor or shopper, plus records of how metrics moved before and after each kind of improvement card. See Section 11 of our Privacy Policy.
The script is about 29KB and loads async. Events are sent with sendBeacon, so rendering and navigation are never held up.
Every operation is wrapped in try/catch, so a problem in tracking never affects the site itself.
Requests from known bot user agents are discarded rather than recorded.
If you use only our first-party snippet, nothing is written to the visitor’s device, so it generally falls outside cookie-consent rules. Whether you can drop the banner entirely still depends on the law in your market, on regulator guidance, and on every other tag on your site (advertising, chat widgets and so on). Please confirm with your own legal advisors.
Open the demo — no signup — and explore the cookieless dashboard directly.
Try the demoThe 7-day free trial needs no credit card.
This page reflects the current implementation. For the legal detail, see our Privacy Policy. Privacy Policy