Privacy Policy

What we collect, why and for how long. The data controller is Webcode; full registration details are in the Terms of Service.

Effective from September 1, 2026

1. Two roles, two kinds of data

This document covers two situations that should not be confused.

For your metuno account data we are the controller: we decide why and how it is processed.

For data collected by the measurement script on your website we are a processor, and you are the controller. We process it solely to show you statistics, and solely in line with this document, which serves as the data processing agreement.

2. Your account data

We store an email address, a password hash, an optional display name, the chosen plan and the dates of account creation and last login. We do not know your password - only its hash is stored.

The legal basis is performance of a contract (Article 6(1)(b) GDPR) and, for billing and accounting records, a legal obligation (Article 6(1)(c) GDPR).

Account data is kept for as long as the account exists. Deleting the account removes it immediately along with all measurement data; only accounting documents remain, for the period required by tax law.

We pass the email address to our email provider in order to deliver a confirmation message or a password reset link. Outside those two cases nothing leaves with it - we run no marketing mailings.

3. Data collected on websites

The measurement script records only these fields:

Page address
The path of the visited page, without form field contents.
Referrer
Where the visit came from, together with UTM campaign parameters.
Browser and system
Name and version, read from the header the browser sends.
Device type
Desktop, phone or tablet, and a window width bracket.
Country, region, city
Derived from the network address using a local database on our server.
Language and time zone
From the browser header.
Time on page and scroll depth
Measured by the script during the visit.
Speed metrics
Core Web Vitals for that single page load.
Pseudonym and visit id
Numbers described in the next section.

4. How we recognise a visitor

We store no cookies and nothing else in the browser. Instead we compute a single-use pseudonym as a cryptographic hash of three things: the site id, the truncated network address and the browser header, signed with a random salt for that day.

The address is truncated before it enters the calculation: IPv4 loses its last octet, IPv6 is cut to /48. The full address exists in server memory for the duration of one request and is never written down - the database schema has no column for it.

The salt changes with every UTC day and its row is deleted after two days. A pseudonym from yesterday cannot be joined to one from today - not by you and not by us, because the material needed to do so no longer exists.

The site id goes into the hash, so the same person visiting two sites measured by metuno has two different pseudonyms. Tracking anybody across sites is technically impossible.

We do not ask the browser about its properties - no canvas, no font list, no screen resolution, nothing used to build a device fingerprint.

5. Cookies

We set no cookies and store no data in the browser on our customers websites.

In the metuno dashboard we use one session cookie, strictly necessary to keep you logged in. It is not used for analytics and requires no consent.

6. How long we keep data

  • Measurement events - 25 months from collection, then deleted automatically.
  • Daily salts - two days.
  • Account data - until the account is deleted.
  • Accounting documents - for the period required by tax law.

7. Who we share data with

We do not sell data, do not share it with advertisers or data brokers, and do not pass it to anyone for their own purposes. The dashboard loads no third-party scripts.

We use two subprocessors and only two. The first is OVH SAS, based in France, the provider of the servers the Service runs on; all of them are in Warsaw.

The second is Resend (Plus Five Five, Inc.), which delivers account messages: email confirmation and password changes. It receives only the recipient address and the contents of that one message - never measurement data from websites. Sending happens in the Irish region, that is, within the European Union.

Country and city are resolved from the DB-IP Lite database downloaded onto our server - no location lookup leaves our infrastructure.

Data may be disclosed to competent authorities where required by law.

8. Transfers outside the EEA

Measurement data collected on websites never leaves the European Union under any circumstances. It sits on servers in Warsaw with no non-EU service connected to it.

Account holders email addresses are additionally processed by Resend, in its Irish region, so also within the Union. The company is incorporated in the United States, so despite the European server location the processing relies on standard contractual clauses in our data processing agreement with them. This concerns the account email address only - not the data of people visiting your website.

9. Your rights

For data where we are the controller you have the right of access, rectification, erasure, restriction of processing, data portability and to object to processing.

You can delete your account and all its data yourself in the dashboard settings. For anything else write to contact@metuno.com - we reply within thirty days.

You also have the right to lodge a complaint with a supervisory authority; ours is the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland.

For measurement data collected on someone else website, the controller is its owner and requests should go to them. We will help them comply. Note that a pseudonym expires after one day, so beyond that we cannot locate a particular person data - not because we will not, but because there is nothing left to look for.

10. Security

Connections to the dashboard and to the event collector are encrypted. Passwords are stored only as hashes. Access to infrastructure is limited to people who need it.

The event collector, the only component exposed to traffic from the whole internet, has no access to the account database or to passwords. Even a successful attack on that process gives no way into customer data.

11. Changes to this policy

We will announce material changes at the account email address at least fourteen days before they take effect. The effective date of the current version is shown at the top of this document.

enpldees