# Privacy and GDPR for cookieless analytics

> How Privatus Analytics measures without cookies or persistent identifiers, what happens to IP addresses, and what it means for GDPR and cookie banners.

> **Note:** This section explains how the product works and gives
> templates. It isn't legal advice. Your obligations depend on your
> jurisdiction and your other processing. Check with your own counsel.

## The data journey

1. **Browser:** the tracker sends one request per pageview or event with
   the page URL, referrer, screen width, language and the properties you
   choose. It reads and writes nothing on the device (except an
   [opt-out flag](/docs/tracker/opt-out) the visitor sets themselves) and
   uses no fingerprinting APIs.
2. **Ingest (US):** the request arrives at our US region with the
   visitor's IP address and User-Agent, as every HTTP request does. This
   is the same for every visitor, including visitors from the EU/EEA, the
   UK and Switzerland. In memory only, while the request is handled, the
   IP and User-Agent are used to:
   - check for bots,
   - compute the daily visit key
     `HMAC(daily salt, site, IP, User-Agent)`.

   The visitor's country comes from the `CF-IPCountry` header that our
   network provider, Cloudflare, adds to the request. Location is country
   only: no region, city or coordinates are collected.
3. **Minimization:** the URL is stripped of query parameters (except
   campaign parameters and your allowlist), the
   [PII scrubber](/docs/privacy/pii-scrubbing) redacts emails, ids and
   tokens, your [path masks](/docs/tracker/exclusions-and-masking) and
   [traffic rules](/docs/privacy/traffic-rules) apply, and the User-Agent
   is reduced to browser, OS and device type.
4. **Storage (US):** only the minimized event is stored. **The IP address,
   the raw User-Agent and the visit key are never written to disk, logs,
   queues or backups.**

## Key facts

| Question | Answer |
|---|---|
| Cookies or device storage? | None (only the visitor's own opt-out flag) |
| Persistent identifiers? | None. Visit ids are random and last at most one UTC day |
| Cross-site or cross-device tracking? | Impossible by design |
| IP addresses stored? | Never, not even for bots or security |
| Data sold or shared? | Never. Not used for advertising or model training |
| Where is data stored? | United States. See [Where data lives](/docs/privacy/where-data-lives) |
| Affiliate referrals? | Attributed without cookies or click logs. See [Affiliate program](/docs/billing/affiliates#how-referrals-are-attributed-privacy) |
| Can we re-identify a visitor? | Not from stored data: the daily salt that could link a visit to an IP is destroyed after the day |

We describe this data as **pseudonymous, heavily minimized** data, not as
"anonymous": for one day, a visit key could in theory be linked to an IP
by someone holding the salt. See
[How visitors are counted](/docs/metrics/how-visitors-are-counted).

## Do I need a cookie banner?

For Privatus Analytics alone, in most setups, no:

- **ePrivacy / PECR** consent rules cover storing or reading information
  on a device. The tracker does neither.
- **GDPR** still applies to the transient processing of IP addresses. Most
  customers rely on **legitimate interests** (Art. 6(1)(f)). Use our
  [LIA template](/docs/privacy/dpia-lia) to document it, and describe the
  processing in your privacy policy ([templates](/docs/privacy/policy-templates)).
- **US state laws** (CCPA/CPRA and others): we act as your service
  provider/processor, so there's no "sale" or "sharing" of personal
  information. We honour **Global Privacy Control** by default anyway.

Some regulators and some organizations take stricter views. The
[opt-out](/docs/tracker/opt-out) and [GPC/DNT handling](/docs/privacy/dnt-gpc)
exist for them.

## Our role

You're the **controller** of your visitors' data, and we're your
**processor**. Our Data Processing Agreement (with the EU Standard
Contractual Clauses and the UK addendum) is part of the Terms and is
published at [/legal/dpa](/legal/dpa), with the
[subprocessor list](/legal/subprocessors). The DPA includes our technical
and organizational measures.

## In this section

- [Data inventory](/docs/privacy/data-inventory): every stored field.
- [Where data lives](/docs/privacy/where-data-lives).
- [PII scrubbing](/docs/privacy/pii-scrubbing) and
  [traffic rules](/docs/privacy/traffic-rules).
- [DNT and GPC](/docs/privacy/dnt-gpc) and the [opt-out snippet](/docs/privacy/opt-out).
- [Privacy policy templates](/docs/privacy/policy-templates) in six
  languages.
- [DPIA and LIA templates](/docs/privacy/dpia-lia).
