We measure pages, not people
This page explains what the Traqlyte tracker collects, what it deliberately cannot know about you, and how long we keep it. It applies to this website and to any site running our tracker.
What the tracker collects
When you visit a page running Traqlyte, our script records: the page path you viewed, the referring page, campaign tags in the URL (UTM parameters), page performance timings (how fast the page loaded and responded), basic page metadata (title, description, heading structure), and which links or buttons were clicked. Each browsing session gets a random identifier that expires after 30 minutes of inactivity and is never connected to a new one.
What it deliberately does not collect
- No names, email addresses, or account identities.
- No cookies. The short-lived session identifier lives in your browser's local storage and identifies a visit, not a person.
- No cross-site tracking, no fingerprinting, no advertising identifiers, and no data sales — to anyone, ever.
- No IP addresses stored with analytics data. IPs are used transiently for abuse prevention (rate limiting) and appear only in security logs.
Do Not Track is an off switch, not a suggestion
If your browser sends the Do Not Track signal or Global Privacy Control, the tracker loads and does nothing at all — no events, no session identifier, no requests. This is built into the script itself, not a server-side filter.
Why we cannot answer "delete my data" for visitors
Honestly, because we cannot find you. There is no name, account, or stable identifier in our analytics data that connects a person to their rows. GDPR anticipates exactly this situation: where processing does not require identifying anyone, a service is not obliged to collect extra identifying information just to service access or erasure requests (Article 11). Not knowing who you are is the point.
One nuance for our customers' sites: a customer may choose to connect experiment assignments to their own user identifiers (for example, their own customer IDs). Those identifiers are opaque to us, and that customer remains responsible for their meaning. Where such a link exists, per-identifier deletion is the customer's lever to pull, and we provide it to them.
How long we keep data
Aggregated statistics (daily counts, performance percentiles per test group) contain no personal data and are kept indefinitely — long-horizon comparison is the product. Raw event data is kept indefinitely by default; customers whose own compliance obligations require a shorter window can set a per-account retention period and we enforce it automatically.
Roles, plainly
On sites owned by our customers, the customer is the data controller and Traqlyte is a processor acting on their instructions. On this site, we are the controller — and we run the same tracker with the same rules described above, because we use our own product.
Questions
Write to privacy@traqlyte.ai. This page describes our practices in plain language and is not a substitute for a data processing agreement; customers who need a DPA should ask.