Is Sealmetrics GDPR, ePrivacy, CCPA, and PECR Compliant?
This is a self-assessment, not a certification. No supervisory authority certifies or validates analytics tools, and Sealmetrics holds no third-party security certification (no ISO 27001, no SOC 2). This page documents how the architecture is designed to meet the published criteria of each framework.
Sealmetrics is built to keep personal data to the minimum: we store nothing on the device and no data that identifies anyone. The session identifier is ephemeral: it rotates daily and, once rotated, not even we can reconstruct it. Reports are always aggregated. This is our own assessment against:
- GDPR (European Union)
- ePrivacy Directive (EU)
- CCPA (California Consumer Privacy Act)
- PECR (UK Privacy and Electronic Communications Regulations)
Sealmetrics achieves this by operating on a privacy-first, cookieless, consentless measurement model based entirely on isolated hits.
1. European Infrastructure & Legal Alignment
Sealmetrics is a European company, and:
- Analytics data is hosted and processed only in the EU (Dublin)
- Service emails (e.g. account notifications) are sent through Resend (US) under SCCs, as listed in Annex 3 of the DPA
- Operations are designed around GDPR’s data handling requirements
All customer analytics data therefore stays within the EU.
2. Privacy by Design: Minimal Data, No Tracking
Sealmetrics does not:
- Track individual users
- Correlate hits across sessions or days
- Build user profiles
- Store anything on the device (no cookies, localStorage or sessionStorage), or keep any persistent identifier or stored fingerprint
- Insert any tracking code in the user’s terminal beyond the measurement script
This architectural model is designed so that no data that identifies anyone is stored. The session identifier is pseudonymised data while the daily salt exists, processed under legitimate interest (GDPR Art. 6(1)(f)), and unrecoverable once it rotates. Together with the audience-measurement exemption criteria (own-site statistics only, no cross-site tracking, no reuse of the data), this is why, in our assessment, no cookie banner or consent is needed for Sealmetrics' own measurement. In Germany this is an open question: the DSK does not extend §25(2) TDDDG to audience measurement, and the tracker reads device properties via JavaScript, which may count as "access" under §25(1) — see Germany.
3. Based on “Isolated Hits” — No User Tracking
Sealmetrics does not track users.
It measures page views (hits) that are never linked to a person, and are grouped only within a single session — never across sessions or days.
For each hit, Sealmetrics collects only a small set of non-identifying fields:
- Timestamp
- User Agent (used for device classification; the raw string is used in flight and never written to storage — only the derived browser/OS/device categories persist in aggregates — never linked to a person)
- Current URL
- Referral URL
- Browser timezone (used to assign the country)
- Session identifier (a hash of standard device characteristics computed in the browser and never stored on the device; re-keyed on the server with a daily salt that is destroyed on rotation, so it cannot be linked across days — see What We Track)
These fields allow meaningful analytics, but are chosen so they do not identify anyone. The session identifier is a pseudonym for one day and cannot be reconstructed after the daily rotation, not even by Sealmetrics; reports are always aggregated.
4. How does Sealmetrics interpret the ePrivacy Directive?
Sealmetrics follows a strict privacy interpretation:
Tracking individual users without consent is not permissible — even anonymously — under the ePrivacy Directive.
Sealmetrics never tracks individuals and never correlates hits across sessions or days. Nothing is stored on the device; the tracker does read standard browser properties to compute the session identifier, so the consent exemption rests on the audience-measurement criteria described in Analytics Cookies: Consent Exemption Requirements.
This makes Sealmetrics one of the only analytics platforms capable of providing cookieless and consentless analytics that still offer valuable insights.
5. How the Architecture Maps to Each Regulation
GDPR
✔ No data that identifies anyone stored
✔ No persistent identifiers; the pseudonymised session identifier is unrecoverable after daily rotation
✔ Legal basis: legitimate interest (Art. 6(1)(f)); consent not used
✔ EU-based processing
ePrivacy Directive
✔ No individual user tracking
✔ No cross-session reconstruction
✔ Nothing stored on the device; no stored device fingerprint
✔ Session identifier computed in the browser from device characteristics and re-keyed on the server with a daily-rotating salt that is destroyed — not linkable across days or across sites (exemption self-assessed against the audience-measurement criteria)
CCPA
✔ No information that identifies a consumer stored; reports aggregated
✔ No user profiling
✔ No cross-site tracking
PECR
✔ No cookies or identifiers stored on the device
✔ No persistent technology used
Is Sealmetrics compliant by design?
Sealmetrics is designed for GDPR, ePrivacy, CCPA and PECR from the architecture up. This is our self-assessment, not a certification, and it rests on four facts about measurement:
- 0 data that identifies anyone
- 0 cookies
- 0 user identifiers
- Hits that are never joined to a person, or to each other across sessions or days
Those zeros describe measurement: what the tracking script does on your site. Signing in to the Sealmetrics dashboard uses a session cookie on my.sealmetrics.com, like any web application — it is not part of measurement and never reaches your visitors.
This enables marketers and analysts to access reliable, actionable analytics without compromising user privacy — and, on our self-assessment, without a consent banner for the analytics itself (Germany: open question).
- Sealmetrics collects only a small set of non-identifying fields per hit — timestamp, user agent (raw string never written to storage), current URL, referral URL, browser timezone and a daily-re-keyed session identifier — and never links hits to a person or across sessions.
- Analytics data is hosted and processed only in the EU (Dublin).
- This is a self-assessment against GDPR, ePrivacy, CCPA and PECR — Sealmetrics holds no ISO 27001 or SOC 2 certification and no supervisory authority certifies analytics tools.
Related documentation
- Does Sealmetrics comply with CNIL guidelines? — the French consent-exemption criteria in detail.
- Legal FAQ — Sealmetrics Compliance Questions — audits, DPIA, data processing, and retention questions.
- UK PECR Self-Assessment: Sealmetrics Compliance — the UK analytics exemption under DUAA 2025.
- GDPR and Cookieless Analytics — the GDPR reasoning behind the isolated-hit model.
- What We Track vs What We Don’t — the fields Sealmetrics records and nothing more.