Skip to content
All documentation pages

Your data

Privacy and data collection

Every statement on this page describes how the tracker and the collector behave today.

Nothing on the visitor’s device

The tracker sets no cookies and uses no localStorage, sessionStorage or IndexedDB. The build fails if any bundle mentions one of them.

How visitors are counted

Visitors are worked out on the server. For each request the collector computes a keyed hash of your project, the visitor’s IP address and their browser’s user agent, with a secret that changes every half-year (1 January to 30 June and 1 July to 31 December, UTC). The hash cannot be reversed. Each half-year’s secret is deleted one day after that half-year ends, and from then on nobody can recompute those hashes.

The same person on the same browser and network counts as one visitor for the whole half-year. A new browser, device or network gives a different visitor, and so does a return in the next half-year. A session ends after 30 minutes without activity.

Visits cannot be linked to a named person. The tracker collects no name, email address, account id or device identifier. Within a half-year, visits from the same browser and network share one visitor id. Once that half-year’s secret is deleted, nobody, including us, can recompute those ids or match them to visits in another half-year.

IP addresses are never stored

The address is used in memory to compute the half-year’s hash and to look up the country, region and city in a copy of the DB-IP geolocation database that runs inside the collector. Then it is discarded. No database column holds an IP address.

Do Not Track and Global Privacy Control

A browser that sends either signal sends nothing at all: the tracker checks before recording anything. The collector checks the request headers again and discards anything that still arrives.

Page addresses and referrers

The tracker sends each page address without anything after a #, without a user name or password, and without query parameters other than the utm_* campaign tags. Referrers are sent as origin and path only. The collector applies the same rule again before anything is stored, so an older copy of the tracker is covered too. Paths are kept as they are, so keep personal data such as email addresses out of them.

Masking in replays and page captures

Every form input is masked in the browser before anything is sent. Password and payment fields, and fields named like card numbers, security codes, national ID, passport, IBAN or date of birth numbers, are never captured. Images are never captured.

  • Add data-wm-mask or the class wm-mask to an element to mask its text.
  • Add the class wm-block to leave an element out entirely.
  • Add selectors in Data and privacy to mask them across the project, or list them in data-mask on one page.

Click labels

When a visitor clicks a button, link, tab, menu item, toggle or option, the tracker sends the kind of control and its label, so reports say Button “Start free” instead of a CSS selector. The label is the control’s aria-label, the text of a submit button, its visible text, its title or the alt text of an image inside it, cut to 80 characters.

A label is never taken from a form field or anything inside one, from an element that replays mask (the built-in rules, data-wm-mask, wm-mask, wm-block and your project’s and page’s selectors), or from a suggestion listed under a text field. No label is sent until your project’s mask list has loaded. Email addresses and runs of six or more digits are replaced with … in the browser, and again at the collector.

  • Add data-wm-no-label to an element to keep its label, and every label inside it, out of events.
  • Add data-click-labels="false" to the script tag to send clicks from that page without labels.

Session replay and page captures

Session replay runs on plans that include it. A page can turn it off with data-replay="false", or wait for consent with data-replay="consent". Recordings are kept for up to 30 days.

Heatmap page captures record the layout of a page with all of its text masked, along with readable attributes such as alt, title and placeholder, so clicks can be drawn over it without any of the words. Each page is captured once for each screen width and layout, on a single visit, for plans that include heatmap pages.

Excluding your own traffic

Add your office or VPN addresses, or CIDR ranges, in Data and privacy. The collector discards their events and does not count them towards your usage.

Bots

Known bots and crawlers are dropped at the collector. They never reach your reports or your usage.

Where data is stored

Events, sessions, recordings, page captures and account data are stored in the European Union. The subprocessors page lists each provider and its region.

The privacy policy and the data processing agreement set out who is responsible for what.