Privacy is Not an Afterthought, It's Our Foundation
We built TrueMetric because we believe you shouldn't have to choose between getting valuable website insights and respecting your visitors' privacy. Here's how we achieve both.
No Cookies, Period.
TrueMetric does not use any browser cookies (first-party or third-party) or other persistent client-side storage mechanisms (like localStorage) for tracking visitors.
This means:
- Immunity to cookie consent banner fatigue and rejection for analytics tracking.
- Compliance with PECR (ePrivacy Directive) requirements regarding cookie usage for analytics.
- Tracking works even if users block cookies or clear them frequently.
- No cross-site tracking capabilities via cookies.
Strict IP Address Handling
Visitor IP addresses are considered personal data under GDPR. We handle them with extreme care:
- IPs are used only momentarily in memory during the request.
- We use the IP solely for deriving geographic location (Country/Region/City) and generating a daily `visitId`.
- The full IP address is never stored on disk or in our database logs.
- Enhanced privacy measures: We truncate IP addresses (removing the last octet for IPv4, last 80 bits for IPv6) during processing to further reduce identifiability.
- This process makes it impossible to identify or track an individual user via their IP address over time in our system.
Daily Activity Tracking
Instead of traditional session tracking with cookies, we've developed a privacy-preserving alternative called "Daily Activity Tracking" using sophisticated pseudonymization techniques:
- We generate a pseudonymous daily `visitId` hash derived from:
- Truncated IP address (with identifying portions removed)
- User agent information
- Current date (YYYY-MM-DD format)
- A secret, daily rotating salt value
- This allows us to recognize page views from the same visitor within the same 24-hour period only.
- The daily salt rotation and date inclusion ensure that it's impossible to link visits from the same person across different days.
- Our hash algorithm (SHA-256) ensures this process is one-way and cannot be reversed to identify individuals.
- This approach provides essential metrics like daily unique visitors, bounce rates, and pages per visit while maintaining strong privacy protections.
Minimal Data Collection
We only collect the data absolutely necessary to provide core web analytics:
- Page URL
- Referrer URL
- User Agent string (for browser/OS/device type)
- Derived Geographic Location (Country/Region/City - from discarded IP)
- UTM parameters (if present)
- Screen resolution
- Pseudonymous daily `visitId`
We do not collect granular user flow paths, mouse movements, form inputs, or any other potentially sensitive behavioral data. Website owners can configure even more limited data collection (such as country-only geolocation) if desired.
European Data Sovereignty
All analytics data collected by TrueMetric's hosted solution is processed and stored on infrastructure located within the European Union.
This helps businesses comply with GDPR data transfer requirements and addresses concerns about data access by non-EU authorities. For ultimate control, explore our self-hosting option.
Transparent Privacy Dashboard
TrueMetric provides a public-facing Privacy Dashboard for each website, giving visitors full transparency into data collection practices:
- A clear visual summary of key privacy practices (no cookies, no IP storage, etc.)
- Detailed explanation of what data is collected and how it's used
- Information about data retention periods
- Sample privacy policy text for website owners
- Options for visitors to understand and control their data
This transparency builds trust with site visitors and helps website owners demonstrate compliance with privacy regulations. The Privacy Dashboard is accessible without requiring authentication.
Flexible Legal Framework
TrueMetric supports two distinct legal approaches to help website owners meet their compliance obligations:
Legitimate Interest Approach
Our privacy-preserving techniques create a strong case for using Legitimate Interest as the lawful basis for processing under GDPR:
- Strong pseudonymization (daily visitId)
- Truncated IPs, never stored
- No cookies or persistent identifiers
- Data minimization by design
- Easy opt-out implementation
Benefit: Higher coverage (typically 99% vs. 70-80% with consent banners)
Opt-In Consent Approach
For organizations preferring or required to use explicit consent:
- Customizable consent UI integration
- Server-side consent verification
- Granular consent options
- Integration with CMPs
- No tracking until consent given
Benefit: Maximum compliance certainty in strict jurisdictions
While TrueMetric provides the tools and infrastructure to support both approaches, the final responsibility for determining the appropriate legal basis rests with the website owner as the data controller.
User Privacy Controls
TrueMetric respects visitor choices about tracking and provides several control options:
- Do Not Track (DNT) signals: TrueMetric can be configured to respect browser DNT signals.
- Opt-out mechanisms: Site owners can implement easy opt-out controls for visitors.
