1. Who we are
WebTracko (the “Service”) is a website analytics and live visitor observation product operated by Xapp Digital Solutions (“we”, “us”, “our”). This policy explains what personal data we process, why, how it is protected and the choices available to you.
For any privacy question or request, contact us at info@xappdigital.com.
2. Two kinds of data, two roles
WebTracko handles two distinct categories of data, and our role is different for each:
- Customer account data — information about the people and businesses who sign up for WebTracko. For this data we act as the controller.
- Website visitor data — information collected by the WebTracko script on our customers' websites about the people who visit those websites. Our customer (the website owner) decides to collect this data and is the controller; we process it on the customer's behalf as a processor, only to provide the Service to that customer.
If you visited a website that uses WebTracko and have questions about your data, please contact that website's owner first. We will support them in responding to your request.
3. Customer account data we collect
| Data | Details |
|---|---|
| Identity & contact | First and last name (optional) and email address. |
| Credentials | Your password, stored only as a salted bcrypt hash. One-time verification codes, which expire after 15 minutes. |
| Websites you add | Website names, domains and the settings you choose for them. |
| Billing | Plan, subscription status and Stripe customer and subscription identifiers. Card details are entered directly with Stripe and never reach our servers. |
| Account activity | Security and billing events such as email verification, password changes, plan changes and website changes. |
| Technical data | IP address and browser information included in requests to our dashboard and API, used for security, rate limiting and troubleshooting. |
We use this data to create and secure your account, provide the Service, process payments, send transactional emails (such as verification codes and billing notices) and respond to support requests. We do not send marketing email without your consent.
4. Website visitor data the script collects
When a customer installs the WebTracko script, it collects the following about visitors to that customer's website. Data is only sent after a visitor has produced about two seconds of real mouse movement; until then nothing leaves the browser.
| Data | Details |
|---|---|
| Anonymous identifiers | A random visitor ID stored in the browser's localStorage and a random session ID stored in sessionStorage. They contain no personal information and are not cookies. |
| IP address | Derived by our server from the network request (the script never looks up its own IP). Stored with the session in full by default; the Service can be configured to store a truncated (anonymized) IP or no IP at all. |
| Country | Derived from the IP address using a geolocation database that runs on our own servers. The IP is not sent to any third party for this purpose. |
| Device information | Browser, operating system and device type (derived from the user agent), browser language, screen size and window (viewport) size. |
| Traffic source | The referring website and UTM campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content). |
| Pages | Page URLs and titles viewed. Query strings and fragments are removed before storage, because they can contain personal data; only route fragments such as “#/settings” used by single-page apps are kept. |
| Interactions | Sampled mouse pointer positions, click positions with a short description of the clicked element (tag name, id and class — never its text), scroll position, window resizes and navigation between pages, each with a timestamp. |
| Live page snapshots | Only while the website owner is actively watching that visitor: a sanitized structural copy of the visible page (see below). Snapshots are held in memory only and are never written to disk. |
5. What we never collect
The WebTracko script is designed so that the following data cannot be collected, regardless of configuration:
- Keystrokes or any keyboard events.
- Text typed into forms, and the values of input, textarea and select fields, checkboxes and radio buttons.
- Passwords, payment card details and other form contents.
- Text inside editable regions (contenteditable).
- Text inside elements the website owner marks with
data-wt-mask(replaced by bullets), or anything inside elements markeddata-wt-block(replaced by an empty box). - Scripts, embedded frames, cookies or browser storage of the visited website.
WebTracko does not record video, does not store replays of sessions and does not use device fingerprinting.
6. How we store and protect website data
Protecting the data our customers entrust to us is central to how WebTracko is built. Our safeguards include:
- Hosting location. The WebTracko application and database run on servers located in Germany, in the European Union.
- Encryption in transit. All traffic between visitors' browsers, our servers and the WebTracko dashboard is encrypted with HTTPS (TLS).
