Legal
Privacy Policy
Last updated 13 August 2026. This policy explains what Visitorly processes when you use our marketing site, dashboard, and tracker.
Visitorly (“we”, “us”) provides multi-site website analytics software. This policy covers visitors to our marketing pages, customers who create accounts, and end-users of sites that install the Visitorly tracker.
1. Who is responsible
The Visitorly platform operator who hosts this deployment is the controller for account and platform data. When you install our tracker on your website, you are typically the controller of your visitors’ analytics events; Visitorly processes that data on your behalf as a processor for the purpose of providing the product.
2. Data we collect
- Account data: name, email, phone (on plan requests), company, password hash, plan/subscription status.
- Site configuration: domains, site names, public tracker keys, integration settings (e.g. Clarity project ID; Google OAuth tokens encrypted at rest).
- Tracker / analytics events: page path, referrer, UTM parameters, approximate device/browser, language/timezone signals, anonymous visitor and session identifiers. We do not intentionally collect form field contents or payment card numbers via the tracker.
- Third-party metrics: if you connect Google Analytics, Search Console, or Clarity, we store synced metrics and connection metadata you authorize.
- Technical logs: IP addresses and request metadata may appear in hosting/provider logs (e.g. Vercel) for security and reliability.
3. How we use data
- Provide dashboards, Real-Time, Audience, Acquisition, and AI digests.
- Authenticate sessions (HTTP-only cookie) and enforce plan limits.
- Process subscription requests and admin approvals.
- Secure the service, prevent abuse, and debug outages.
- Improve product behavior using aggregated, non-identifying patterns where appropriate.
4. Legal bases (where applicable)
Depending on your jurisdiction, we rely on contract performance (providing the SaaS you requested), legitimate interests (security, product integrity), and/or consent where you or your site’s policies require it for analytics cookies/identifiers.
5. Sharing
We do not sell personal data. We share data only with:
- Infrastructure providers (hosting, database, email if configured).
- Integration providers you choose to connect (Google, Clarity, OpenRouter for AI).
- Authorities when required by law.
Customer analytics data is isolated per account. Platform administrators can access account and site metadata as needed to operate Visitorly.
6. Cookies
Visitorly uses an authentication cookie for signed-in users. The first-party tracker may set or read anonymous identifiers in the browser of your site’s visitors. See our Cookie Policy.
7. Retention
Account data is kept while your subscription is active and for a reasonable period afterward for disputes and legal compliance. Tracking events and daily metrics are retained according to the operator’s retention practice (typically aligned with plan needs). You may request deletion of your account data subject to legal holds.
8. Security
We use industry-standard measures including encrypted transport (HTTPS), hashed passwords, encrypted integration secrets where implemented, and access controls. No method of transmission or storage is 100% secure.
9. Your responsibilities
If you install Visitorly on a customer-facing website, you must provide an appropriate privacy notice and obtain any consents required in your region for analytics. You must not use Visitorly to collect sensitive personal data unlawfully.
10. International transfers
Data may be processed in regions where our hosting and database providers operate. Where required, appropriate transfer safeguards should be applied by the platform operator.
11. Contact
For privacy requests (access, correction, deletion), contact the Visitorly operator using the support email provided when your plan was approved, or the admin contact shown on your account communications.