Privacy Policy
Last Updated September 15, 2026
Our analytics tracker uses browser storage instead of analytics cookies. Website owners can optionally identify users and send profile details. Databuddy account sign-in uses session cookies.
This policy explains how we collect, use, and protect information for both our customers and end users. We’re committed to privacy-first analytics that respects everyone’s privacy.
Databuddy ("we", "our", or "us") is a privacy-first analytics service that provides website insights without compromising user privacy. This Privacy Policy describes how we collect, use, and protect information when you use our service or visit websites that use our analytics.
Who This Policy Applies To
This privacy policy covers two groups of people:
- Customers: Individuals or organizations who sign up for and use Databuddy's analytics services for their websites.
- End Users: Visitors to websites that use Databuddy analytics. If you're visiting a website that uses our analytics, this policy explains what data we collect about you and how we protect your privacy.
Note: We are committed to privacy-first analytics that respects the rights of all users, whether they are our customers or visitors to websites using our service.
Our Privacy-First Principles
- Optional identification: Website owners choose whether to link activity to their own user IDs and profile details.
- Cookieless collection: The browser tracker uses first-party localStorage and sessionStorage for visitor and session information.
- Configurable visitor IDs: Ingestion salts and hashes visitor IDs by default. Website owners can change this behavior with the visitor-ID anonymization setting.
- Event-level analytics: We store individual events and session information to produce reports. Identified profiles may contain personal data supplied by the website owner.
- No data sales: We never sell or share user data with third parties for advertising or marketing purposes.
Information We Collect
From Our Customers (Website Owners)
When you sign up for Databuddy, we collect:
- Account information: Email address, name (optional), and password
- Billing information: Payment details, billing address, and contact information for subscriptions
- Website information: Domain names and website URLs you want to track
- Usage data: How you use our dashboard and analytics features
- Communications: Support requests, feedback, and survey responses
- Account security information: Session identifiers, IP addresses, and browser information
From End Users (Website Visitors)
Depending on the enabled features and information the website owner sends, we collect:
- Page addresses and titles, referrer addresses, and selected campaign and advertising-click parameters.
- Visitor and session IDs, timestamps, navigation activity, and enabled interaction measurements.
- Browser, operating system, device and viewport information, language, and time zone.
- Approximate country, region, and city derived from the request IP address.
- Custom events and properties, error messages and stack traces, and performance measurements.
- Profile IDs and optional names, email addresses, or other traits supplied through user identification.
The standard browser tracker removes query strings from page and referrer addresses, but collects selected attribution parameters separately. URL paths, page titles, custom properties, errors, and optional profile details can still contain personal information. Website owners should review what they send and use the available masking and filtering controls.
Cookieless Analytics and Browser Storage
The analytics tracker does not set analytics cookies. It stores a random visitor ID in localStorage and session information in sessionStorage. Advertising-click identifiers may also persist in localStorage. If the website identifies a user, the supplied profile ID is stored until cleared.
The tracker honors Global Privacy Control, Do Not Track, and its stored opt-out settings. Cookieless collection does not by itself determine whether consent is required; that depends on the configuration, collected information, and applicable rules.
How We Use Information
Customer Data Usage
We use customer information to:
- Provide and maintain our analytics service
- Process payments and manage subscriptions
- Send important service updates and security notifications
- Provide customer support and respond to inquiries
- Improve our service based on usage patterns
- Ensure compliance with legal obligations
End User Data Usage
We process visitor information to provide the features the website owner uses, including analytics reports, session and profile views, error tracking, performance monitoring, and AI-assisted analysis.
AI features send prompts and supporting context to the configured AI gateway and model providers. Connected delivery services receive the findings or messages the customer configures them to deliver. See our Data Policy for service-provider information.
Note: End user data is never used for advertising, marketing, or any purpose other than providing analytics insights to website owners.
GDPR and Privacy Rights
Legal Basis for Processing
Under GDPR, our legal basis for processing data is:
- Customer Data: Contractual necessity (to provide our service) and legitimate interests (service improvement)
- End User Data: The website owner determines the legal basis for collecting and using visitor information and is responsible for obtaining consent where required. Databuddy processes this information on the website owner’s behalf.
Your Rights (Customers)
As a customer, you have the right to:
- Access: Request copies of your personal data
- Rectification: Correct inaccurate information
- Erasure: Request deletion of your account and data
- Portability: Export your data in a machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interests
End User Rights
As an end user (website visitor), you have the right to:
- Information: Know what data is collected (detailed in this policy)
- Objection: Object to analytics tracking (use browser Do Not Track or ad blockers)
- Access, correction, and deletion: Contact the website owner about information collected through their website. We assist them with requests concerning data we process on their behalf. Whether a particular record can be located depends on the identifiers and information available.
Personal data does not lose its legal protections merely because an identifier is hashed or a visitor’s name is absent.
Data Security
Customer workspaces use authentication and permission controls. Standard analytics event records omit the raw IP address after it is used for request handling and approximate location. Visitor-ID anonymization, path masking, filtering, and opt-out controls help limit collection.
See our security documentation for configuration details and our Data Processing Agreement for our security and data-protection commitments.
Contact Us
If you have any questions about this Privacy Policy, want to exercise your privacy rights, or have concerns about how your data is handled, please contact us:
We typically respond to privacy inquiries within 24 hours, and will fulfill data subject requests within 30 days as required by GDPR.