Privacy Policy
Effective: September 2026
Last updated: September 2026
This policy explains what information Vistiqo handles, why, and for how long. It covers two different groups of people: our own customers, and the visitors to the websites those customers track.
1. Two groups of people, two different relationships
This distinction matters throughout the rest of this page.
Vistiqo customers are people who create a Vistiqo account, add their websites and view the dashboard. For their account information, Vistiqo decides how and why data is handled - we are the controller.
Website visitors are people who browse a website that has the Vistiqo script installed. They have no relationship with Vistiqo, do not have Vistiqo accounts, and usually will not have heard of us. For their data, the customer who runs the website decides what is collected and why - they are the controller and we act as their processor, handling analytics on their instructions.
If you are a visitor with a question about analytics collected on a particular website, the operator of that website is the right first point of contact, since they decide what is collected there. You are still welcome to contact us at support@vistiqo.online and we will help route the request.
2. Information about Vistiqo customers
Account information. Vistiqo accounts are created only through Google sign-in. From Google we receive your email address, your name and profile picture where you have them, and a stable identifier for your Google account. We store those, along with when your account was created and when you last signed in. We never receive your Google password, and Vistiqo has no password of its own.
Website configuration. For each website you add: its name, domain, time zone, an optional description, the tracking key that identifies it, and whether you have enabled a public dashboard.
Subscription information. Your plan, subscription status, current billing period, whether a cancellation is scheduled, and the customer and subscription identifiers issued by Creem. We also keep a record of the payment webhooks we receive, for reconciliation and to avoid processing the same event twice. Vistiqo never receives or stores card numbers or other payment credentials - those go directly to Creem.
Support correspondence. If you email us, we keep the message so we can respond.
3. Information collected from website visitors
When the Vistiqo script runs on a customer's website, it records the following about each visit. This is the complete list of what is stored.
| Category | What is stored |
|---|---|
| Page views | Page path and URL, page title, hostname, timestamp, referring URL and referring domain, and UTM campaign parameters where present in the link |
| Sessions | Start and last-activity time, duration, number of pages viewed, entry and exit page, landing URL, referrer, traffic channel, and whether the visit bounced |
| Visitor record | A random identifier generated in the browser, plus first-seen and last-seen times |
| Approximate location | Country, country code, region and city, derived from the IP address |
| Device and software | Device type (desktop, mobile, tablet), device model where reported, browser and version, operating system and version, screen width and height, and browser language |
| Interactions | Clicks on links leading away from the site (destination and source page), and any custom events the website operator chooses to send |
IP addresses are not stored. A visitor's IP address is used at the moment of the request to look up an approximate country, region and city, and to rate-limit abusive traffic. Only the resulting location is saved. There is no IP address column anywhere in the Vistiqo database.
Vistiqo does not ask visitors for names, email addresses or account details, does not attempt to identify individuals by name, and does not track visitors across unrelated websites. The visitor identifier is scoped to a single tracked website and is not shared between customers. Note that a website operator can send custom event data of their own choosing; what that contains is their responsibility, and they should not put sensitive personal information in it.
4. Why we handle this information
Account and subscription information is used to give you access, run your subscription, enforce your plan's limits, provide support, and keep the service secure. Analytics data is processed to produce the dashboards our customers are paying for. We also use operational logs to diagnose faults and protect the service from abuse.
We do not sell personal data, we do not use it for advertising, and we do not use one customer's analytics for anything other than serving that customer.
Where a data-protection law such as the GDPR applies, the customer running the tracked website determines the lawful basis for analytics collected on it and is responsible for providing notice and obtaining consent where required. We handle that data on their instructions.
5. Who we share information with
Vistiqo uses a deliberately small number of external providers. These are all of them.
- Google - account sign-in. Google tells us your email, name, profile picture and account identifier when you sign in. See Google's Privacy Policy.
- Creem - payments, as merchant of record. Creem receives what it needs to take payment and issue an invoice, including your email address; it collects your payment details directly. See Creem's Privacy Notice and Buyer Terms.
