VisitorType

Privacy Policy

Last updated: July 10, 2026.

Who we are

VisitorType (“the Service”) is operated by VISITORTYPE SL, C. del Poeta Joan Maragall, 43, Tetuán, 28020 Madrid, Spain. Contact: [email protected]. For website visitors of sites that use our snippet, we act as a data processor on behalf of the site owner (the data controller). For registered users of our dashboard, we are the data controller.

Data we process about website visitors (as processor)

When a site using our snippet is visited, we process:

  • User-agent string and derived bot/AI classification
  • Page path and referrer — with query strings and fragments removed before storage
  • A random per-browser-session identifier (expires when the tab session ends)
  • Engagement measurements (time on page, scroll depth)
  • Technical automation signals used solely for bot classification

We do notstore IP addresses of website visitors, do not use persistent cookies or cross-site identifiers, and do not build visitor profiles. The snippet honors the Global Privacy Control (GPC) and Do Not Track signals by collecting nothing when they are present. Event data is automatically deleted according to the account’s retention period (from 30 days, depending on the site owner’s plan).

Data we hold about registered users (as controller)

  • Account data: name, email, hashed password or OAuth identity
  • Authentication session metadata (IP address, user agent) for account security
  • Container configuration, tags, triggers, API keys (stored hashed)
  • Optional AI-provider API keys you add for the assistant (encrypted at rest, never displayed in full)

Legal bases: performance of contract (operating your account) and legitimate interest (security). We do not sell personal data.

Sub-processors

The Service runs on our self-hosted infrastructure fronted by Cloudflare, Inc. (network delivery, CDN, and DDoS protection). Data sub-processors: Neon (database storage, EU — Frankfurt, Germany), Resend (transactional email), and PostHog (EU, cookieless product analytics). If you configure the built-in assistant, your prompts and aggregated analytics summaries are sent to the AI provider you choose and key you supply (e.g. Anthropic, OpenAI, DeepSeek, Zhipu, or your own Ollama server) — that processing happens under your relationship with that provider.

Your rights

Under GDPR you may request access, rectification, erasure, restriction, portability, or object to processing — contact [email protected]. Website visitors should direct requests to the owner of the website they visited (the controller); we support controllers in fulfilling them. You may lodge a complaint with your supervisory authority.

Retention & deletion

Visitor events: deleted automatically according to the account’s plan retention period (from 30 days). Account data: deleted upon account deletion request to [email protected]; deleting a container permanently deletes all its events. Backups are retained for a limited period (up to 30 days) by our database provider.

← Back to home