Privacy Policy

Last updated: June 27, 2026

This document is a draft and a starting point. It must be reviewed by a qualified legal professional and have its placeholders completed before being relied upon.

1. Who we are & our two roles

Datyze is a privacy-first, cookieless-by-default web analytics service operated by [Legal entity name] ("Datyze", "we", "us"). Under the EU General Data Protection Regulation (GDPR), we act in two distinct capacities:

  • As a data controller — for the personal data of our own users (the people who create a Datyze account): your name, email, authentication and billing data. This policy governs that processing.
  • As a data processor — for the visitor data we collect on behalf of our customers, on the websites where they install Datyze. There, our customer is the controller and decides why the data is processed; we only act on their instructions. Those terms are set out in our Data Processing Agreement.

2. Information we collect

2.1 Account data (we are the controller)

  • Name and email address
  • Authentication data (password hash, or Google/GitHub OAuth identifiers)
  • Team and membership information
  • Billing data (processed by our payment provider — we do not store card numbers)

2.2 Visitor analytics data (we are the processor)

On our customers' websites, what we collect depends on the privacy mode the customer has chosen for that site:

  • Cookieless mode (default). No identifier is stored on the visitor's device. We derive a daily, rotating visitor hash on the server from a secret daily salt combined with the site, IP address and user-agent. The raw IP address is never stored — it is used only in transit for geolocation and rate-limiting. Geolocation is limited to country level. Page URL, referrer, device/browser type and UTM parameters may be recorded. Because the salt rotates daily and is then discarded, past hashes cannot be re-derived.
  • Full mode (consent-based). Only after a visitor grants consent through the Datyze banner do we set a persistent identifier (_datyze_id) in the visitor's browser, which unlocks multi-day journeys, returning-visitor recognition and identify(). City-level geolocation may then be recorded. Until consent is granted — and always under Do Not Track or Global Privacy Control — the site falls back to cookieless mode and nothing is stored on the device.

3. How we use your information

As a controller (account data), we use your information to:

  • Provide, maintain and secure the Service
  • Process subscriptions and send related billing information
  • Send administrative messages, updates and support responses
  • Detect, prevent and address fraud, abuse and technical issues
  • Improve the Service and develop new features

As a processor (visitor data), we only process the data to provide analytics to the customer who collected it, on their documented instructions.

We never sell personal data, and we do not use it for cross-site advertising.

4. Cookies & device storage

  • The Datyze dashboard uses a single strictly-necessary cookie to keep you signed in. We do not use advertising or third-party tracking cookies on our own site.
  • The Datyze analytics tracker stores nothing on a visitor's device in cookieless mode. In full mode it stores a consent flag and the persistent identifier _datyze_id only after the visitor has granted consent, and honours Do Not Track and Global Privacy Control signals.

5. Sharing & sub-processors

We share personal data only with the service providers needed to operate Datyze, each bound by a data processing agreement:

  • Hosting: [Hosting provider], on infrastructure located in the European Union (self-hosted via Coolify)
  • Billing: Lemon Squeezy (subscription payments)
  • Transactional email: Brevo
  • Revenue attribution (optional, customer-enabled): Stripe, via Stripe Connect, when a customer links their own payment account
  • Error monitoring (optional): Sentry
  • Authentication (optional): Google, GitHub (OAuth sign-in)

We may also disclose data when required by law, or in connection with a merger, acquisition or sale of assets. We do not sell your personal information to third parties.

6. Data security

  • Encryption of data in transit (TLS) and at rest
  • Access controls, authentication and least-privilege practices
  • The visitor IP address is never written to storage
  • Regular review of our security posture

7. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request erasure of your data
  • Object to or restrict processing
  • Data portability
  • Withdraw consent at any time
  • Lodge a complaint with your supervisory authority (in France, the CNIL)

To exercise these rights, contact us at contact@datyze.fr. If your request concerns visitor data collected on a customer's website, we will refer you to that customer (the controller) or act on their instructions.

8. Data retention

Visitor analytics data is retained for a default of 365 days, configurable per site by the customer, after which it is deleted. Account data is retained for as long as your account is active; when you delete your account we delete or anonymise your data within a reasonable timeframe, unless retention is required by law.

9. International data transfers

Datyze hosts data within the European Union. Where a sub-processor processes data outside the EU, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses).

10. Children's privacy

The Service is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, please contact us so we can remove it.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date above.

12. Contact

For any question about this policy or your data:

See also our Legal Notice, Terms of Service and Data Processing Agreement.