Privacy Policy
This policy consists of three parts.
- Part I: data about StatJolt users. Here I am the data controller.
- Part II: data about visitors of measured websites. Here the user is the controller and I act as a processor.
- Part III: the processing terms, that is, the agreement under Article 28 GDPR.
The controller
I run StatJolt as a private individual. My details:
- Name: Liktor Gábor
- Address: 1173 Bp. Tabán u. 2-8.B. II/8.
- Email: on the contact page
I have not appointed a data protection officer. You can contact me directly about any privacy matter.
Part I: your account data
What I hold about the account
- Email address. For login, identification and system messages. Legal basis: performance of the contract (Article 6(1)(b) GDPR).
- Password. I do not store the password itself, only its bcrypt hash, from which the original cannot be recovered. Legal basis: performance of the contract.
- Account settings: language, email notification preferences. Legal basis: performance of the contract.
- Data about the measured websites: domain, name, time zone, badge settings, goals, funnels, custom labels, share links. Legal basis: performance of the contract.
- Messages and email addresses sent through the contact page. Legal basis: legitimate interest (Article 6(1)(f) GDPR) in answering the enquiry.
Cookies and browser storage on statjolt.com
- Login session. A strictly necessary cookie that keeps you signed in. It ends when you log out or close the browser.
- Password protected shared view. A 24 hour session cookie that opens the view after the correct password is entered.
- Interface preferences. Dark or light mode and the collapsed state of the navigation live in your browser's localStorage. This is not a cookie, it never leaves your machine and it never reaches me.
- There are no third party scripts, no advertising or social media pixels and no cookie banner.
- I measure traffic on statjolt.com with my own StatJolt snippet, under exactly the rules described in Part II.
Part II: what StatJolt measures on websites
Three principles
- Raw IP addresses never reach the disk. They are not written to a database and not written to a log file. They exist only in memory while the request is processed, then they are gone. Access logging on the web server is switched off so they do not end up there either.
- The visitor identifier is a daily hash. The formula is SHA-256 (IP address + that day's random salt). The salt is replaced every midnight. Yesterday's hash can neither be reversed nor matched to today's. Tracking across days or across websites is therefore technically impossible.
- No cookies and no fingerprinting. The measurement uses no cookies, reads no device characteristics to build a fingerprint and creates no visitor profile.
There is more on why this means the end of the cookie banner in analytics without a cookie banner.
What is stored in the browser
The snippet stores exactly one thing in the visitor's browser: a random session identifier in sessionStorage. It is deleted when the browser tab closes, it contains no personal data and it cannot be read from another website. If sessionStorage is disabled, measurement continues without it.
What is recorded per event
- event type, name and timestamp
- the page path without query parameters and the page title
- the referrer and its domain
- UTM parameters: source, medium, campaign, content, term
- country, region and city
- browser and version, operating system and version, device type
- the browser language as two characters and the screen width
- Core Web Vitals: LCP, INP, CLS, FCP, TTFB
- JavaScript errors: message, file, line, stack trace
- automatically detected events: form submit, incomplete form, outbound link click, file download, scroll depth
- custom events: name, category, label, value, currency
- the session identifier and the daily visitor hash
Location data comes from the MaxMind GeoLite2 database downloaded to the server and used locally, offline. The IP address does not leave the server and never reaches MaxMind. This product includes GeoLite2 data created by MaxMind, available from maxmind.com.
What is not recorded
IP addresses, cookie identifiers, device fingerprints, mouse movement, keystrokes, session recordings, form field contents, usernames, email addresses. I build no visitor profiles, use no data for advertising and sell nothing to anyone.
What website owners need to watch out for
Page paths, page titles, form and button labels, custom event labels and JavaScript error messages can contain text that you put there. If personal data ends up in them, for example an email address in a URL or a customer name in an error message, it will end up in StatJolt too. This is why the Terms of Service forbid sending personal data in these fields.
If you are preparing for a privacy audit, this walks through what the auditor asks: privacy audit and analytics risk.
Legal basis for visitor data
On the measured website you are the controller so it is for you to determine the legal basis and state it in your own privacy policy. For cookie-free measurement that cannot identify a person, legitimate interest (Article 6(1)(f) GDPR) is typically applicable.
