---
description: What UsherStats records about your visitors and what it does not, cookies, Global Privacy Control, GDPR roles, and what to tell your readers.
nav: Privacy & compliance
---
# Privacy and compliance

UsherStats is built to measure a site without following the people who read it.

## What is recorded

For each confirmed pageview: the page's path; the `utm_source`, `utm_medium` and `utm_campaign` tags (and no other part
of the address); the referring site's hostname (not its full address); the browser window's width, language and time
zone; scroll depth, time on page and whether the reader interacted; and a page counter for the tab. From the request,
UsherStats derives the country, the network operator, a device class and a summary of the connection's encryption
settings.

With the Worker SDK or proxy mode, each request your server answers is recorded too: its path, status, and the kind of
client that made it.

## What is not

- **No cookies for analytics**, and no identifier that follows a reader from one site to another, or from one day to
  the next. The page counter lives in the tab's session storage, which the browser clears when the tab closes.
- **No IP addresses and no full browser identification strings** are stored. They are used while a request is handled,
  to classify it, and then dropped.
- **No names, email addresses or form contents.** Never put them in event names or labels either.
- **Global Privacy Control**: browsers that send it are not recorded at all.

Two cookies can exist on your domain, both first-party and both outside analytics:

- `us_pass`, set only on a visitor who has just completed a [bot protection](bot-protection.md) check, so they are not
  asked again for a day;
- the internal-traffic cookie, set only in your own team members' browsers when they mark them as internal (see
  [Concepts](concepts.md#internal-traffic)).

## GDPR roles

For your visitors' data, you are the **controller** and UsherStats is your **processor**. Our
[data processing agreement](https://usherstats.com/dpa) sets out the processor terms (GDPR Article 28) and covers
transfers with the Standard Contractual Clauses. The companies we use are on the
[subprocessors](https://usherstats.com/subprocessors) page, and the [privacy policy](https://usherstats.com/privacy)
describes everything in full.

## What to put in your own privacy policy

You can describe UsherStats along these lines, adjusted to how you use it:

> We use UsherStats to measure how our site is used. It sets no cookies for analytics, stores no personal data and no
> IP addresses, and does not follow you across sites or days. It records the page you visited, the site that referred
> you, campaign tags, your browser's language, time zone and window size, your country and network, and how long you
> stayed. Browsers that send Global Privacy Control are not recorded. UsherStats processes this data on our behalf.

If you use bot protection, add that requests are checked for automated traffic and some visitors may be asked to
complete a short check, which sets a cookie for a day. Whether you need consent for analytics depends on where you and
your readers are and how you use the data; this page is not legal advice.

## Data retention and deletion

Data is kept for as long as your account exists unless you delete it or set a retention period for a site. See
[Exporting your data](data-export.md).

## Contact

Privacy questions: privacy@usherstats.com.
