Skip to content
trackd.one

Privacy

Privacy & GDPR

What trackd.one collects, how visitors can opt out, how long data is kept — and what you should consider as an operator.

Principles

  • No cookies in the tracking script
  • Nothing stored on the device (no localStorage or sessionStorage)
  • No browser fingerprinting
  • IP addresses are never stored — only a hash with a salt deleted daily
  • Automatic deletion: raw records after max. 400 days, statistics according to plan

How it works technically: Privacy by design.

Counting visitors without cookies

We build a SHA-256 hash from the IP address, a secret key, a daily random salt and the website ID. Same visitor on the same day = same hash; the next day a new hash is created and the old salt is deleted. The IP address itself is not stored and cross-site tracking is impossible. In apps the SDKs use a random session id that lives in memory only.

Opt-out

  • Global Privacy Control (GPC) — the browser’s built-in privacy signal, on by default in Firefox, Brave and DuckDuckGo.
  • Do Not Track (DNT) — the classic browser setting; trackd.one honors it.
  • Site switch — your site (e.g. your consent banner) sets, before or after the script loads:
window.trackdOptOut = true   // false = measure again

Exclude specific pages with data-do-not-track="true" on the script tag. In apps offer setEnabled(false), which stops tracking and drops the queue.

Without cookies, without storage on the device and with pseudonymised data, trackd.one is designed for use on the basis of legitimate interest (Art. 6(1)(f) GDPR). Whether § 25 TDDDG (or Art. 5(3) ePrivacy) requires consent in an individual case is for you as the operator to assess. The script reads no device properties such as screen size or language. Not legal advice.

Apps

The app SDKs read device and app information on the device (e.g. app and OS version, screen size, language). Whether you need consent for this has to be assessed for your app.

Privacy policy & DPA

  • Mention trackd.one in your privacy policy (purpose: audience measurement; recipient: trackd.one as processor; storage in the EU).
  • The data processing agreement under Art. 28 GDPR is concluded at sign-up.
  • Information for your visitors is in part B of our privacy policy.

Storage & retention

Data is stored in a Cloudflare D1 database created with EU jurisdiction. Requests are processed in Cloudflare’s global network; Cloudflare, Inc. is certified under the EU-US Data Privacy Framework, and standard contractual clauses apply additionally. Expired data is deleted daily: raw records after at most 400 days, aggregated statistics after 6 months (Free), 3 years (Pro) or 5 years (Business); Enterprise custom up to 10 years.

Ready in minutes

Create a free account, add your website or app, copy the snippet.

Start for free