Legal

Privacy Policy

Last updated: September 1, 2026

This policy explains what we collect, why, and how we protect it. Short version: very little data, and none of it used to track people.

1. Our Privacy-First Promise

Lumenlytic is built around a simple principle: count pageviews, not people. We do not set tracking cookies, do not run fingerprinting, do not store IP addresses in identifiable form, and do not build profiles of individual visitors. This is not a marketing claim — it is how the product is architected.

2. Information We Collect From You

When you create an account we collect your name, email address, and (when you add billing) payment details via our payment processor. We use this to operate your account, send service notices, and provide support. We do not sell or share your personal information.

3. Website Visitor Data

The tracking script collects anonymous, aggregate information about visitors to your Sites, including: page URLs, referrers, viewport and screen size, browser language, device type, and timing data (such as Core Web Vitals). We deliberately do not collect names, email addresses, or any other personal data from your visitors.

4. No Cookies, No Fingerprinting

The Lumenlytic script sets no cookies and uses no localStorage or similar persistent identifiers. Sessions are approximated anonymously in-memory and via a session token held only for the duration of the visit. As a result, we cannot, and do not, track individual users across sites or over time.

5. How We Use Data

We use analytics data to provide the Service to you — aggregated dashboards, reports, and exports for the Sites you register. We may use aggregate, non-identifying statistics to improve the Service.

6. Data Retention

Your dashboard history is aggregated analytics data, retained for the period of your plan. Raw events are kept only briefly for processing and are not tied to your plan.

  • Free: 30 days
  • Starter: 1 year
  • Growth: 1 year
  • Pro: 1 year
  • Business: 1 year

7. Data Processing & GDPR

Where you use Lumenlytic to measure traffic for websites that you operate, you act as the data controller of any personal data your visitors generate, and we act as a data processor. Our Data Processing Agreement forms part of these arrangements and is available here.

8. Hosting & Sub-processors

Our Service is hosted on infrastructure in the European Union by our infrastructure provider. We only engage sub-processors that provide a comparable level of data protection, and we keep a current list available on request.

9. Your Rights

Depending on your jurisdiction (including under the GDPR), you may have the right to access, correct, export, or delete your personal information, and to object to or restrict processing. To exercise these rights, email info@lumenlytic.com. We will respond within the time required by law.

10. Security

We apply industry-standard safeguards: encrypted connections (TLS), hashed credentials, scoped access controls, and regular security review. The ingest endpoint is rate-limited and filtered against bot traffic. No system is perfectly secure, but we take our responsibility seriously.

11. Data Deletion & Export

You can export your analytics data to CSV or JSON at any time, and you can delete a Site (and all of its data) from its settings. Deleting your account triggers deletion of your personal information and analytics data in accordance with our retention schedule.

12. Children's Privacy

The Service is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

13. Changes to This Policy

We may update this policy as the Service evolves. Material changes will be announced by email or in-product notice. The "Last updated" date at the top reflects the latest revision.

14. Contact

Privacy questions or data requests: info@lumenlytic.com.