- Consent preferences: When using the opt-in approach, visitors have granular consent options.
- Privacy Dashboard access: Visitors can view the public Privacy Dashboard to understand exactly what data is collected.
- No long-term tracking: By design, the daily identifier reset ensures visitors cannot be tracked beyond a 24-hour period.
These controls ensure that TrueMetric respects user autonomy while still providing valuable analytics data to website owners.
Compliance by Design
TrueMetric's architecture is fundamentally aligned with GDPR, CCPA/CPRA, and PECR principles. By avoiding cookies for tracking and never storing personal data like IP addresses long-term, you can often use TrueMetric for essential website analytics without needing a separate analytics consent banner, simplifying your user experience and potentially increasing data capture rates compared to consent-gated platforms.
Disclaimer: Always consult with a legal professional to ensure compliance for your specific situation and data usage.
Need Help With Your Privacy Policy?
To help you accurately describe how TrueMetric works on your site, here's some sample language you can adapt. Remember to integrate it thoughtfully into your overall privacy policy.
Important Disclaimer
This is sample language, not legal advice. You are responsible for ensuring your privacy policy accurately reflects all your data practices (not just analytics) and complies with applicable laws (like GDPR, CCPA, PECR, etc.) in your jurisdiction(s). Always have your final privacy policy reviewed by a qualified legal professional.
Sample Language: Website Analytics
We use TrueMetric to collect anonymous information about how visitors use our website. TrueMetric is a privacy-focused analytics tool that helps us understand website traffic and improve user experience without compromising individual privacy. It operates without using cookies and does not store visitors' IP addresses.
Data Collected via TrueMetric:
TrueMetric provides us with aggregated insights by collecting the following types of information:
- Page URL
- Referrer URL
- User Agent string (for browser/OS/device type)
- Derived Geographic Location (Country/Region/City - from discarded IP)
- UTM parameters (if present)
- Screen resolution
- Pseudonymous daily `visitId`
How TrueMetric Protects Your Privacy:
- No cookies or local storage: TrueMetric doesn't use cookies or browser storage mechanisms to track visitors.
- No IP address storage: IP addresses are used momentarily for geolocation and creating a daily identifier, then immediately discarded.
- Daily reset: The pseudonymous visitId is reset every 24 hours, preventing long-term tracking.
- European data processing: All data is processed and stored on EU-based servers.
- No cross-site tracking: Data collected is strictly limited to activity on our website.
Legal Basis for Processing (GDPR):
We process this anonymous analytics data based on our legitimate interest in improving our website and user experience. Given the privacy-preserving measures implemented by TrueMetric (no cookies, no IP storage, daily identifier reset), we believe this represents a minimal privacy impact that is balanced by the benefits of providing an optimized website experience.
Alternative consent-based language: "We only process analytics data with your explicit consent. If you have consented to analytics cookies/tracking, we use TrueMetric to collect anonymous information about how you use our website. You can withdraw this consent at any time through our cookie/privacy preferences panel."
Data NOT Collected or Stored by TrueMetric:
- Personally Identifiable Information (PII)
- Full IP addresses (only processed momentarily for geo-location)
- Tracking cookies or data from local browser storage
- Information that allows tracking users across different websites or over time (beyond a single day's pseudonymous session)
- Sensitive data like form inputs or detailed user interactions
Purpose of Data Collection:
The anonymous, aggregated data collected through TrueMetric is used solely for the purpose of:
- Understanding how our website is used (e.g., popular pages, traffic sources).
- Improving website content, performance, and usability.
- Measuring the effectiveness of marketing campaigns (via UTM parameters).
- Generating aggregated statistical reports about website activity.
This data helps us make informed decisions to enhance the website for our visitors.
Data Retention:
Analytics data is retained for [INSERT YOUR RETENTION PERIOD] months, after which it is automatically deleted. The pseudonymous visitId is automatically reset every 24 hours.
Your Controls:
You can learn more about our analytics practices by visiting our TrueMetric Privacy Dashboard. If you wish to opt out of anonymous analytics tracking, you can [DESCRIBE OPT-OUT METHOD - e.g., "use our privacy preferences panel" or "enable Do Not Track in your browser"].
Remember to tailor this language to fit the context of your full privacy policy. For the original full template (which includes sections not shown here and requires careful legal review), see our Privacy Policy Template page.
Have Questions About Our Approach?
We believe in transparency. Reach out to us if you have specific questions about our privacy practices or how TrueMetric fits your compliance needs.