ShonyLabs
DocsPricingChangelog
Log inGet started

Privacy Policy

Last updated: September 6, 2026

This document is provided as-is and does not constitute legal advice. If your business has specific regulatory obligations, have it reviewed by qualified counsel for your jurisdiction before relying on it.

This policy explains what data ShonyLabs Analytics ("ShonyLabs") collects, both about you as a ShonyLabs customer and about visitors to websites that use a ShonyLabs tracking snippet. If you are a visitor to a site that uses ShonyLabs, the site owner — not ShonyLabs — is responsible for telling you about that in their own privacy policy; see our DPA for how that responsibility is split.

1. Information we collect about you (our customer)

  • Account data: your email address and password hash, and any team/site metadata you create.
  • Billing data: payments are handled by our third-party payment processor, Dodo Payments, which acts as merchant of record. Dodo Payments collects and stores your payment details directly — ShonyLabs never receives or stores full card numbers. We store your plan tier, subscription status, billing interval, renewal date, and the customer and subscription identifiers returned to us by Dodo Payments, plus a record of each successful charge or refund.
  • Support communications you send us.

2. Information collected about your website's visitors

Depending on which tracking snippet you install (see GDPR & cookieless tracking):

  • Cookie-based snippet: a randomly generated visitor identifier stored in localStorage and a first-party cookie, plus page URLs, referrers, UTM parameters, approximate geographic location (country/region/city, derived from IP — the IP address itself is used transiently to resolve location and is not stored), browser/OS/device type, screen size, language, and timezone.
  • Cookieless snippet: the same page/browser/geo data, but no cookie or browser storage is used — the visitor identifier is instead derived server-side from a salted, rotating hash of IP address and user agent, and is never persisted.
  • If you use the identify API, whatever you choose to send (e.g. a user ID, name) — this is data you control and supply, not data ShonyLabs collects independently.
  • If you use the transactions API, purchase amounts, currency, and transaction IDs you report.

We do not knowingly collect visitor names, email addresses, or other directly identifying information unless a customer explicitly submits it via the identify or transactions APIs.

3. How we use this information

Visitor data is used solely to generate analytics for the website owner who installed the tracking snippet, and to operate, secure, and improve the Service. We do not sell visitor data, and we do not use it to build cross-site advertising profiles.

4. Sharing of data

We do not sell personal data. We share data only with infrastructure providers who process it on our behalf (see our DPA for the current list), or where required by law.

5. Cookies

ShonyLabs itself sets a single session cookie when you log in to the dashboard. It is strictly necessary for authentication, is httpOnly (not readable by client-side scripts), and carries a signed session token only — no tracking or advertising identifiers.

The tracking snippet you install on your own site comes in two variants, and you choose which one to use:

  • Default (cookie-based) snippet: sets one first-party cookie (and a matching localStorage value) on your visitors to recognise returning visitors. As the site owner you are responsible for obtaining any consent this requires in your jurisdiction — see our Terms of Service.
  • Cookieless snippet: sets no cookie and uses no browser storage at all on your visitors. The visitor identifier is derived server-side from a salted, rotating hash and is never persisted. On this basis a consent banner is typically not required for ShonyLabs — see GDPR & cookieless tracking. When you declare a site as cookieless in your Settings, the dashboard also stops showing that site's per-visitor Visitors and Journey views, since a rotating daily hash isn't a stable identity to build a persistent visitor profile from.

6. Data retention

Visitor analytics data and identity records are kept for as long as the account that owns the site is active. We do not currently run a fixed rolling-window purge — data is not automatically deleted once it reaches a certain age while the account is active. When you delete a site, that site's analytics events, identity records, and related data are deleted. When you delete your account, all of your sites and their data are permanently deleted along with it. Your account record is removed at the same time; residual copies may persist in encrypted database backups for a limited period before those backups are rotated out. If one of your own visitors asks you to delete their data, you can also erase a single visitor's events, identity record, tags, and transactions from their journey page in your dashboard, without deleting the whole site — see our DPA for how this fits your obligations as the data controller for your visitors.

7. Security

We apply the following technical measures, among others:

  • All traffic is served over HTTPS/TLS, with TLS termination and DDoS mitigation provided by our CDN (Cloudflare).
  • Account passwords are stored only as bcrypt hashes, never in plain text. Two-factor authentication is available and can be enabled from your settings.
  • Dashboard sessions use a signed, httpOnly cookie, so a session token cannot be read or exfiltrated by client-side scripts.
  • Every dashboard request and API call is checked against a per-site access-control rule before any data is read or written, so one customer's data is isolated from another's.
  • The event-ingestion endpoint is rate-limited and bot-filtered, and is served through our CDN rather than exposing the origin server directly. Database queries are parameterised.
  • Where a feature requires storing a third-party credential (for example an OAuth token for an optional integration), that credential is encrypted at rest with AES-256-GCM.
  • Administrative actions on the platform are recorded in an internal audit log.
  • Database backups are encrypted.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If you believe you have found a security vulnerability, please report it as described at /.well-known/security.txt.

8. Your rights

If you are a ShonyLabs customer, you can access, correct, or delete your account data from your dashboard settings, or by contacting [email protected]. If you are a visitor to a site using ShonyLabs and want to exercise a data subject right, please contact that site's owner directly — they control that data as described in our DPA.

9. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email to the address on your account.

10. Governing law

This policy is governed by the laws of the State of Israel.

11. Contact

Questions about this policy can be sent to [email protected].

ShonyLabs Analytics

Privacy-friendly web analytics that shows which channels actually drive revenue.

© 2026 ShonyLabs. All rights reserved.

Product

  • Log in
  • Sign up
  • Pricing
  • Changelog
  • Documentation
  • API reference

Guides

  • Quickstart
  • Tracking snippet
  • Goals
  • Transactions
  • Identify visitors
  • Cookieless tracking

Company

  • About
  • Contact
  • Terms of service
  • Privacy policy
  • Data processing agreement