Last updated 3 September 2026
This page has two audiences. If you landed here from a website that uses OriginStat, section 1 is about you. If you are an OriginStat customer, sections 2 onwards are about your account.
The short version. We set no cookies and never store an IP address or a user agent. The identifier that tells one visitor from another is a hash that is rebuilt from a secret every midnight UTC, so it cannot follow anybody into tomorrow, and it is different on every site. We do not sell data, we do not run ads, and we do not build profiles across our customers' sites.
The site you visited embeds a script that sends us one small message per page view. That site's owner is the data controller and decides to use us; we act on their instructions.
utm_source).Your IP address and your user agent string are used once, in memory, and never written down. They are combined with a site identifier, the current date and a secret we hold, then hashed. Only the first eight bytes of that hash are kept. That value is what distinguishes one visitor from another for the rest of the day, and because the date is part of the input, it is discarded and rebuilt at midnight UTC. It cannot be reversed into an address, it is not shared between two sites, and it does not survive the day.
The script keeps a small record in the website's own localStorage — not a cookie, and never readable by any other site. It holds a counter and timestamp used to tell one visit from the next, and, where the site owner has enabled revenue attribution, a note of the source and campaign of your first visit so that a later purchase can be credited to it. It contains no name, no address and no account identifier. You can clear it at any time through your browser's site-data controls, and the script continues to work without it.
Depending on where you are, storing anything on your device may require the website's consent notice to mention it. That is a decision for the owner of the site you visited, not for us — but they can switch this storage off, and if they have, none of the above is written at all.
Individual events are held for 90 days. After that only aggregates remain — counts by day, page, source, country and device — which contain nothing specific to any one visitor.
We hold what running the account requires and nothing beyond it:
For abuse limits we store a salted hash of the address a signup came from. As with visitor identifiers, the address itself is never written down.
| Processor | What for | Where |
|---|---|---|
| Cloudflare | Hosting, the database, and analytics storage | Global edge network |
| Resend | Transactional email — sign-in codes, alerts, summaries | United States |
| Polar | Payments, as merchant of record | United States |
That is the whole list. We add no analytics of our own to your dashboard beyond OriginStat measuring its own marketing pages, we run no advertising trackers, and we share nothing with anyone not named above except where the law requires it.
If you are in the UK, EU, or another jurisdiction with comparable law, you may ask for a copy of what we hold about you, ask us to correct or delete it, object to how we use it, or ask for it in portable form. Write to support@originstat.com and we will answer within 30 days.
For analytics data about a site you do not own, we are the processor and not the controller: we will pass your request to the site's owner, who is the one able to act on it.
Deleting your account removes your sites, their analytics and your connected credentials. Backups age out within 30 days.
The controller for account data is [[ LEGAL ENTITY ]], [[ REGISTERED ADDRESS ]]. Questions, requests and complaints go to support@originstat.com. If you are in the EU or UK you also have the right to complain to your local supervisory authority.
If this page changes in a way that affects you, we will say so by email before it takes effect.