Legal
Privacy policy.
Last updated August 22, 2026. The short version: the default tracker sets no tracking cookies and builds no cross-site profiles. We never sell data or share it with advertisers. The details below explain what we process, where it lives, and how to request deletion.
Who we are
Revtrail ("we") provides cookieless, revenue-first web and app analytics. For questions about this policy or your data, email [email protected].
Two kinds of data
We handle two distinct data sets. (1) Visitor analytics: measurements the Revtrail snippet or SDK collects from our customers' websites and apps — here we act as a processor on the customer's behalf. (2) Account data: information you give us when you create a Revtrail account — here we act as the controller.
What the snippet collects
Page URL and path, hostname, referrer, UTM parameters, country (derived from the request, never stored as an IP), client type, device class, browser, and operating system family, plus custom events the site owner chooses to send. Verified payment providers can also send revenue amounts through signed server-to-server webhooks. The hostname is used to apply site exclusions and is not retained in the event store. The default daily mode places no visitor identifier in cookies or localStorage. A site owner may explicitly enable persistent anonymous identity, which stores a random site-scoped identifier in localStorage for retention reporting. There is no fingerprinting or cross-site identifier. Opting out removes that identifier and stores only the privacy preference.
How visitors are counted without cookies
In default daily mode, each pageview carries a visitor hash computed on our servers from the site, the visitor's IP address, and browser signature, mixed with a secret salt that rotates daily. The raw IP address is discarded immediately and never stored. The hash cannot link a visitor across days or sites and cannot be reversed into an identity. In optional persistent mode, the server hashes the random site-scoped browser identifier instead. Mobile apps may similarly supply a random app-scoped device identifier.
No direct identifiers by default
The snippet does not ask for names or email addresses, and customers must not place personal data inside custom event names or payloads. Revtrail processes the request IP only long enough to create the daily visitor hash and does not store the raw address. Revenue attribution joins verified payments to an anonymous visitor hash; card details never touch Revtrail.
Account data
When you sign up we store your email address, display name, and a salted hash of your password (never the password itself). The dashboard uses a session cookie strictly to keep you signed in — an essential cookie, not a tracking one. Billing is handled by Stripe; we store your subscription state and Stripe customer reference, and we never see your card number.
Where data lives and for how long
All data is stored in the United States: the application and its database run on Fly.io, and analytics events and aggregates live in Tinybird (AWS us-east). Raw analytics events are retained for 3 years and then deleted automatically. Deleting a site starts an audited purge. Revtrail keeps the site configuration until the raw-event purge succeeds, then removes its local configuration and dashboard snapshots.
Subprocessors
Fly.io (application hosting, USA), Tinybird (event storage and aggregation, USA), and Stripe (payments, USA). Each processes data solely to provide their part of the service. We will update this list before adding subprocessors.
What we never do
We never sell data, never share it with advertisers or data brokers, never build cross-site profiles, and never use your visitors' data for anything except showing you your own analytics.
GDPR and your rights
The default snippet sets no tracking cookies, stores no persistent visitor identifier, and keeps no cross-site profile. Optional persistent identity stores a random site-scoped identifier in localStorage, so site owners who enable it are responsible for appropriate disclosure, consent, and their own legal assessment. A browser opt-out removes that identifier and stores only the preference. Account holders can request access, correction, export, or deletion by emailing [email protected]. Contact that address if you need data-processing terms for your review.
Changes
If this policy changes materially we'll note it here with a new effective date and email account holders before the change takes effect.