Back to Produl

Legal

Privacy Policy

Last updated: April 2026

Produl is built around a single conviction: you should have powerful analytics without your visitors paying for them with their privacy. This policy explains what we collect, what we don't, and why.

1. What We Collect

Produl collects anonymous usage data about visits to websites that use our tracker. We deliberately collect the minimum needed to give site owners meaningful insights.

We record:

  • Page URL and referrer (stripped of query parameters that could contain personal data)
  • Country and region, derived from IP address — the IP itself is never stored
  • Browser family and operating system (e.g., “Chrome / macOS”)
  • Device type (desktop, mobile, or tablet)
  • Screen resolution
  • Session duration and bounce signal, derived from anonymous heartbeat pings
  • Core Web Vitals (LCP, FID, CLS) when reported by the browser
  • Custom events your site explicitly fires via our SDK

We do not collect names, email addresses, phone numbers, or any other information that could identify a specific person. We do not build visitor profiles or track individuals across sessions.

2. Cookies

The Produl tracker sets no cookieson your visitors' browsers. Zero. We do not use local storage, fingerprinting, or any other persistent identifier.

Because we never touch a browser's cookie jar, sites using Produl can truthfully tell their visitors that no tracking cookies are used. There is nothing to disclose in a cookie banner for analytics purposes.

Produl's own dashboard does use a session cookie (ma_session) strictly to keep you logged in. This cookie is httpOnly, never shared with third parties, and is deleted when you log out or your session expires.

3. Third Parties

We do not sell, rent, or trade your data — or your visitors' data — to anyone. Ever.

We use a small number of sub-processors to run the service:

  • Neon — serverless PostgreSQL database hosting where analytics data is stored
  • Vercel — infrastructure and CDN for serving the dashboard and tracker script
  • Resend — transactional email for account-related messages (password resets, receipts)
  • Stripe — payment processing for paid plans (we never see or store full card details)

Each sub-processor is bound by its own privacy and data processing agreements. None of them receive visitor-level analytics data.

4. Data Storage & Retention

All data is stored on servers in the United States via Neon's managed PostgreSQL infrastructure.

Analytics data (pageviews, events, Web Vitals) is retained for as long as your account is active. If you delete a site from your dashboard, all associated analytics data is permanently deleted within 30 days. If you close your account, all data is deleted within 30 days.

Account data (email address, billing information) is retained as required by law or until you request deletion, whichever comes first.

Active visitor records (used for real-time dashboards) are automatically expired and purged after a short inactivity window of approximately 5 minutes.

5. Your Rights

Because Produl does not collect personal data about your visitors, there is no individual profile to access, correct, or delete on their behalf. You can share this policy with your visitors as evidence that their data is not being collected.

As a Produl account holder, you have the right to:

  • Access all data associated with your account
  • Export your analytics data (via the dashboard or by contacting us)
  • Correct inaccurate account information
  • Delete your account and all associated data at any time
  • Object to or restrict processing of your account information

To exercise any of these rights, contact us at the address below. We will respond within 30 days.

6. Contact

Questions about this policy or how Produl handles data? We take privacy seriously and are happy to talk through specifics.

Reach us at privacy@produl.io.

We will acknowledge your message within 2 business days and resolve most inquiries within 14 days.