Este texto está disponível somente em inglês.
Última atualização em outubro 1, 2026
Effective date: October 1, 2026
Summary
- Two roles. For our customers' accounts and for visitors to privatusanalytics.com, Two Phase LLC is the controller. For the analytics our customers collect about their visitors, the customer is the controller and we are their processor.
- Visitors to our customers' websites: no cookies, no local storage and no fingerprinting. IP addresses and user agents are used in memory for a moment and never stored. Location is country only.
- Our own website uses the same cookieless analytics. Public pages set no cookies. Signing in sets strictly necessary cookies only.
- We do not sell or share personal information, and we don't use it for advertising.
- Data is stored and processed in the United States. You can download your account data or delete your account from Account settings, or email [email protected].
Who we are and our two roles
Privatus Analytics is operated by Two Phase LLC, a Wyoming limited liability company (“we”, “us”). This policy explains how we handle personal data.
- As a controller we decide how and why data is used for: our customers' accounts, workspaces, billing and support, our newsletter and emails, our programs, and visitors to privatusanalytics.com.
- As a processor (a “service provider” under the CCPA) we process analytics data on behalf of our customers, who decide which websites to measure and how. Our Data Processing Agreement governs that processing. The next section explains what it involves, so that visitors to our customers' sites know what happens to their data.
Visitors to our customers' websites
When you visit a website that uses Privatus Analytics, the site's owner is responsible for the analytics and you should read their privacy notice. Here is what our tracker and servers do.
- No cookies or device storage. The tracker sets no cookies and uses no localStorage, sessionStorage or IndexedDB, and no fingerprinting techniques. The only exception is an opt-out flag (
privatus_optout) saved in the site's own localStorage if you choose to opt out, so your choice is remembered. - IP address and user agent in memory only. Your browser sends these with every request. We use them only during that request, to filter bots and data-center traffic, to apply the site owner's exclusion rules, and to recognize a visit within one day. Then they are dropped. They are never written to our database, logs, queues or backups.
- Visits are recognized with a keyed hash of the site, IP address and user agent, made with a random salt that changes every day. The salt is held only in memory with an expiry and is never saved, so the hash can't be recalculated or linked across days. Stored visits get a random identifier that isn't derived from your data.
- Location is country only. The country comes from the country code our network provider, Cloudflare, adds to each request. We don't look up or store anything more precise, and we don't use your IP address for location.
- What is stored: the page (host and path, with query strings removed except campaign parameters and any the site allows, and with patterns that look like emails, tokens or long numbers scrubbed), the referring site, campaign (UTM) tags, browser and operating system family and major version, device type, a screen size range, browser language, country, time spent and scroll depth, and any custom events, properties, revenue, Web Vitals or click targets the site owner sends. Bots are counted in totals only.
- Privacy signals. The tracker honors Global Privacy Control by default, so a browser that sends it isn't counted. Site owners can also choose to honor Do Not Track.
- Retention is set by the site owner's plan: 6 months on the Free plan, and for as long as the customer subscribes on paid plans, unless the owner sets a shorter period or deletes the data.
Because we store nothing that identifies you, we usually can't find data about a particular visitor. If you have a request, contact the website's owner. We help our customers respond as the DPA describes.
Data we collect as a controller
| Data | Why we use it | Legal basis (GDPR) | How long we keep it |
|---|---|---|---|
| Account: name, email address, password (stored only as a one-way hash), preferences, time zone, two-factor secrets and backup codes (encrypted), passkeys (public keys only), and accounts you connect for sign-in (Google, GitHub or your company's SSO) | Creating and securing your account | Contract | Until you delete your account |
| Sign-in records: browser and operating system name, IP address and times of each signed-in session, plus the number of sign-ins and the time of your latest and previous sign-in on your account record (no IP address) | Showing your active sessions, security and fraud prevention | Legitimate interests (security) | Session records, including their IP addresses: while the session is active and 30 days after it ends. Sign-in count and times: until you delete your account |
| Audit log: who changed what in a workspace, with the member's IP address and any API token used | Security and accountability for workspace admins | Legitimate interests, contract | 30 days on Free and Pro, 1 year on Business, as agreed on Enterprise, and deleted with the workspace |
| Workspaces and content: workspace and site settings, members and invitations, goals, reports, dashboards, notes, API tokens (stored as a hash) and integrations you connect | Providing the Service | Contract | Until you delete them or the workspace |
| Billing: plan, billing email addresses, tax ID, Paddle customer and subscription references, and invoice records (number, amount, date) | Billing, tax and accounting | Contract, legal obligation | Invoice records as long as tax law requires, even after the workspace is deleted. The rest until the workspace is deleted |
| Support and contact messages: your name, email, company and message | Answering you and keeping a record of the conversation | Legitimate interests, contract | 24 months after you send the message, then deleted automatically. Ask us to delete them sooner at any time |
