Privacy policy
Updated August 28, 2026
1. In brief
Metrimato is an analytics service designed so that no register of personal data comes into being about the visitors of tracked sites. We set no cookies, store no IP addresses and build no browser fingerprint.
2. What is collected about site visitors
The following is stored for every event:
- the page path without query parameters (except UTM campaign parameters)
- the referring site's domain, never the full URL
- the traffic channel (direct, search, social, referral, campaign, email)
- browser and its major version, operating system, device type, screen size class
- country code from the CDN header and the browser's language setting
- timestamp, time spent on the page and scroll depth as a percentage
- the per-day visitor hash (see section 3)
If the site uses its own search, we store the typed search term lowercased and at most 80 characters long. The term belongs to a visit, not to a person, and the site owner can turn search tracking off in the site settings or on the tracking snippet. We advise against collecting search on sites where sensitive information gets typed into the search box.
We do not store the IP address, the user agent string, cookies, device ids, precise location or anything that could identify a visitor.
3. How the visitor hash is formed
So that pageviews can be joined into a single visit, an irreversible hash is computed from them. The original details cannot be computed back from it.
The random value behind the hash changes daily, and old values are deleted within two days. After that the hash cannot be recomputed or joined to anything. The hash is per site, so data from different sites cannot be combined.
4. Roles
The site owner (our customer) decides on taking tracking into use. Because the collected data is not personal data, Metrimato does not process personal data about visitors. For the customer's own user details (name, email, password hash, sessions) Metrimato is the controller.
5. Retention periods
- Event and visit data: the period the customer chooses, at most what the plan allows (6–36 months)
- Daily random values: 2 days
- Sign-in sessions: 30 days from last use
- The customer's user details: for as long as the account exists
Expired data is deleted by an automatic nightly job.
6. Security
- All traffic is encrypted (HSTS, HTTPS only)
- A strict Content Security Policy, no third-party resources
- Passwords are stored encrypted, sessions in signed cookies
- Rate limiting and strict input validation on the API
- Servers and backups in the EU
7. Your rights
As a customer you can export your account's data in machine-readable form and delete the account with all of its data at any time in account settings. For visitors, requests cannot be targeted, because the data cannot be tied to a person.
8. Contact
Privacy matters: [email protected]