Privacy, cookieless mode and erasing data
Last updated
Metrickle is built to find lost conversions without collecting more than it needs. Raw IP addresses are never stored, form input is never read, and you can run a site in cookieless mode so nothing is stored on the visitor's device at all. This page explains what is stored, the choices you have, and how to delete data when someone asks.
For the full list of what is stored with each event, see data and privacy in the trust center.
What is never stored
- IP addresses. The raw IP address is not stored with events. Location is reduced to country, region and city.
- User-agent strings. They are reduced to browser, operating system and device type.
- Query strings. Page URLs are stored without them.
- Form input. The web script never reads what people type into form fields.
- Private text. Text inside elements marked
data-mk-maskordata-privateis never captured. - Bot traffic. Requests from known bots are dropped before they reach your numbers.
Cookieless mode
The web script never sets cookies. In standard mode it keeps a random visitor id and the current session in the browser's local storage, so it can recognise someone who comes back. In cookieless mode it stores nothing on the device: no cookies, no local storage and no session storage.
To turn it on, add data-cookieless to the script tag:
<script defer src="https://app.metrickle.com/m.js" data-key="mk_pub_…" data-cookieless></script>
If you install the npm package, pass cookieless: true to init. See the web SDK.
You can mix modes: run your marketing site cookieless and your signed-in product in standard mode, as separate apps.
How visitors are counted
Without an id on the device, the server works out who is who for one day at a time. The visitor id is a keyed hash (HMAC-SHA256) of the day, the app, the IP address and the user agent, using a secret that never leaves Metrickle. The raw IP address is then dropped. Because the day is part of the hash, the same person gets a new id every day, so nobody can be followed from one day to the next. Sessions are approximated in 30-minute windows.
What you give up
| Feature | Standard mode | Cookieless mode |
|---|---|---|
| Visitors, pages, sources, campaigns | Yes | Yes |
| Goals, funnels, tasks and revenue | Yes | Yes |
| Friction, accessibility settings, heatmaps | Yes | Yes |
| Feedback widget | Yes | Yes |
| Sessions | Tracked on the device | Approximated on the server |
| Returning visitors across days | Yes | No: the visitor id changes daily |
| Retention cohorts | Yes | No: every day's visitors look new |
| In-app surveys | Yes | No: they need storage |
| Session replay | Yes, with consent | No: it needs storage and consent |
Visitors' own choices
- The web script honours Do Not Track and Global Privacy Control by default. If either is on, the visitor is opted out and nothing is sent.
- Your app can offer its own opt-out with
metrickle.optOut(), and undo it withmetrickle.optIn(). In standard mode the choice is remembered on the device.
What to ask for in a consent banner
The question Metrickle needs your banner to ask is about session replay: may we record how you use this site, with text and inputs hidden? When the visitor says yes, call:
metrickle.consent({ replay: true });
Replay waits for this call by default, and metrickle.consent({ replay: false }) stops it again. See consent for session replay.
In cookieless mode nothing is stored on the device and replay never runs. Whether that changes what you must ask visitors for depends on where you operate and what else your site does, so confirm your own obligations with whoever advises you on privacy law.
Masking
Heatmap page snapshots and session replays mask every input value, always, and mask all page text by default. You can show regions you know are safe with data-mk-unmask, and leave an element out entirely with data-mk-block. Owners and Admins can force all text to be masked in every app from the Security page. See page snapshots and workspace-wide rules.
Feedback screenshots are only taken when the person chooses to attach one. Their browser asks permission each time, and they can hide parts of the image before sending.
Erase a visitor's data
To answer a right-to-erasure request under GDPR or CCPA:
- Open the app, choose Settings and find Privacy & data.
- Enter the person's visitor id or your own user id for them.
- Choose Erase.
This deletes, for that app:
- their events, including survey answers;
- their session replay recordings;
- their feedback reports, with any screenshots;
- their records as a study participant;
- the links between them and your revenue sources.
If you enter an email address instead, Metrickle also removes support tickets and study participants matched to that email.
If the workspace has a warehouse export set up, the erasure is listed in the next export, so you can remove the same person from your warehouse. See the warehouse export.
Erasing needs the permission "Erase a visitor's data". Owners and Admins have it by default. It is a person-only permission, so an API token or AI assistant can never erase data. See team and access.
How long history is kept
Each plan sets the most history a workspace can keep. See plans and billing.
To keep less, an Owner or Admin can set a shorter period:
- Open Security in the sidebar and find Data.
- Enter the Days of history to keep. You can keep less than your plan allows, not more. Leave it empty to keep everything your plan allows.
- Choose Save data rules. If the new period is shorter, you're asked to confirm.
Once a day, Metrickle deletes events, replay recordings and feedback reports (with their screenshots) older than that period, for good. A large backlog can take a few days to clear.
Deleting an app
To delete an app and everything in it, open the app's Settings and choose Delete next to Delete app, then type the app's name to confirm. Ingestion stops and its events, replays and feedback screenshots are deleted. This can't be undone.
Where data is stored
Your data is stored in the region chosen for your workspace. See data location.