Privacy
Plain language. No legal puffery.
What we collect
- Pageviews, clicks on links and buttons, form submits and abandons, scroll depth (25/50/75/100), and time spent on each page.
- Source attribution — where each visitor came from on their first visit and on their most recent visit. We use the standard
utm_*parameters and the referring page’s host. - A visitor identifier kept in
localStorageon the visitor’s own browser. We use it to tell new visitors from returning visitors and to attach the right campaign source to conversions later. - A salted, daily-rotating hash of
IP + UA + siteId + dayas a bot-resistance signal. The raw IP is never written to the database — it’s hashed during the request and then discarded. - Browser, OS, device class, language, screen size, timezone, and the two-letter country code from the edge.
What we don’t do
- We don’t sell or share your data.
- We don’t run ads against it, and we don’t feed it to third-party advertising or marketing platforms.
- We don’t fingerprint beyond the broad device class above.
- The data belongs to the site owner. webfaCeMEdia hosts and processes it on their behalf.
Retention
- Raw events: 90 days (configurable per site).
- Daily rollups: indefinite.
- Weekly reports: indefinite.
Consent
Site owners are responsible for any consent disclosures their jurisdiction requires. Most reasonable analytics use is fine in Canada and the US — if you operate in the EU/UK or somewhere stricter, check your own rules. We’ll help you write the disclosure if you ask.
DNT
The tracker honours navigator.doNotTrack === '1'. The script still loads (so SPA route changes don’t leak), but no events are sent.