Simplytics

Privacy Policy

Simplytics is built so that we know as little as possible about the people who visit the websites we track. This page explains exactly what we collect and what happens to it.

Visitors of websites that use Simplytics

Simplytics account holders

Other companies involved

Named in full, including the two that only ever see an account holder rather than a visitor:

No advertising network, no data broker, no analytics-on-our-analytics. A visitor to a site you track is never in contact with anything except Cloudflare's edge. The subprocessor list says what each company gets and where it sits.

Where data is stored, and who can reach it

All analytics data lives in a Cloudflare D1 database whose primary storage is located in the European Union (Warsaw, Poland). Pages are delivered through Cloudflare's global network.

Simplytics is operated by one person based in India. Storage stays in the EU, but running the service — deploying code, investigating a fault, answering a support email — means reading that EU-hosted database from India. Under the GDPR that access is itself an international transfer: what counts is that the data is made available to someone in a third country, not where the disk sits. India has no EU adequacy decision and is not covered by UK adequacy regulations. This is written down because you may need it for your own records, and because no amount of EU hosting would make it untrue.

What limits it: the primary database stays in the European Union, and the only personal data held about you as an account holder is your email address and your subscription status. What does not limit it is a promise that has not been made — there are no Standard Contractual Clauses behind this yet, no transfer risk assessment, and no EU or UK representative appointed. Claiming any of those would be worth less than saying nothing. The data-processing agreement says the same thing in the place a customer's lawyer will look for it.

GDPR

For visitor data, the website owner using Simplytics is the data controller and Simplytics acts as a processor. Because no personal data is stored — identifiers are anonymised, rotated daily, and raw records deleted nightly — no consent banner is required on tracked websites. For account data, Simplytics is the controller.

Why we are allowed to hold your account data

GDPR Article 13 asks a controller to name a lawful basis for each purpose rather than one for the whole page, so here they are separately.

Where the basis is legitimate interests you have the right to object, and for the marketing ones objecting is a single click: every such email carries a link that stops all of them, and the account page has the same switch. Where the basis is consent you can withdraw it at any time, and withdrawing does not affect anything sent before you did.

How long we keep it

Your rights

Under the GDPR and the UK GDPR you can ask for a copy of your data, to have it corrected, to have it deleted, to restrict what we do with it, to object to processing based on legitimate interests, and to receive it in a portable form. Where we rely on consent you can withdraw it.

Most of these you can exercise yourself without asking anyone: full CSV export at any time, the email toggles on the account page, and account deletion from the same page. For anything else, email nikhil@simplytics.dev and you will get an answer within one month. There is no charge and no form.

Two limits worth stating rather than leaving you to discover. Visitor data is de-identified within two days at the outside, so for a visitor we usually cannot locate the data to act on a request — that is a consequence of the design, not a refusal. And erasure reaches the live database immediately but backups only as they age out, which is what the 90 days above means.

If we get it wrong, you can complain about us. In the UK that is the Information Commissioner's Office (ico.org.uk/make-a-complaint). In the EU it is the supervisory authority for the country you live in; the European Data Protection Board keeps the list (edpb.europa.eu). You do not have to raise it with us first, though we would rather you did.

Is giving us this data required?

Your email address is: it is the account, and there is no way to have one without it. Everything else is optional — the digest, the spike alerts, your timezone, and how many sites you add. Nothing is fed into automated decision-making and nothing is profiled.

Who we are

For your account data the controller is Simplytics, which is not a company: it is one person, based in India, and the about page says so plainly. The contact point for anything in this policy, including every right above, is nikhil@simplytics.dev.

Article 13 expects more than that, and the rest is missing. We publish no postal address. We have appointed no EU representative and no UK representative, which a controller outside both is normally expected to have. There are no Standard Contractual Clauses behind the operator access described further up. There is no data protection officer, though at this size one is not required. None of those exists, and rather than print a plausible-looking placeholder we are naming the gaps — a made-up address would be worth less to you than this paragraph. If you need any of them before you can buy, say so and you will get a straight answer about whether and when.

Contact

Questions about privacy or data requests: nikhil@simplytics.dev