- Strict tenant isolation. Every stored record is tied to a specific website, and every website belongs to exactly one account. Every dashboard request is checked against the authenticated account before any data is returned, so one customer can never access another customer's websites, visitors or analytics.
- Data minimization. Visits are only recorded after real mouse movement; query strings are stripped from URLs; mouse movement is sampled rather than captured continuously; and live page snapshots are only produced while someone is watching.
- Memory-only snapshots in a secure sandbox. Live page snapshots are sanitized on the visitor's browser and again on our servers (scripts, event handlers, embedded frames and form values are removed), are kept in memory only while being viewed, and are displayed in an isolated sandbox in which no script can run.
- Validated, rate-limited ingestion. Our collection endpoint only accepts data from the domains a customer has configured, enforces a strict data format with size limits, and applies rate limits to prevent abuse and data pollution.
- Account security. Passwords are stored as salted bcrypt hashes; sign-in sessions use secure, HTTP-only cookies; sensitive account actions (password change, account deletion) require a one-time code sent by email; and authentication endpoints are rate-limited.
- Restricted access. Access to production systems and databases is limited to authorized Xapp Digital Solutions personnel who need it to operate and support the Service.
- No secondary use. We do not sell visitor data, use it for advertising, combine it across customers or build profiles of individuals.
No system is perfectly secure. If we become aware of a security incident affecting personal data, we will notify affected customers without undue delay and as required by applicable law.
7. How long we keep data
- Website visitor data is kept while the website exists in the customer's account so that historical analytics remain available. Raw interaction events are stored in monthly partitions so they can be expired on a retention schedule. Deleting a website permanently deletes all of its visitor data.
- Live page snapshots exist only in memory while being viewed and are discarded shortly after viewing stops.
- Account data is kept while the account is active. When an account is deleted, all of its websites and their visitor data are deleted immediately, any subscription is cancelled, and we retain only a minimal record (such as email address and billing identifiers) where needed for legal, tax, fraud-prevention or accounting purposes.
- Server logs are kept for a limited period for security and troubleshooting.
9. International transfers
WebTracko data is stored in the European Union. Some service providers (for example email delivery and payment processing) may process limited customer account data outside the EU. Where this happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision.
10. Cookies and browser storage
On customer websites, the WebTracko script sets no cookies. It uses the browser's localStorage and sessionStorage for the anonymous visitor and session identifiers described above, a temporary flag that stops tracking when collection is not permitted, and an optional opt-out flag.
On webtracko.com, we use a single strictly necessary, HTTP-only cookie to keep you signed in, and localStorage to remember your light/dark theme preference. We do not use advertising or third-party tracking cookies.
11. Responsibilities of website owners
Customers who install WebTracko on their websites are responsible for:
- Informing their visitors about the use of WebTracko in their own privacy notice.
- Obtaining any consent required by applicable law (for example under the EU ePrivacy Directive and the GDPR) before the script stores identifiers in the visitor's browser or collects data.
- Using the masking and blocking attributes for any page content that should not be visible in live view.
- Responding to requests from their visitors to exercise their privacy rights. We will provide reasonable assistance.
The website owner can disable WebTracko for a visitor at any time by setting window.webtrackoOptOut = true or the localStorage key _wt_optout to 1 before the script runs.
12. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to restrict or object to certain processing, and to withdraw consent. Customers can update their profile and delete websites or their entire account directly from the dashboard.
To exercise any right, email info@xappdigital.com. We may need to verify your identity. You also have the right to lodge a complaint with your local data protection authority.
13. Children
WebTracko is a business service and is not directed at children under 16. We do not knowingly collect personal data from children as customers.
14. Changes to this policy
We may update this policy as WebTracko evolves. We will post the new version on this page with a new “last updated” date and, for material changes, notify customers by email or in the dashboard.
15. Contact
Xapp Digital Solutions — privacy and legal enquiries: info@xappdigital.com. For product support, see our Support page.