Skip to content
ProductWhy GlytiqPricingFAQs
Log in Get started
TRUST & TRANSPARENCY

Privacy Policy

How visitor data is collected, used and protected in Glytiq.

Updated September 2026 · Glytiq product plans
Privacy PolicyData Processing AgreementSecurity
ON THIS PAGE01What we collect about your visitors02How sessions are counted03Cookies, local storage and consent04B2B company identification05Custom event properties06Hosting and data location07Your data and export
01

What we collect about your visitors

Glytiq collects the measurements needed to provide web analytics: page URL, referrer origin, UTM parameters, coarse geography derived from network metadata, browser, operating system, device type, and custom events you explicitly configure. Automatic outbound-link and download events keep the destination origin and path, without URL credentials, query parameters or fragments. Core visitor analytics does not use tracking cookies and does not create cross-site profiles.

02

How sessions are counted

To distinguish visits without storing an IP address, Glytiq derives a daily-rotating session hash from the site, IP address, user-agent and current day. The IP address is processed transiently for this calculation and is not persisted in the event database. The hash is designed not to be reversible to a person and becomes unsuitable for tracking on the next day.

03

Cookies, local storage and consent

Core analytics is cookieless and creates no persistent browser identifier. Explicitly configured A/B testing stores assigned variants and an experiment identifier to attribute later conversions in the same browser. These remain until that browser storage is cleared; removing all experiment assignments also removes the identifier on the next tracked event. The tracker opt-out stores the visitor's choice. Dashboard and client-portal authentication use secure session cookies for signed-in users. Whether a banner or notice is required depends on your configuration and jurisdiction; the final legal assessment remains with you as the site operator.

04

B2B company identification

When company identification is enabled, the visitor IP address is used transiently to look up the associated organization, after which the IP is discarded. The result is an organization-level signal such as company name or industry, not an identified individual.

05

Custom event properties

Glytiq lets you define custom event names and properties. Because those properties can contain arbitrary strings supplied by your implementation, you must not send names, email addresses, free-text messages or other personal data in custom events. Glytiq's standard event schema is not designed to require personal data, but your implementation controls what you choose to send.

06

Hosting and data location

Glytiq is deployed in the EU. The production application is hosted with Railway in EU West (Amsterdam, Netherlands), and the production database is hosted with TiDB Cloud on AWS in Frankfurt (eu-central-1). Visitor analytics data is processed and stored within the EU.

07

Your data and export

You can export your statistics from Site settings and delete a site together with its associated analytics data. Raw events, aggregates and derived records are removed from active systems; residual backup copies expire according to the retention schedule used for disaster recovery.

Questions about this document?

Contact legal@glytiq.com .

These pages describe the product's current technical behavior and are not legal advice. Your implementation, configured events, local laws and contractual terms determine the obligations that apply to your deployment.

SEO, analytics and company intelligence.
For the conversation that follows.

A woman exploring illustrated analytics panels.
Explore GlytiqProductWhy GlytiqPricingFAQs
Your workspaceDashboardClient portalLog in
Privacy & securityPrivacyDPASecurity
© 2026 Glytiq Cookieless by designBack to top