Privacy by design
How trackd.one works — verifiably
No promises, just facts: exactly what is sent, how counting works, when data is deleted — and how to check it yourself in your browser.
What the script sends
Exactly one request per pageview. The script reads no device properties such as screen size or language; language and device type are derived by the server from the request headers that are sent anyway.
POST https://trackd.one/api/collect
Content-Type: text/plain (no cookies: credentials "omit")
{
"type": "pageview",
"website_id": "8f0c…",
"url": "https://example.com/pricing?utm_source=newsletter",
"referrer": "https://www.google.com/",
"title": "Pricing",
"utm_source": "newsletter"
}- Query parameters with sensitive names (e.g. token, email, password) are removed before sending, email addresses in URLs are replaced with [email].
- Of the URL only the path and utm_* parameters are stored; of the referrer only origin and path.
- Optional and only if you enable it: Web Vitals (≈ 1.5 KB module) and click positions for heatmaps.
How visitors are counted
We build a SHA-256 hash from the IP address, a secret key, a random salt that changes daily and the website ID. Same visitor on the same day = same hash; the next day produces a new hash and the old salt is deleted. The IP address itself is not stored, and cross-site tracking is not possible. In apps, the SDKs use a random session ID that is kept in memory only.
What is never stored
- IP addresses (only the salted daily hash)
- Cookies, localStorage, sessionStorage — nothing is stored on the device
- The full user agent (only browser and OS family)
- Fingerprinting signals such as canvas, WebGL or fonts
- Cross-site identifiers — the same visitor has two different hashes on two websites
No canvas, no WebGL, no font detection. From the user agent we only derive the browser and OS family — the string itself is neither stored nor used to recognise visitors.
How long data is kept
Expired data is deleted automatically every day: individual records after at most 400 days, aggregated statistics after 6 months (Free), 3 years (Pro) or 5 years (Business), depending on your plan; Enterprise individually up to 10 years.
Where data is stored
In a Cloudflare D1 database created with EU jurisdiction — data is stored in the EU. Requests are processed in Cloudflare's global network; Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework, and standard contractual clauses apply in addition. Details are in the DPA.
Opt-out for visitors
Visitors can opt out of tracking in three ways:
- Global Privacy Control (GPC) — The browser's built-in privacy signal. Enabled in Firefox, Brave, and DuckDuckGo by default.
- Do Not Track (DNT) — The classic browser setting. trackd.one respects it.
- Site switch — your page (e.g. your consent banner) sets, before or after the script loads:
<!-- exclude a page entirely -->
<script defer src="https://trackd.one/t.js" data-website="YOUR_WEBSITE_ID"
data-do-not-track="true"></script>
// e.g. from your consent banner, before or after loading
window.trackdOptOut = true // false = measure againVerify it yourself
- 1Open your browser’s developer tools on a website that uses trackd.one.
- 2"Network" tab: each pageview produces exactly one request to /api/collect. Its body matches the example above.
- 3"Application" / "Storage" tab: there is no trackd.one entry under cookies, local storage or session storage.
- 4The script itself is public: https://trackd.one/t.js — below 2 KB (gzip), no external dependencies.
Legal context
With no cookies, no storage on the device and pseudonymised data, trackd.one is designed for use based on legitimate interest (Art. 6(1)(f) GDPR). Whether Section 25 TDDDG (German ePrivacy law) or similar ePrivacy rules require consent in a specific case is for you as the operator to assess.
No cookies, nothing stored on the device, no device properties read (language and device type are derived on the server from request headers). According to the German DSK (guidance on digital services 2024) such audience measurement usually does not require consent; the EDPB interprets Art. 5(3) ePrivacy Directive more broadly. The assessment in the individual case is up to the operator — not legal advice. Does not apply to the app SDKs.
This does not automatically apply to the app SDKs:
Yes. SDKs for Android, iOS, Flutter and JavaScript capture screens and events in the same account — websites and apps share one event pool. Important: the app SDKs read device and app information on the device. Whether you need consent for this is something you have to check for your app.
Ready to respect your visitors?
Start for free — the Free plan works without payment details.