Legal · Effective 2026-09-24
Privacy Policy
What Deeplitic collects on behalf of the sites that use it, why, and what it deliberately does not collect.
1. Who this policy covers
This policy describes how Deeplitic (“Deeplitic”, “we”) processes data through the Deeplitic analytics service: the tracking script installed on customer websites, the collection API, and the dashboard used by our customers to view their own traffic data.
For most of the data described below, our customer (the website owner who installed the Deeplitic tracking script) is the data controller, and Deeplitic acts as a data processor under a data processing agreement. For account and billing data about our customers themselves, Deeplitic is the controller.
2. Account authentication data
When you create or sign in to an account, Firebase processes the authentication identifier and provider details needed to verify you. Deeplitic receives the verified email address, Firebase user identifier, display name when available, and provider sign-in result so it can create and protect your application session. Email/password accounts must complete Firebase email verification before a Deeplitic session is created. Google and GitHub authentication is handled by those providers and Firebase under their respective privacy policies.
3. What we collect from website visitors
The Deeplitic tracking script sends the following, per page view or interaction:
- The page URL, page title, and referring URL
- Named events you configure (clicks, scroll depth at 25/50/75/90%, custom
track()calls) and how long a page stayed open - Coarse technical context such as device type
- A randomly generated visitor key and visit key, created in the browser and never derived from your IP address, email, or any account identifier
We deliberately do not collect, and the collection format has no field for:
- Cookies of any kind
- Persistent cross-site or cross-device identifiers
- Names, email addresses, or other directly identifying information about site visitors
- Full or precise IP addresses in the analytics database
- Keystroke, form-field, or input content
4. How the anonymous visitor key works
On first page view, the tracking script generates a random identifier using the browser’s native crypto.randomUUID() and stores it in sessionStorage — not a cookie — scoped to that browser tab. It is cleared automatically when the tab is closed and is never synced across devices, domains, or sessions. Before this identifier ever reaches our servers, the collection API hashes it with SHA-256; we store only the resulting one-way hash, never the raw value transmitted by the browser. This lets us count returning visits within a single browsing session without recognizing the same person again later or across sites.
5. IP addresses
Your device’s IP address is visible to our infrastructure at the network level, the same way it is for any web request, in order to route and deliver the request. It is not written into the analytics database, is not attached to any event or visitor record, and is not used to compute location or any other stored field. Standard hosting and network-security logs (e.g. for abuse prevention) may retain IP addresses transiently and separately from analytics data, for a short, limited period, consistent with our hosting provider’s security practices.
6. Where data is stored and processed
Deeplitic is built to run on infrastructure located in the European Union (EU/EEA). Our customers choose the specific hosting region and provider when they deploy Deeplitic; where Deeplitic itself operates the hosted service, data is processed and stored within the European Union (EU/EEA), and any transfer outside of it is subject to appropriate safeguards under Chapter V GDPR (such as Standard Contractual Clauses).
7. Legal basis for processing (GDPR)
Because Deeplitic does not use cookies or any equivalent tracking technology covered by Article 5(3) of the ePrivacy Directive, and does not build cross-visit or cross-site visitor profiles, our customers can typically rely on legitimate interest (GDPR Art. 6(1)(f)) as the legal basis for first-party, aggregate web analytics — measuring which pages and campaigns perform, without profiling identifiable individuals. Each customer remains responsible for assessing the correct legal basis for their own use and jurisdiction, and for their own site’s cookie or privacy notice if they use other tracking technology alongside Deeplitic.
8. Data retention
Raw event and page-view records, along with the hashed visitor and visit keys, are retained only for as long as needed to compute aggregated daily metrics, and are deleted or aggregated on a rolling basis thereafter. Aggregated daily metrics (pageviews, referrers, and page-level totals) contain no visitor-level identifiers and may be retained for longer to support historical reporting. Specific retention windows are configurable per customer workspace.
9. Your rights
Because analytics events are not tied to a persistent, re-identifiable visitor profile, Deeplitic generally has no reliable way to locate a specific individual’s data on request — this is a deliberate design choice, not a gap in rights. If you are a website visitor with a question about a specific site’s use of Deeplitic, please contact that site’s owner first. If you are a Deeplitic customer with account or billing data, you may request access, correction, export, or deletion of that data by contacting privacy@deeplitic.com.
10. Contact
Deeplitic
[Registered address required before publishing]
Email: privacy@deeplitic.com
You also have the right to lodge a complaint with your local data protection supervisory authority, or with [Supervisory authority required before publishing].
11. Changes to this policy
We will update the effective date above when this policy changes and, for material changes, will provide reasonable notice to customers before the change takes effect.