Trace

Privacy policy

Last updated October 1, 2026

Trace is a web analytics service. This policy explains what we collect when you use Trace, and what the Trace tracking script collects about the visitors to websites that use it.

Two kinds of data

  • Account data is about you, our customer: who you are and how you use Trace. We are responsible for it.
  • Analytics data is about the visitors to your websites, collected by the tracking script you install. You decide what to collect and why; we process it on your behalf.

Account data

When you sign up and use Trace, we store:

  • your name, email address and password (stored as a hash, never in plain text);
  • your workspaces, websites, teammates and settings;
  • billing details. Payments are handled by our payment provider, which acts as merchant of record; we never see or store your full card number;
  • credentials for integrations you connect, such as a read-only Stripe key, stored encrypted.

We use this data to provide and bill for the service, keep it secure, and contact you about your account. We don't sell it.

Analytics data collected by the tracking script

For each pageview and event on a website using Trace, the script and our servers record:

  • the page URL, page title and referrer, including any UTM campaign parameters;
  • browser, operating system and device type, worked out from the user agent;
  • an approximate location (country, region and city), looked up from the IP address;
  • time on page and scroll depth;
  • custom events and properties the website owner chooses to send;
  • if the website owner turns it on, a session recording of the page, with text and elements masked as they configure.

IP addresses are not stored. We use them while handling a request to look up the location, apply the website owner's exclusion rules and, in privacy mode, compute a visitor ID, and then discard them.

Cookies and browser storage

The script sets a first-party cookie, df_visitor_id, so that returning visitors are counted once. It also keeps short-lived session state in the browser. It never sets third-party cookies and never tracks people across different websites. In privacy mode, visitor IDs are computed on our servers from a salted hash that changes every day, instead of from the cookie.

This website

This marketing website may itself use Trace to measure visits, under the same rules as above. It sets no advertising cookies.

Where data is stored and who processes it

Data is stored with our cloud hosting provider. We use a small number of service providers to run Trace: hosting, email delivery and payment processing. They may only process data to provide their service to us.

How long we keep data

  • Account data is kept while your account is open, and deleted when you delete your account.
  • Analytics data is kept until the website owner deletes it or deletes the website.
  • Session recordings are deleted automatically after 30 days.

Your rights

You can access, correct or delete your account data from your account settings, or by contacting us at [email protected]. If you visited a website that uses Trace and want to exercise your rights over the analytics data, contact that website's owner. They can delete an identified user's data from their dashboard.

Changes

If we make significant changes to this policy we'll tell customers by email before they take effect. The date at the top shows when it last changed.

Contact

Questions about this policy: [email protected].