Legal
Privacy policy.
Last updated July 21, 2026. The short version: the tracking snippet collects no tracking cookies and no personal profiles — we measure journeys, not people — and we never sell or share data. The details below spell out exactly what is collected, where it lives, and how to get it removed.
Who we are
Revtrail ("we") provides cookieless, revenue-first web and app analytics. For questions about this policy or your data, email privacy@revtrail.dev.
Two kinds of data
We handle two distinct data sets. (1) Visitor analytics: measurements the Revtrail snippet or SDK collects from our customers' websites and apps — here we act as a processor on the customer's behalf. (2) Account data: information you give us when you create a Revtrail account — here we act as the controller.
What the snippet collects
Page URL and path, hostname, referrer, UTM parameters, country (derived from the request, never stored as an IP), device class, browser, and operating system family, plus any custom events — and revenue amounts — the site owner chooses to send. The hostname is used to apply site exclusions and is not retained in the event store. The default daily mode places no visitor identifier in cookies or localStorage. A site owner may explicitly enable persistent anonymous identity, which stores a random site-scoped identifier in localStorage for retention reporting. There is no fingerprinting or cross-site identifier. Opting out removes that identifier and stores only the privacy preference.
How visitors are counted without cookies
In default daily mode, each pageview carries a visitor hash computed on our servers from the site, the visitor's IP address, and browser signature, mixed with a secret salt that rotates daily. The raw IP address is discarded immediately and never stored. The hash cannot link a visitor across days or sites and cannot be reversed into an identity. In optional persistent mode, the server hashes the random site-scoped browser identifier instead. Mobile apps may similarly supply a random app-scoped device identifier.
No personal data by default
The snippet never collects names, emails, or other personal information, and customers are required not to place personal data inside custom event names or payloads. Revenue attribution joins payments to the anonymous visitor hash via the customer's payment processor — card details never touch Revtrail.
Account data
When you sign up we store your email address, display name, and a salted hash of your password (never the password itself). The dashboard uses a session cookie strictly to keep you signed in — an essential cookie, not a tracking one. Billing is handled by Stripe; we store your subscription state and Stripe customer reference, and we never see your card number.
Where data lives and for how long
All data is stored in the United States: the application and its database run on Fly.io, and aggregate event data lives in Tinybird (AWS us-east). Raw analytics events are retained for 3 years and then deleted automatically. Deleting a site removes its configuration and dashboards immediately; associated event data can be purged on request.
Subprocessors
Fly.io (application hosting, USA), Tinybird (event storage and aggregation, USA), and Stripe (payments, USA). Each processes data solely to provide their part of the service. We will update this list before adding subprocessors.
What we never do
We never sell data, never share it with advertisers or data brokers, never build cross-site profiles, and never use your visitors' data for anything except showing you your own analytics.
GDPR and your rights
The default snippet is designed to operate without consent banners: it sets no tracking cookies, stores no persistent visitor identifier, and keeps no personal profile. Optional persistent identity stores a random site-scoped identifier in localStorage, so site owners who enable it are responsible for appropriate disclosure, consent, and their own legal assessment. A browser opt-out removes that identifier and stores only the preference. Account holders can access, correct, export, or delete their data by emailing privacy@revtrail.dev. A data processing agreement (DPA) is available on request.
Changes
If this policy changes materially we'll note it here with a new effective date and email account holders before the change takes effect.