Privacy Policy
Last updated July 27, 2026
SimpleStat ("we", "us") provides privacy-friendly web analytics. This policy explains what data we collect, why, and how it's handled, both for people who use SimpleStat to track their own website, and for the visitors of those tracked websites.
Who is responsible for what
If you install the SimpleStat tracking snippet on your website, you are the data controller for your visitors' data, and SimpleStat is your data processor. You're responsible for making sure your own use of SimpleStat complies with the laws that apply to your website and your visitors (for example the GDPR if you have EU visitors).
Account data
When you create a SimpleStat account, we store your name, email address, and your plan/billing details. Authentication (login, password resets, email changes) is handled by our authentication provider, Supabase, so your password itself never touches our own servers in plain text.
Data collected from your website's visitors
The tracking snippet sends the following to SimpleStat whenever someone visits a page on your website:
- The page path visited, and the referring website (if any)
- A randomly generated visitor id, stored in a first-party cookie on your domain, so we can tell repeat visits apart from new ones without any personal information
- Country, region, and city, derived from the visitor's IP address at the moment of the request. The IP address itself is not stored
- Browser, operating system, and device type, parsed from the browser's user agent string
- Campaign parameters (such as utm_source) present in the URL, if any
- Whether the visit matched a goal you configured, and the associated conversion value if so
We do not use third-party advertising cookies, do not sell data, and do not track visitors across unrelated websites.
Optional: Google Search Console
If you choose to connect your Google Search Console account in Settings, we request read-only access to your search performance data (queries, clicks, impressions, position) via Google's OAuth flow. Access tokens are stored encrypted. You can disconnect at any time, which deletes the stored tokens and the synced search data for that website.
Sub-processors
- Supabase, authentication and database hosting
- MaxMind, whose GeoLite2 database we use locally to turn an IP address into a country/region/city, no visitor data is sent to MaxMind to do this
- Google, only for accounts that choose to connect Search Console
- Stripe, for billing (once payments are enabled)
Data retention
Visitor data is retained for 3 years on the Starter plan and 5 years on the Growth plan, after which it is automatically deleted. If you delete a website from your account, all of its data is deleted immediately and permanently.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. To exercise any of these rights, contact us at support@simplest.at.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or an in-app notice.
Contact
SimpleStat
support@simplest.at