| Newsletter: your email address, how you joined and when you confirmed or unsubscribed | Sending the newsletter | Consent (double opt-in: nothing is stored until you confirm from our email) | Until you ask us to delete it. After you unsubscribe we keep the record only so we never email you again |
| Product and marketing emails to account holders: which emails we sent you, when, and whether they were opened or a link was clicked (times and counts only, with no IP address or device data) | Onboarding and product news, and stopping mail you don't read | Legitimate interests (existing customers), with a one-click unsubscribe in every email | Until you delete your account. An unsubscribed address is then kept only as a one-way hash so a new account with it isn't emailed |
| Email report recipients: an address a customer added to a scheduled report, whether it accepted the invite, and who sent the invite. If you decline or unsubscribe, a one-way hash of your address | Sending the report only to people who accepted it, and never inviting you again after you decline or unsubscribe | Consent (you accept the invite. Members of the customer's workspace are added without one), and legitimate interests for the hash | Unanswered invites: 14 days. Otherwise until the customer removes you or the report. The hash: until you ask for reports again |
| Waitlists: your email address and the list you joined | Telling you when the feature is ready | Consent | 24 months after you join, or 30 days after the feature launches, whichever comes first, then deleted automatically. Ask us to delete it sooner at any time |
| Discount and program applications: organization name, website, proof link, license and notes, and our review | Reviewing and applying discounts | Contract, legitimate interests | Until the workspace is deleted |
| Affiliate program: your application, referral code, website, payout method, Wise email address, commissions and payouts. For people who sign up through a referral link, only the fact that they were referred (no clicks, IP addresses or devices) | Running the program and paying commissions | Contract, legal obligation (accounting) | Until the affiliate's account is deleted. Referral records stay for commission history, without the referred person's account once it is deleted |
| AI assistant questions and answers | Answering your questions about your analytics | Contract | 30 days after the last message in a conversation. You can delete them sooner |
| Bing Webmaster Tools API key, if you connect Bing to a site (stored encrypted, never shown again) | Reading search performance for the site you choose, and nothing else | Contract | Until you disconnect Bing or replace the key. You can also revoke it in Bing Webmaster Tools at any time |
| Bot checks on our forms (Cloudflare Turnstile): your IP address and browser signals, processed by Cloudflare | Stopping spam and automated abuse on sign-up, sign-in, password reset, magic link, contact, newsletter, waitlist, status page and shared dashboard password forms | Legitimate interests (security) | We use only the pass or fail result and store nothing from the check |
We don't ask for sensitive data, and we don't make decisions about you based solely on automated processing that have legal or similarly significant effects.
Our own website
We measure privatusanalytics.com with Privatus Analytics itself, in the same cookieless way as our customers' sites. We use no third-party analytics, advertising pixels or social media trackers. Some pages load services from other companies only when you use them:
- Cloudflare Turnstile on sign-up, sign-in and other account forms, and on public forms once you start filling them in.
- Paddle checkout, on billing and payment pages only, which Paddle provides under its own privacy notice.
- Google, GitHub or your company's SSO provider, only if you choose to sign in with them.
Cookies
Public pages set no cookies for anonymous visitors, and the tracker sets no cookies. When you sign in, or open a page with a sign-in or account form, we set strictly necessary first-party cookies: the session cookie, a “remember me” cookie if you ask for it, a preference cookie for the site you last viewed, and a short-lived cookie after you enter a shared dashboard's password. The cookie statement lists each one.
Emails we send
- Service emails such as sign-in links, security alerts, invitations, reports you set up, usage notices and receipts. We send these as part of the Service.
- Email reports that a customer sets up for someone outside their team start with one invite. Nothing more is sent unless you accept. Declining or unsubscribing stops every customer from inviting you again, until you ask for reports again yourself.
- The newsletter, only after you confirm your address from the email we send.
- Product emails to account holders, such as onboarding tips. Each one says why you get it, carries our mailing address and has a one-click unsubscribe link. Unsubscribing stops them all, and only you can turn them back on. We record whether they are opened or clicked, with times and counts only.
AI assistant
If you use the in-app AI assistant, your question and the analytics results needed to answer it (aggregated figures such as page paths, sources and counts, never IP addresses) are sent to Anthropic, PBC, which provides the model. Under Anthropic's commercial terms, API data is not used to train its models. We keep your conversations for 30 days after the last message. The MCP server works differently: it lets AI tools you choose read your data, and those tools are governed by their providers' terms.
Who we share data with
- Service providers who process data for us under contract: hosting (DigitalOcean), network and bot protection (Cloudflare), email delivery (Amazon Web Services), our mailbox for the email you exchange with us (Proton Mail, provided by Proton AG), error monitoring with request headers and tokens stripped (Sentry) and the AI assistant (Anthropic). Each is listed with its purpose and location on our subprocessors page.
