Metrickle

Privacy, cookieless mode and erasing data

Last updated

Metrickle is built to find lost conversions without collecting more than it needs. Raw IP addresses are never stored, form input is never read, and you can run a site in cookieless mode so nothing is stored on the visitor's device at all. This page explains what is stored, the choices you have, and how to delete data when someone asks.

For the full list of what is stored with each event, see data and privacy in the trust center.

What is never stored

  • IP addresses. The raw IP address is not stored with events. Location is reduced to country, region and city.
  • User-agent strings. They are reduced to browser, operating system and device type.
  • Query strings. Page URLs are stored without them.
  • Form input. The web script never reads what people type into form fields.
  • Private text. Text inside elements marked data-mk-mask or data-private is never captured.
  • Bot traffic. Requests from known bots are dropped before they reach your numbers.

Cookieless mode

The web script never sets cookies. In standard mode it keeps a random visitor id and the current session in the browser's local storage, so it can recognise someone who comes back. In cookieless mode it stores nothing on the device: no cookies, no local storage and no session storage.

To turn it on, add data-cookieless to the script tag:

<script defer src="https://app.metrickle.com/m.js" data-key="mk_pub_…" data-cookieless></script>

If you install the npm package, pass cookieless: true to init. See the web SDK.

You can mix modes: run your marketing site cookieless and your signed-in product in standard mode, as separate apps.

How visitors are counted

Without an id on the device, the server works out who is who for one day at a time. The visitor id is a keyed hash (HMAC-SHA256) of the day, the app, the IP address and the user agent, using a secret that never leaves Metrickle. The raw IP address is then dropped. Because the day is part of the hash, the same person gets a new id every day, so nobody can be followed from one day to the next. Sessions are approximated in 30-minute windows.

What you give up

FeatureStandard modeCookieless mode
Visitors, pages, sources, campaignsYesYes
Goals, funnels, tasks and revenueYesYes
Friction, accessibility settings, heatmapsYesYes
Feedback widgetYesYes
SessionsTracked on the deviceApproximated on the server
Returning visitors across daysYesNo: the visitor id changes daily
Retention cohortsYesNo: every day's visitors look new
In-app surveysYesNo: they need storage
Session replayYes, with consentNo: it needs storage and consent

Visitors' own choices

  • The web script honours Do Not Track and Global Privacy Control by default. If either is on, the visitor is opted out and nothing is sent.
  • Your app can offer its own opt-out with metrickle.optOut(), and undo it with metrickle.optIn(). In standard mode the choice is remembered on the device.

The question Metrickle needs your banner to ask is about session replay: may we record how you use this site, with text and inputs hidden? When the visitor says yes, call:

metrickle.consent({ replay: true });

Replay waits for this call by default, and metrickle.consent({ replay: false }) stops it again. See consent for session replay.

In cookieless mode nothing is stored on the device and replay never runs. Whether that changes what you must ask visitors for depends on where you operate and what else your site does, so confirm your own obligations with whoever advises you on privacy law.

Masking

Heatmap page snapshots and session replays mask every input value, always, and mask all page text by default. You can show regions you know are safe with data-mk-unmask, and leave an element out entirely with data-mk-block. Owners and Admins can force all text to be masked in every app from the Security page. See page snapshots and workspace-wide rules.

Feedback screenshots are only taken when the person chooses to attach one. Their browser asks permission each time, and they can hide parts of the image before sending.

Erase a visitor's data

To answer a right-to-erasure request under GDPR or CCPA:

  1. Open the app, choose Settings and find Privacy & data.
  2. Enter the person's visitor id or your own user id for them.
  3. Choose Erase.

This deletes, for that app:

  • their events, including survey answers;
  • their session replay recordings;
  • their feedback reports, with any screenshots;
  • their records as a study participant;
  • the links between them and your revenue sources.

If you enter an email address instead, Metrickle also removes support tickets and study participants matched to that email.

If the workspace has a warehouse export set up, the erasure is listed in the next export, so you can remove the same person from your warehouse. See the warehouse export.

Erasing needs the permission "Erase a visitor's data". Owners and Admins have it by default. It is a person-only permission, so an API token or AI assistant can never erase data. See team and access.

How long history is kept

Each plan sets the most history a workspace can keep. See plans and billing.

To keep less, an Owner or Admin can set a shorter period:

  1. Open Security in the sidebar and find Data.
  2. Enter the Days of history to keep. You can keep less than your plan allows, not more. Leave it empty to keep everything your plan allows.
  3. Choose Save data rules. If the new period is shorter, you're asked to confirm.

Once a day, Metrickle deletes events, replay recordings and feedback reports (with their screenshots) older than that period, for good. A large backlog can take a few days to clear.

Deleting an app

To delete an app and everything in it, open the app's Settings and choose Delete next to Delete app, then type the app's name to confirm. Ingestion stops and its events, replays and feedback screenshots are deleted. This can't be undone.

Where data is stored

Your data is stored in the region chosen for your workspace. See data location.