Privacy Policy
Last updated: July 5, 2026
How DataLaunch handles account data, visitor analytics, tracking modes, and your responsibilities as a site owner.
Overview
DataLaunch ("we", "us") provides website analytics software for site owners. This Privacy Policy describes how we handle information when you use datalaunch.io, create an account, or install our tracking script on a website you control. Analytics for your visitors is processed on your behalf; you remain responsible for notices and lawful bases required for your site.
Roles: controller vs processor
For account, billing, and platform usage data, DataLaunch acts as the data controller. For visitor analytics collected through your tracking script (pageviews, sessions, events, referrers, device categories, coarse location), DataLaunch generally acts as a data processor and you, the site owner, act as the controller toward your visitors. You should publish your own privacy notice explaining what you collect via DataLaunch.
Account & billing data we collect
When you register or sign in, we collect information needed to operate the service: email address, authentication identifiers (via our auth provider), account metadata, site configuration (name, domain, tracking mode, exclusions), team invitations, and billing status. Signing into the DataLaunch dashboard may use session cookies or similar technologies for authentication—these are separate from the analytics tracking script and are not placed on your visitors' sites by our tracker. If you subscribe, payment is handled by our payment provider; we do not store full payment card numbers on our servers.
Visitor analytics we process for you
When the DataLaunch script runs on a site you configure, we may process: anonymous session identifiers, page paths, referrers, UTM campaign parameters, browser/OS/device categories, language, screen size categories, custom event names you define, session duration (via heartbeat updates), and coarse location (country, region, city when available). We do not intentionally store raw IP addresses in the analytics dataset; IP may be used transiently for geolocation and, in cookieless mode, for generating a short-lived pseudonymous visitor key.
Tracking modes (your choice per site)
You choose a tracking mode when adding a site or in Settings → General. Neither mode uses HTTP cookies for analytics. Cookieless (track.cookieless.js): uses session-only browser storage (sessionStorage) for the current tab session. Visitor pseudonyms are derived server-side from signals such as IP address, user-agent, site domain, and a salt that rotates about every 24 hours (UTC). The same person on different days may not be linked as one long-lived profile. Standard (track.js): uses localStorage for a persistent anonymous visitor ID and first-touch attribution data across sessions. This improves returning-visitor analytics, journeys, and long-range attribution but may have different consent implications in some jurisdictions than cookieless mode. Your live site must load the script that matches the mode configured in your dashboard.
What we do not do
We do not sell visitor analytics data. We do not use third-party advertising trackers in the analytics script. We do not intentionally collect names, emails, or other direct identifiers from your visitors unless you send them via custom events you control. We do not perform cross-site profiling across unrelated customer sites.
AI analytics chat (Pro / eligible plans)
If you use the in-dashboard AI analyst, your questions are sent to our AI provider to generate answers. The assistant queries aggregated analytics for your site via server-side tools—it does not receive raw visitor identities from us. Do not paste personal data into chat prompts.
Subprocessors & infrastructure
We use trusted providers to run the service, including hosting, database/auth (e.g. Supabase), email delivery, payment processing (e.g. Dodo Payments), and AI inference where enabled. These providers process data only as needed to deliver the service.
Retention & trial lifecycle
Analytics retention depends on your plan (e.g. 1 year on Starter, 3 years on Pro). New accounts may receive a 7-day free trial with an event limit. If a trial ends without a paid plan, a grace period (currently 8 days) may apply before analytics data for affected sites is purged. Purged data is not recoverable. You can delete sites from your dashboard; contact us for account-level requests.
Security
We apply technical and organizational measures appropriate to an analytics SaaS product, including access controls, encrypted transport (HTTPS), and separation of customer data by site. No method of transmission or storage is 100% secure.
Your rights & contact
Depending on your location, you may have rights to access, correct, delete, or restrict certain processing of your account data. Site owners should handle visitor rights requests for data they control. Contact us at hello@datalaunch.io for privacy questions or requests.
Changes
We may update this policy as the product evolves. We will post the revised version on this page with an updated date. Continued use of the service after changes constitutes acceptance of the updated policy.
See also our Terms of Service.