What we collect about your visitors
Glytiq collects the measurements needed to provide web analytics: page URL, referrer origin, UTM parameters, coarse geography derived from network metadata, browser, operating system, device type, and custom events you explicitly configure. Automatic outbound-link and download events keep the destination origin and path, without URL credentials, query parameters or fragments. Core visitor analytics does not use tracking cookies and does not create cross-site profiles.
How sessions are counted
To distinguish visits without storing an IP address, Glytiq derives a daily-rotating session hash from the site, IP address, user-agent and current day. The IP address is processed transiently for this calculation and is not persisted in the event database. The hash is designed not to be reversible to a person and becomes unsuitable for tracking on the next day.
Cookies, local storage and consent
Core analytics is cookieless and creates no persistent browser identifier. Explicitly configured A/B testing stores assigned variants and an experiment identifier to attribute later conversions in the same browser. These remain until that browser storage is cleared; removing all experiment assignments also removes the identifier on the next tracked event. The tracker opt-out stores the visitor's choice. Dashboard and client-portal authentication use secure session cookies for signed-in users. Whether a banner or notice is required depends on your configuration and jurisdiction; the final legal assessment remains with you as the site operator.
B2B company identification
When company identification is enabled, the visitor IP address is used transiently to look up the associated organization, after which the IP is discarded. The result is an organization-level signal such as company name or industry, not an identified individual.
Custom event properties
Glytiq lets you define custom event names and properties. Because those properties can contain arbitrary strings supplied by your implementation, you must not send names, email addresses, free-text messages or other personal data in custom events. Glytiq's standard event schema is not designed to require personal data, but your implementation controls what you choose to send.
Hosting and data location
Glytiq is deployed in the EU. The production application is hosted with Railway in EU West (Amsterdam, Netherlands), and the production database is hosted with TiDB Cloud on AWS in Frankfurt (eu-central-1). Visitor analytics data is processed and stored within the EU.
Your data and export
You can export your statistics from Site settings and delete a site together with its associated analytics data. Raw events, aggregates and derived records are removed from active systems; residual backup copies expire according to the retention schedule used for disaster recovery.