StatJolt uses no cookies and creates a single sessionStorage entry for the lifetime of the tab. Whether that requires consent in your jurisdiction is for you to assess.
There is more on the rulings around Google Analytics and where things stand today in Google Analytics and the GDPR.
Who has access to the data
I do not sell your data and I do not pass it to anyone for their own purposes. The following providers store or transmit it in order to run the Service:
- Hetzner Online GmbH (Németország és Finnország): provides the server the Service runs on. All data is stored here, inside the European Union.
- AhaSend B.V. (Hollandia): delivers outgoing email, such as password delivery and notifications. Only the recipient's email address and the content of the message reach them, no measurement data.
- Authorities, where the law obliges me to disclose data.
Nobody else has access. There is no advertising network, no analytics partner and no data selling. The servers are inside the European Union and beyond the above there is no transfer outside the EEA.
How long data is kept
- Account data: until the account is deleted. Deletion can be started at any time in the account settings.
- Measurement data: for as long as the account and the website exist. There is no automatic expiry. If you delete a website or the account, the related statistics are deleted with it.
- The daily salt: replaced at midnight, the old one is not kept.
- Transient data: the list of currently active visitors clears itself after 5 minutes, the processing queue within seconds.
- Server logs: only error level entries are written, rotated every 10 MB. No access log is kept.
- Contact correspondence: for at most three months after the matter is closed.
How data is protected
- Every connection is encrypted, with Let's Encrypt certificates.
- Passwords are stored as bcrypt hashes.
- The databases are not reachable from outside: the analytics database only from the server's internal loopback, the cache only through a local socket.
- A firewall runs on the server, with only the necessary ports open.
- Raw IP addresses are not stored.
Your rights
You may request access to the data concerning you, its rectification or erasure, restriction of processing, a portable copy of your data and you may object to processing based on legitimate interest.
Write to the address on the contact page. I answer free of charge, within 30 days at the latest.
One important limit: for visitor data, the daily hash means I cannot tell which row belongs to which person. Under Article 11 GDPR, if the controller cannot identify the data subject, access and erasure requests cannot be fulfilled and I will not ask you for further identifying data either. If you want to exercise your rights as a visitor of a measured website, please contact the operator of that website, because they are the controller.
You may lodge a complaint with the supervisory authority:
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Falk Miksa utca 9-11, 1055 Budapest, Hungary
- Postal address: 1363 Budapest, Pf. 9, Hungary
- ugyfelszolgalat@naih.hu, naih.hu
You may also go to court or to the supervisory authority of your own country of residence.
Part III: processing terms
This section is the data processing agreement between me and the user under Article 28 GDPR. It takes effect on registration, without a separate signature. In this relationship the user is the controller and I am the processor.
- Subject matter and duration: processing visitor data of the measured websites, for as long as the user contract is in force.
- Nature and purpose: web analytics, that is, collecting, storing and presenting visitor events in aggregated form on the user's dashboard.
- Categories of data subjects: visitors of the measured websites.
- Categories of data: those listed in Part II.
- Instructions: I process the data solely on the controller's instructions and for the purpose of providing the Service. If I consider an instruction unlawful, I will say so and will not carry it out.
- Confidentiality: nobody else has access to the data. I am bound by confidentiality, which survives the end of the contract.
- Security: I apply the security measures described above.
- Sub-processors: those listed above, under a general authorisation. If I add or replace one, I will notify you in advance by email and in the interface. You may object, in which case you may terminate the contract.
- Assistance: I help within reason with data subject requests and with data protection impact assessments. The identification limit caused by the daily hash applies here too.
- Personal data breach: I notify you by email without undue delay and provide the information needed for your own notification.
- Fate of the data at the end: measurement data is deleted when the contract ends. I keep no copies, unless the law requires it.
- Audit: on request I provide written information about the processing and allow inspection within reason.
Changes to this policy
If this policy changes, I update it here and change the effective date. I will also notify you by email of any material change. This document is available in several languages. In case of any discrepancy, the Hungarian text prevails.
Cseréld le a GA4-et 2 perc alatt
Elég bemásolnod a kódot és látni fogod, mennyivel áttekinthetőbb. Nincs süti, nincs süti-kezelő. 0 Ft-ért 2027-ig, bármekkora forgalommal. Utána is 0 Ft marad a kis forgalmú oldalaknak.
Kérem az ingyenes fiókom