Legal
Privacy Policy
Last updated: September 1, 2026
This policy explains what we collect, why, and how we protect it. Short version: very little data, and none of it used to track people.
1. Our Privacy-First Promise
Lumenlytic is built around a simple principle: count pageviews, not people. We do not set tracking cookies, do not run fingerprinting, do not store IP addresses in identifiable form, and do not build profiles of individual visitors. This is not a marketing claim — it is how the product is architected.
2. Information We Collect From You
When you create an account we collect your name, email address, and (when you add billing) payment details via our payment processor. We use this to operate your account, send service notices, and provide support. We do not sell or share your personal information.
3. Website Visitor Data
The tracking script collects anonymous, aggregate information about visitors to your Sites, including: page URLs, referrers, viewport and screen size, browser language, device type, and timing data (such as Core Web Vitals). We deliberately do not collect names, email addresses, or any other personal data from your visitors.
4. No Cookies, No Fingerprinting
The Lumenlytic script sets no cookies and uses no localStorage or similar persistent identifiers. Sessions are approximated anonymously in-memory and via a session token held only for the duration of the visit. As a result, we cannot, and do not, track individual users across sites or over time.
5. How We Use Data
We use analytics data to provide the Service to you — aggregated dashboards, reports, and exports for the Sites you register. We may use aggregate, non-identifying statistics to improve the Service.
6. Data Retention
Your dashboard history is aggregated analytics data, retained for the period of your plan. Raw events are kept only briefly for processing and are not tied to your plan.
- Free: 30 days
- Starter: 1 year
- Growth: 1 year
- Pro: 1 year
- Business: 1 year
7. Data Processing & GDPR
Where you use Lumenlytic to measure traffic for websites that you operate, you act as the data controller of any personal data your visitors generate, and we act as a data processor. Our Data Processing Agreement forms part of these arrangements and is available here.
8. Hosting & Sub-processors
Our Service is hosted on infrastructure in the European Union by our infrastructure provider. We only engage sub-processors that provide a comparable level of data protection, and we keep a current list available on request.
9. Your Rights
Depending on your jurisdiction (including under the GDPR), you may have the right to access, correct, export, or delete your personal information, and to object to or restrict processing. To exercise these rights, email info@lumenlytic.com. We will respond within the time required by law.
10. Security
We apply industry-standard safeguards: encrypted connections (TLS), hashed credentials, scoped access controls, and regular security review. The ingest endpoint is rate-limited and filtered against bot traffic. No system is perfectly secure, but we take our responsibility seriously.
11. Data Deletion & Export
You can export your analytics data to CSV or JSON at any time, and you can delete a Site (and all of its data) from its settings. Deleting your account triggers deletion of your personal information and analytics data in accordance with our retention schedule.
12. Children's Privacy
The Service is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to This Policy
We may update this policy as the Service evolves. Material changes will be announced by email or in-product notice. The "Last updated" date at the top reflects the latest revision.
14. Contact
Privacy questions or data requests: info@lumenlytic.com.