Privacy Policy
This policy explains what data Trafnova collects, why, where it lives, and what you can do about it. It covers both visitors to trafnova.com and visitors to customer websites that load our tracker script.
1. Who we are
Trafnova ("we", "us", "the service") is an analytics service for website owners, operated by [OPERATOR_NAME], registered at [OPERATOR_ADDRESS]. Contact: [email protected].
For data we collect about visitors to our customers' websites (via the tracker snippet), we act as a data processor and the customer is the data controller. See our Data Processing Addendum for the Article 28 terms that govern that relationship.
For data we collect about our own customers (people who sign up for Trafnova accounts and visit trafnova.com), we act as the data controller. The rest of this policy is about that role.
2. What we collect about Trafnova customers
2.1 Account data
- Email address (required for sign-in via magic link)
- Optional: name, time zone, digest preferences
- If you sign in with Google OAuth: your Google email address and the OAuth refresh token used to read your Google Search Console properties (only when you explicitly connect GSC)
2.2 Billing data
When paid plans launch, billing is handled by Stripe, Inc. We store your Stripe customer ID and last-four of the payment method label; full card numbers never reach our servers.
2.3 Usage logs
Our hosting provider's web server logs include the IP address, user agent, and request path of every request to trafnova.com. These logs rotate automatically; we don't analyse or join them with account data.
3. What the tracker collects on customer websites
When a website loads our t.js snippet, we collect, per event:
- URL, path, hostname, referrer URL
- UTM parameters (source / medium / campaign / content / term)
- Browser, browser major version, OS, OS major version, device type, derived from the User-Agent string
- Country, region, and city, derived from the visitor IP via a local MaxMind GeoLite2 lookup
- An anonymous session identifier (a 16-character hash of visitor IP + User-Agent + site token, rotated daily) so we can count unique visitors without storing the IP
- Optional custom event names and properties the website passes via
tn('event', ...)
What the tracker does NOT collect
- No cookies (the tracker writes nothing to
document.cookie) - No raw IP address is stored — only used to derive geo and the session hash, then discarded at the end of the request
- No cross-site identifiers, no fingerprinting beyond the daily session hash, no advertising profiles
- We respect
navigator.doNotTrackandnavigator.webdriver, and visitors can opt their device out entirely vialocalStorage.tn_ignore(see Cookie Policy)
4. Why we collect it (lawful basis)
For Trafnova customer accounts: performance of the contract you sign up for (GDPR Art. 6(1)(b)) and our legitimate interest in operating a reliable service (Art. 6(1)(f)).
For tracker data on customer websites: the customer is responsible for identifying the lawful basis under their own privacy policy, since they are the controller. We process the data on their instructions as described in the DPA. Because no cookies are set and no personal identifiers are stored, most customers rely on legitimate interest without needing a consent banner — but you should check the rules in your jurisdiction.
5. Where data lives
Customer accounts, events, and aggregated stats live on servers located in the European Union. Daily database backups are stored on the same servers. We don't transfer personal data outside the EU/EEA except via the sub-processors listed below.
6. Sub-processors
We rely on the following third parties to deliver the service. Each one is bound by a written data processing agreement.
| Sub-processor | Purpose | Data shared | Region |
|---|---|---|---|
| Maileroo | Transactional email (magic links, digests, anomaly alerts) | Recipient email, subject line, body | EU |
| MaxMind | GeoLite2 database for IP → country/region/city lookup | None — DB is local, no live API calls | n/a |
| Anthropic (Claude API) | Generates the natural-language daily digest body | Pre-aggregated portfolio stats (totals, deltas, top pages). No personal data, no individual events. | US |
| Google (Search Console API) | Reads GSC data for sites the customer has explicitly connected | OAuth refresh token, queried site URL | US |
| Hosting provider | Server infrastructure (Caddy, Rails, Postgres, Solid Queue) | All of the above, encrypted at rest and in transit | EU |
When Stripe is added for paid plans we will update this table and notify active customers via email at least 30 days before any new sub-processor goes live.
7. How long we keep data
- Event data: retained for the lifetime of the site in the customer's Trafnova account. When the customer deletes the site, all of its events are deleted immediately.
- Customer accounts: retained while the account is active. Deletion within 30 days of cancellation.
- Web server access logs: rotated within 30 days.
- Transactional email metadata at Maileroo: per Maileroo's own retention (typically 30 days).
8. Your rights
If you have a Trafnova account you can access, export, correct, or delete your data at any time from the in-app settings, or by emailing [email protected]. We respond within 30 days.
If you are a visitor to a customer's website and want your tracker data removed, please contact the website owner first — they control retention on their analytics. We will assist on their instruction.
EU/EEA / UK residents also have the right to lodge a complaint with their national data protection authority.
9. Security
We use TLS for all HTTP traffic, encrypted backups, scoped service credentials, and isolation per project. The tracker runs first-party on customer domains where they configure a CNAME. We disclose security incidents that affect personal data within 72 hours, in line with GDPR Art. 33–34.
10. Changes
We will email active customers at least 14 days before any material change to this policy takes effect, with a summary of what changed and why. The current version always lives at trafnova.com/privacy.
11. Contact
Privacy questions: [email protected].
General contact: [email protected].
Postal: [OPERATOR_ADDRESS].