Privacy Policy
Last updated: [EFFECTIVE DATE]
[placeholder]below must be filled in, and the whole document should be reviewed by qualified counsel for your jurisdiction and business before it's relied on or linked as a real policy.This policy explains what data ShonyLabs Analytics ("ShonyLabs", operated by [LEGAL ENTITY NAME]) collects, both about you as a ShonyLabs customer and about visitors to websites that use a ShonyLabs tracking snippet. If you are a visitor to a site that uses ShonyLabs, the site owner — not ShonyLabs — is responsible for telling you about that in their own privacy policy; see our DPA for how that responsibility is split.
1. Information we collect about you (our customer)
- Account data: your email address and password hash, and any team/site metadata you create.
- Billing data: [Describe what is collected once billing exists — e.g. handled entirely by a third-party payment processor, ShonyLabs never stores card numbers.]
- Support communications you send us.
2. Information collected about your website's visitors
Depending on which tracking snippet you install (see GDPR & cookieless tracking):
- Cookie-based snippet: a randomly generated visitor identifier stored in
localStorageand a first-party cookie, plus page URLs, referrers, UTM parameters, approximate geographic location (country/region/city, derived from IP — the IP address itself is used transiently to resolve location and is not stored), browser/OS/device type, screen size, language, and timezone. - Cookieless snippet: the same page/browser/geo data, but no cookie or browser storage is used — the visitor identifier is instead derived server-side from a salted, rotating hash of IP address and user agent, and is never persisted.
- If you use the identify API, whatever you choose to send (e.g. a user ID, name) — this is data you control and supply, not data ShonyLabs collects independently.
- If you use the transactions API, purchase amounts, currency, and transaction IDs you report.
We do not knowingly collect visitor names, email addresses, or other directly identifying information unless a customer explicitly submits it via the identify or transactions APIs.
3. How we use this information
Visitor data is used solely to generate analytics for the website owner who installed the tracking snippet, and to operate, secure, and improve the Service. We do not sell visitor data, and we do not use it to build cross-site advertising profiles.
4. Sharing of data
We do not sell personal data. We share data only with infrastructure providers who process it on our behalf (see our DPA for the current list), or where required by law.
5. Cookies
ShonyLabs itself sets a session cookie when you log in to the dashboard, and (if you use the default tracking snippet on your own site) that snippet sets a first-party cookie on your visitors' behalf, as described above. As the site owner, obtaining any consent required for that cookie is your responsibility — see our Terms of Service.
6. Data retention
[State actual retention periods once decided — e.g. how long visitor analytics data is kept in Postgres, what happens to it if a site or account is deleted, and how long account data is kept after account deletion.]
7. Security
We use reasonable technical measures to protect data, including encrypted connections and access controls. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Your rights
If you are a ShonyLabs customer, you can access, correct, or delete your account data from your dashboard settings, or by contacting [CONTACT EMAIL]. If you are a visitor to a site using ShonyLabs and want to exercise a data subject right, please contact that site's owner directly — they control that data as described in our DPA.
9. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email to the address on your account.
10. Governing law
This policy is governed by the laws of [JURISDICTION].
11. Contact
Questions about this policy can be sent to [CONTACT EMAIL].