OriginStatLog inSign up

Privacy

Last updated 3 September 2026

PrivacyTermsData processingSecurity

This page has two audiences. If you landed here from a website that uses OriginStat, section 1 is about you. If you are an OriginStat customer, sections 2 onwards are about your account.

The short version. We set no cookies and never store an IP address or a user agent. The identifier that tells one visitor from another is a hash that is rebuilt from a secret every midnight UTC, so it cannot follow anybody into tomorrow, and it is different on every site. We do not sell data, we do not run ads, and we do not build profiles across our customers' sites.

1. If you visited a site that uses OriginStat

The site you visited embeds a script that sends us one small message per page view. That site's owner is the data controller and decides to use us; we act on their instructions.

What is sent

  • The page URL and the referring URL, including any campaign parameters in the link (such as utm_source).
  • The width of your browser window, and how long the page was open.
  • The name of an action, if the page's owner has marked a button as a goal.
  • Your country and region, and your browser, operating system and device type — all derived by our host from the connection and the user agent string.

What is never stored

Your IP address and your user agent string are used once, in memory, and never written down. They are combined with a site identifier, the current date and a secret we hold, then hashed. Only the first eight bytes of that hash are kept. That value is what distinguishes one visitor from another for the rest of the day, and because the date is part of the input, it is discarded and rebuilt at midnight UTC. It cannot be reversed into an address, it is not shared between two sites, and it does not survive the day.

Storage on your device

The script keeps a small record in the website's own localStorage — not a cookie, and never readable by any other site. It holds a counter and timestamp used to tell one visit from the next, and, where the site owner has enabled revenue attribution, a note of the source and campaign of your first visit so that a later purchase can be credited to it. It contains no name, no address and no account identifier. You can clear it at any time through your browser's site-data controls, and the script continues to work without it.

Depending on where you are, storing anything on your device may require the website's consent notice to mention it. That is a decision for the owner of the site you visited, not for us — but they can switch this storage off, and if they have, none of the above is written at all.

How long it is kept

Individual events are held for 90 days. After that only aggregates remain — counts by day, page, source, country and device — which contain nothing specific to any one visitor.

2. If you have an OriginStat account

We hold what running the account requires and nothing beyond it:

  • Your email address, and a password stored only as a PBKDF2-SHA256 hash at 600,000 iterations.
  • Your sites, their settings, and the analytics they collect.
  • Your plan, billing status and billing period.
  • If you turn on two-factor authentication, a shared secret and your recovery codes.
  • If you connect a payment provider to attribute revenue, the read-only key you gave us — encrypted with AES-GCM under a key held separately from everything else, and shown back to you only as a masked fragment.

For abuse limits we store a salted hash of the address a signup came from. As with visitor identifiers, the address itself is never written down.

3. Who else touches it

ProcessorWhat forWhere
CloudflareHosting, the database, and analytics storageGlobal edge network
ResendTransactional email — sign-in codes, alerts, summariesUnited States
PolarPayments, as merchant of recordUnited States

That is the whole list. We add no analytics of our own to your dashboard beyond OriginStat measuring its own marketing pages, we run no advertising trackers, and we share nothing with anyone not named above except where the law requires it.

4. Your rights

If you are in the UK, EU, or another jurisdiction with comparable law, you may ask for a copy of what we hold about you, ask us to correct or delete it, object to how we use it, or ask for it in portable form. Write to support@originstat.com and we will answer within 30 days.

For analytics data about a site you do not own, we are the processor and not the controller: we will pass your request to the site's owner, who is the one able to act on it.

Deleting your account removes your sites, their analytics and your connected credentials. Backups age out within 30 days.

5. Contact

The controller for account data is [[ LEGAL ENTITY ]], [[ REGISTERED ADDRESS ]]. Questions, requests and complaints go to support@originstat.com. If you are in the EU or UK you also have the right to complain to your local supervisory authority.

If this page changes in a way that affects you, we will say so by email before it takes effect.

© 2026 OriginStatPrivacyTermsData processingSecurity