ShonyLabs
DocsPricingChangelog
Log inGet started

Data Processing Agreement

Last updated: September 6, 2026

This document is provided as-is and does not constitute legal advice. If your business has specific regulatory obligations, have it reviewed by qualified counsel for your jurisdiction before relying on it.

This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Customer") and ShonyLabs ("ShonyLabs") governing ShonyLabs' processing of personal data collected via the ShonyLabs tracking snippet and APIs on the Customer's behalf.

1. Key terms

  • Controller:the Customer — the party that decides what data is collected from their website's visitors and why (e.g. by choosing which tracking snippet to install, which custom events to send, and whether to use the identify or transactions APIs).
  • Processor:ShonyLabs — processes visitor data solely to provide the analytics Service, on the Customer's documented instructions.
  • Subprocessor: a third party ShonyLabs engages to help provide the Service (see Section 4).

2. Scope of processing

ShonyLabs processes the categories of visitor data described in our Privacy Policy — page/session activity, approximate geographic location, device/browser information, and, depending on the tracking snippet the Customer installs, either a cookie/localStorage-based visitor identifier or a server-derived, storage-free one (see GDPR & cookieless tracking) — solely to provide analytics, goal/funnel tracking, and revenue attribution back to the Customer. ShonyLabs does not use this data for its own marketing purposes and does not sell it.

3. Data retention

Visitor analytics events and identity records are retained for as long as the Customer account that owns the site is active; ShonyLabs does not apply a fixed rolling-window purge. When the Customer deletes a site, that site's analytics events, identity records, and related data are deleted. When the Customer deletes their account, all of their sites and the associated data are permanently deleted along with the account record. Residual copies may remain in encrypted database backups for a limited period until those backups are rotated out. The Customer can also erase a single visitor's data on request without deleting the whole site or account — see Section 8.

4. Subprocessors

ShonyLabs runs its ingestion API, queue, and analytics database on its own dedicated server rather than on a third-party cloud hosting provider. The subprocessors ShonyLabs engages are:

  • Cloudflare, Inc. — CDN/proxy in front of the tracking endpoint, providing the geographic headers used to resolve approximate visitor location. Cloudflare processes visitor request data at its global edge.
  • Dodo Payments— payment processor / merchant of record for the Customer's own ShonyLabs subscription. It processes the Customer's billing and contact details only; it does not receive any website-visitor data.

We will update this list as our infrastructure changes and will use reasonable efforts to notify Customers of material changes.

5. International data transfers

ShonyLabs' server is located in Israel. Israel benefits from a European Commission adequacy decision, so transfers of visitor data from the EEA or UK to ShonyLabs' infrastructure do not require additional safeguards such as Standard Contractual Clauses. Where personal data is processed by Cloudflare at its global edge, Cloudflare's own Data Processing Addendum and Standard Contractual Clauses govern any transfers that occur at that layer.

6. Security measures

ShonyLabs encrypts data in transit (HTTPS), restricts access to production systems, and applies the access-control model described in our architecture (per-site roles, API-key authentication for server-to-server endpoints). All data is encrypted in transit over HTTPS/TLS. Access to production systems is limited to ShonyLabs' operating personnel. Database backups are taken on a regular schedule and stored with access controls. If ShonyLabs becomes aware of a personal data breach affecting Customer data, it will investigate, take steps to contain and remediate the incident, and notify the affected Customer without undue delay (see Section 7).

7. Roles and responsibilities

The Customer (Controller) is responsible for:

  • Having a lawful basis for collecting visitor data via the tracking snippet.
  • Obtaining visitor consent where required (e.g. a cookie banner for the default snippet).
  • Maintaining an accurate privacy notice on their own website.
  • Handling data subject requests from their own visitors.

ShonyLabs (Processor) is responsible for:

  • Processing data only on the Customer's documented instructions (i.e. as configured through the dashboard and APIs).
  • Applying appropriate technical and organizational security measures.
  • Assisting the Customer in responding to data subject requests and regulator inquiries, to the extent required by applicable law.
  • Notifying the Customer without undue delay of any personal data breach affecting their data.

8. Data access, export, and erasure

The Customer can access their processed data at any time via the dashboard. Every breakdown table and the visitors list offers a CSV export. There is no separate bulk data-export API today — access is through the dashboard UI and the CSV exports it provides.

For a specific visitor's data — for example to fulfil an erasure request from that visitor under Section 7 — the Customer (an account owner or member) can open that visitor's journey page in the dashboard and use the "Erase visitor data" action. This permanently deletes that visitor's analytics events, identity record, manual tags, and transactions from the site (and, where the visitor was identified from more than one device, does so across every merged device at once). This action is irreversible. It is not exposed for a site using the cookieless tracking snippet: a cookieless visitor identifier rotates roughly every 24 hours and is derived rather than assigned, so there is no stable, rediscoverable ID a later erasure request could reliably target — the dashboard's Visitors and Journey views are hidden for such a site for the same reason (see GDPR & cookieless tracking).

9. Governing law

This DPA is governed by the laws of the State of Israel.

10. Contact

Questions about this DPA can be sent to [email protected].

ShonyLabs Analytics

Privacy-friendly web analytics that shows which channels actually drive revenue.

© 2026 ShonyLabs. All rights reserved.

Product

  • Log in
  • Sign up
  • Pricing
  • Changelog
  • Documentation
  • API reference

Guides

  • Quickstart
  • Tracking snippet
  • Goals
  • Transactions
  • Identify visitors
  • Cookieless tracking

Company

  • About
  • Contact
  • Terms of service
  • Privacy policy
  • Data processing agreement