GDPR
Last updated 18 June 2026
The EU General Data Protection Regulation (GDPR) sets rules for how organisations collect and process personal data. If you use Penny Metrics on a website that serves visitors in the European Economic Area, this page explains how our analytics approach fits those requirements and what you should do on your side.
This page is for information only and does not constitute legal advice. If you are unsure about your obligations, consult a qualified privacy lawyer.
Our role
When you install the Penny Metrics tracking script on your website, you decide what is measured and why. In GDPR terms, you are typically the data controller for your visitors' analytics data.
We provide the analytics platform and process data on your instructions. We are the data processor for that visitor analytics data. Our relationship is governed by our Terms & Conditions and Privacy Policy.
Privacy by design
Penny Metrics is built to collect only what you need for website analytics — nothing more.
- No cookies — The tracker does not set cookies or other persistent identifiers on visitors' devices, so it does not require a cookie consent banner for analytics storage.
- No raw IP storage — IP addresses are used only in memory to generate a daily visitor hash and are never written to our database.
- Daily-rotating hashes — Visitors are counted using a hash of a daily salt, your site, the IP address, and user agent. The salt changes every day, so visitors cannot be tracked across days.
- No cross-site tracking — Data from one site is never combined with data from another. We do not build advertising profiles.
- Bot filtering — Known crawlers and bots are detected and discarded.
- EU hosting — Analytics data is stored on infrastructure in Frankfurt, Germany.
- Forever retention, deletion on request — Your analytics data is kept for as long as your account exists, so you never lose history. Deletion is always in your hands: clear a site's data, remove imported data, or delete a site or your account — each takes effect immediately and permanently.
What data is processed
For each pageview or custom event, we process:
- Page path and UTM campaign parameters
- Referring website (self-referrals are discarded)
- Coarse device, browser, and operating system (parsed from the user agent)
- Country (from CDN geo headers, not precise location)
- A pseudonymous visitor hash and short-lived session identifier (up to 30 minutes of inactivity)
- Custom event names and properties you choose to send
We do not collect names, email addresses, or other directly identifying information through the tracker. You must not send personal data in custom events — this is prohibited by our Acceptable Use Policy.
Choosing a legal basis
As the controller, you must have a lawful basis under Article 6 GDPR to process visitor data. Many website owners rely on legitimate interest for privacy-friendly analytics that are strictly necessary to understand how their site is used, especially when cookies are not involved and data is minimised.
Whether legitimate interest is appropriate depends on your context — for example, the sensitivity of the pages you measure and the impact on visitors. Some organisations prefer to obtain consent. Penny Metrics does not force either approach; you remain responsible for the choice.
What you should do
To use Penny Metrics in a GDPR-conscious way, we recommend:
- Update your website privacy policy to mention that you use privacy-friendly analytics and describe what is collected.
- Document your legal basis for analytics processing.
- Do not send personal data in custom events or event properties.
- Review our Privacy Policy and Terms & Conditions.
- Respond to data subject requests relating to data you control. Because we do not store raw IP addresses or directly identifying visitor data, individual visitors generally cannot be identified from our analytics records.
Data subject rights
Visitors may contact you to exercise GDPR rights such as access, erasure, or objection. Because our analytics are pseudonymous and aggregated, it is usually not possible to look up a specific individual in your dashboard. If you receive a request you cannot fulfil from dashboard data alone, contact us and we will assist where we can.
Account holders can exercise their own rights regarding account data as described in our Privacy Policy.
International transfers
Analytics data is processed and stored in the European Union. If you access the Service from outside the EU, account-related data may also be processed by our service providers as described in our Privacy Policy.
Questions
For GDPR or data processing questions, email pennymetrics@vblinden.dev.