- ip-api.com - IP geolocation. A visitor's IP address is sent to this service to obtain an approximate country, region and city. No account information is sent. See its legal terms.
We may also disclose information where the law requires it, or to protect the rights and safety of Vistiqo, our customers or others. If Vistiqo were ever sold or transferred, data could move with the business; we would tell customers before that happened.
These providers operate internationally, so information may be handled outside your country. Vistiqo does not currently publish a specific list of hosting locations or standard contractual clauses; if your compliance process requires that detail, ask us at support@vistiqo.online before subscribing.
6. Cookies and browser storage
The Vistiqo application uses a small number of essential cookies to keep you signed in
and to protect forms. The Vistiqo tracking script sets no cookies at all - it uses
localStorage and sessionStorage instead. The
Cookie Policy explains each one in detail.
7. How long we keep information
Analytics are kept for the retention window of the account's current plan: 12 months on Starter and 24 months on Growth. During the trial, and for 30 days after entitlement lapses, analytics are preserved; after that an unsubscribed account retains only the most recent 30 days. A scheduled cleanup removes analytics older than that window; because it runs periodically rather than continuously, data may persist briefly past the boundary before the next pass. Deletion is permanent.
If an account moves to a plan with a shorter window, the shorter window applies from then on and older analytics age out on subsequent cleanup runs. Websites above a plan's limit are deactivated rather than deleted - they stop collecting new data but keep what they already have, subject to retention.
Account and subscription records are kept while your account exists. Subscription and payment history may be retained after account deletion where we or Creem need it for accounting, tax or legal purposes - so we cannot promise that every trace is erased immediately.
8. Your choices and requests
Depending on where you live you may have rights to access, correct, export or delete personal data, or to object to some processing. To make a request as a Vistiqo customer, email support@vistiqo.online. We will verify that the request comes from the account holder before acting.
If your request concerns analytics collected on someone else's website, we will normally need to refer it to that website's operator, since they decide what is collected there and we act on their instructions. We will support them in responding.
You can stop Vistiqo analytics on a site you control at any time by removing the script, deactivating the website in your dashboard, or deleting it.
9. Processing on behalf of customers
For analytics collected on tracked websites, Vistiqo acts on the customer's instructions: we process that data to provide the dashboard, we do not use it for our own purposes, and we apply the retention window attached to the customer's plan. The sub-processors involved are the three providers listed in section 5.
Vistiqo does not currently publish a standalone Data Processing Agreement. Producing one that is actually binding requires legal-entity details, a governing jurisdiction and an international-transfer mechanism that are not established for this service yet, and we would rather say so than publish a document that looks official but is not. If your organisation requires a signed DPA before purchasing, contact support@vistiqo.online and we will handle it as a business matter rather than pointing you at a generic form.
10. Security
Measures actually in place: traffic to Vistiqo is served over HTTPS; sign-in is delegated to Google, so we hold no passwords; access to the application requires an authenticated session, and administrative pages are restricted by role; every request for analytics data is checked server-side against the requesting account's ownership of the website, so one customer cannot read another's data; incoming payment webhooks are rejected unless they carry a valid signature; the tracking endpoints are rate-limited; and API keys and secrets are supplied through configuration rather than being written into the application's source code.
To be straightforward about the limits: Vistiqo does not hold SOC 2, ISO 27001 or PCI DSS certification, has not undergone third-party penetration testing, and we make no claim about database-level encryption at rest beyond whatever the underlying hosting platform provides by default. No service can promise perfect security.
11. Children
Vistiqo is a business tool and is not directed at children. We do not knowingly create accounts for children. Website operators are responsible for the appropriateness of analytics on sites aimed at children under the laws that apply to them.
12. Changes and contact
We will update this policy as the product changes, and the "last updated" date above will always reflect the current version. For anything in this policy, or to make a data request, contact support@vistiqo.online.
Questions about this policy?
Contact us at support@vistiqo.online for support, billing, privacy or data requests. This is the contact point for every topic covered by our policies.
Related