Privacy policy

Last updated 1 August 2026

VisitWatch does not set cookies, does not store anything on a visitor's device and does not build profiles of individual people. Visitors are counted with a key that rotates every day and cannot be reversed.

Our role

For data about your website's visitors, you are the controller and VisitWatch is the processor. You decide which sites are measured and why. We process that data only to produce the reports in your workspace.

For your own account data, VisitWatch is the controller.

What we collect from your visitors

For each pageview we record a small, fixed set of fields. There is no free-form collection and no way to attach your own personal data to a pageview.

  • The page URL, without query strings unless they are campaign parameters
  • The referring source, and UTM parameters when present
  • An approximate country, derived from the IP address and then discarded
  • Device type, operating system and browser
  • A timestamp
  • Custom events you choose to send

How visitors are counted

Rather than storing an identifier on the device, we derive a key from request properties combined with a salt that rotates every 24 hours. Old salts are destroyed, so the key cannot be reversed and cannot be joined across days, across websites or across devices.

This is why retention and returning visitor figures are measured at the level of a group rather than a person, and why no per person history exists to browse or export.

Cookies

VisitWatch sets no cookies on the sites it measures and writes nothing to local storage. Storing something on the device is the most common trigger for a consent requirement, but whether one applies to you depends on your jurisdiction and on everything else running on your site. We cannot make that determination for you; confirm it with a qualified advisor.

The VisitWatch application itself uses a strictly necessary cookie to keep you signed in.

What we collect from you

When you create a workspace we store your name, email address, the websites you add and your plan. If you subscribe, our payment provider handles card details and we never receive them.

Legal basis

We process account data to perform our contract with you, and to meet legal obligations such as tax records. Analytics data is processed on your instructions as the controller, under the terms of this policy and our agreement with you.

Sub-processors

We use a small number of providers for hosting, payments and transactional email. Each is bound by a data processing agreement. The current list is available on request, and we will announce changes before they take effect.

How long we keep it

Aggregated reporting data is retained for the window included in your plan. Account data is deleted within 30 days of a workspace being closed. Backups are rotated on a shorter cycle.

International transfers

Where data is processed outside the region it was collected in, we rely on the appropriate safeguards for that transfer, including standard contractual clauses with our providers.

Your rights

You can export or delete your workspace data at any time from settings. For access, correction, deletion or objection requests relating to your account, contact privacy@visitwatch.com.

Because visitor data cannot be linked to an identified person, we are generally unable to locate records about an individual visitor, and there is nothing to disclose or erase for them.

Security

Data is encrypted in transit and at rest. Access to production systems is limited to the people who need it and is logged.

Changes to this policy

We will update this page when our practices change, and will email workspace owners before any material change takes effect.

Contact

Questions about this policy can be sent to privacy@visitwatch.com.