Analytics by Webtions

Privacy Policy

Last updated: 16 September 2026

This Privacy Policy explains how Webtions OU (“we”, “us”) processes personal data when you use Analytics at https://dash.webtions.com (the “Service”). We are established in Estonia and process data in line with the EU General Data Protection Regulation (GDPR) where it applies.

1. Who is the controller?

Webtions OU, Sepapaja 6, Tallinn 15551, Estonia. VAT EE102051737. Contact: mail@webtions.com.

If you are a site owner using the Service on your own websites, you are typically the controller of visitor analytics for those sites. We act as your processor for that visitor data. We are the controller of dashboard account data (login, billing contact details you give us, and Service administration).

2. What the Service does

Analytics is a privacy-first web analytics product hosted on Cloudflare. Site owners install a small tracker script. The Service records aggregated usage for sites they manage, shows dashboards, optional Search Console metrics, optional uptime checks, and optional email digests.

3. Data we process

A. Website visitors (sites that use the tracker)

  • No tracking cookies and no persistent device identifiers from us.
  • IP addresses are not stored. For each hit we briefly use the IP in memory (with user-agent and a daily rotating salt) to create a one-way visitor hash, then discard the IP.
  • We store path/hostname (with common PII query parameters scrubbed), referrer host, approximate location from the Cloudflare edge (country / region / city), language, screen size, device type, browser, and OS.
  • Custom events and goals you configure (event name and limited parameters).
  • After aggregation, raw hits are archived without region/city detail as designed for privacy.

Lawful basis when we are processor: your instructions as site owner (Art. 28 GDPR). When we are controller for our own product analytics on webtions.com properties: legitimate interests in understanding our sites, balanced against visitor rights (Art. 6(1)(f)).

B. Dashboard users (accounts)

  • Name, email, password (stored as a bcrypt hash), admin/assignment roles, optional TOTP two-factor secret.
  • Session cookies signed with a server secret so you stay logged in.
  • Sites you add (name, domain, timezone, ignored IPs), share links, goals, and any extra report-email addresses you enter. Weekly and monthly report emails are on unless you turn them off for a site.
  • If you connect Google Search Console: OAuth tokens encrypted at rest, property URL, and sync status. Google also processes data under its policies when you authorize the connection.
  • Login security signals (failed attempts / lockout) and optional push alerts via Trigv if configured.

Lawful basis: contract / steps prior to contract (Art. 6(1)(b)), and legitimate interests in securing the Service (Art. 6(1)(f)).

C. Uptime and email

  • If you enable uptime monitoring, we periodically request your site’s public homepage to check availability. We store check results and a 30-day availability figure, and we may email assigned users on confirmed down or recover events.
  • Weekly and monthly report emails, and uptime alerts, are sent through Cloudflare Email Sending from an address on our domain (for example analytics@webtions.com).

4. Processors and subprocessors

  • Cloudflare, Inc. — Workers, D1 database, KV, edge network, Email Sending, and request geolocation. Data is processed on Cloudflare’s global edge and storage regions configured for our account.
  • Google LLC — only if you connect Search Console (OAuth and Search Console API). See Google’s Privacy Policy.
  • Trigv (optional) — push notifications for login/security events if an API key is configured.

5. Cookies

The public tracker does not set cookies. The dashboard uses essential cookies for session authentication and CSRF protection. “Keep me signed in” extends the session cookie lifetime (up to 30 days).

6. Retention

Aggregated analytics and archived logs are kept while your site remains on the Service, unless a retention setting or deletion removes them. Daily visitor-hash salts expire so older hashes cannot be re-derived. Account data is kept while the account exists; you may ask us to delete it. Search Console tokens are removed when you disconnect.

7. Sharing

We do not sell personal data. We share data with processors above to run the Service, or when required by law. Share links you create expose analytics views to anyone with the link — treat them as secrets.

8. International transfers

Cloudflare and Google may process data outside the EEA. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses offered by those providers.

9. Your rights

Under GDPR you may request access, rectification, erasure, restriction, portability, and objection where applicable. Contact mail@webtions.com. You may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.

10. Children

The Service is not directed at children under 16. We do not knowingly create dashboard accounts for them.

11. Changes

We may update this policy. The “Last updated” date above will change. Material changes may also be noted in the product or by email to account holders.

12. Contact

Webtions OU, Sepapaja 6, Tallinn 15551, Estonia. mail@webtions.com. Web: https://webtions.com.

Privacy Policy Terms of Service Sign in

© 2026 Webtions OU · Sepapaja 6, Tallinn 15551, Estonia · VAT EE102051737

mail@webtions.com · https://webtions.com