- Our accountant and professional advisors, such as lawyers, who see personal data only when their work for us needs it, for example invoice records for bookkeeping, and who must keep it confidential.
- Paddle, our merchant of record, sells you your subscription and handles your payment details as an independent controller. We never see your card number.
- Wise, if you are an affiliate paid through Wise, receives your Wise email address and the payout amount.
- Sign-in providers you choose (Google, GitHub or your company's identity provider).
- Authorities, only where the law requires it. We review each request, challenge overbroad ones and disclose as little as possible.
- A buyer of our business, under this policy, if we are ever sold or merged. We would tell you first.
We do not sell or share personal information, as those terms are defined in US state privacy laws, and we never use it for targeted advertising.
Where data is processed
We store and process data in the United States, including data about people in the EU, EEA, UK and Switzerland. For those transfers we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum and the Swiss amendments, and on the protections in this policy, above all that visitors' IP addresses and user agents are never stored. We are not currently certified under the EU-US Data Privacy Framework. If that changes, we will say so here. Our mailbox is hosted by Proton in Switzerland, which the European Commission recognizes as providing adequate protection for personal data.
Security
We use encryption in transit (HTTPS with HSTS), encrypted database connections, encryption of secrets such as two-factor keys and integration credentials, one-way hashing of passwords and API tokens, two-factor authentication and passkeys, rate limits on sign-in, role-based permissions, a workspace audit log, and least-privilege staff access. Our staff can view a workspace only while its owner has granted time-limited support access, and every view is logged in the workspace's audit log. No system is perfectly secure. If a breach affects your personal data, we will notify you and the authorities as the law requires, without undue delay. More is on our security page.
Your rights in the EEA, UK and Switzerland
You have the right to:
- access your personal data and get a copy,
- have inaccurate data corrected,
- have your data erased,
- restrict how we use it,
- receive it in a portable format,
- object to processing based on legitimate interests, and to direct marketing at any time,
- withdraw consent at any time, without affecting processing before you withdrew it,
- complain to your data protection authority, such as the one where you live or work. We'd appreciate the chance to help first.
Your rights in California and other US states
In the last 12 months we collected these categories of personal information about customers and our website's users: identifiers (name, email address, IP address), customer records (billing contacts and tax ID), commercial information (plans and purchases), internet activity (sign-in sessions, audit log entries and email engagement) and account login credentials. We collected them from you and from your use of the Service, for the purposes and periods in the table above, and disclosed them only to the service providers and advisors listed above for business purposes.
- We do not sell or share personal information, and we have not done so in the last 12 months.
- We use sensitive personal information (your login credentials) only to provide the Service and keep it secure, so no right to limit its use applies.
- You have the right to know what we collect and how we use it, and to access, correct and delete it, and to opt out of any sale, sharing or targeted advertising (which we don't do). We honor Global Privacy Control signals.
- We won't discriminate against you for using these rights.
- You can use an authorized agent. We may ask the agent for proof of authority and ask you to confirm your identity.
People in other US states with privacy laws, such as Colorado, Connecticut, Virginia and Utah, have similar rights, including the right to appeal a decision about a request. Email us to appeal.
How to use your rights
- Download a copy of everything we hold about you from Account settings. It is a JSON file with your profile, memberships, API tokens, sign-in sessions (with their IP addresses), connected accounts and integrations, the emails we sent you and their opens and clicks, your AI assistant conversations, discount applications you submitted, your affiliate records, and the contact messages, newsletter, waitlist, invitation and status page records for your email address. Export a workspace's analytics and content from the workspace itself.
- Delete your account from Account settings. It is removed at once, along with the workspaces you own, which are permanently deleted after 7 days.
- Unsubscribe from any marketing email with its link, or change your email settings in Account settings.
- For anything else, or if you don't have an account, email [email protected] or use the contact form with the Privacy topic.
We may need to confirm your identity, usually by replying from your account's email address. We respond within 30 days. If a request is complex and the law allows more time, we'll tell you why within those 30 days. Requests are free unless they are clearly unfounded or excessive.
Children
The Service is not directed at children under 16, and you must be 18 or older, or the age of legal majority where you live if that is higher, to create an account. We don't knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.
Changes to this policy
We'll post any changes here and update the effective date. If a change is material, we'll email account owners at least 30 days before it takes effect.
Contact
The controller is Two Phase LLC, a Wyoming limited liability company.
- Email: [email protected]
- Physical address: Two Phase LLC, 680 South Cache Street, Unit 100, Jackson, WY 83001, USA
- Mailing address: Two Phase LLC, PO Box 14672, Jackson, WY 83002, USA
- Or use our contact form and choose the Privacy topic.
We have not appointed a representative in the EU or the UK. If we appoint one, we will name them here.