Skip to main content

Security & Privacy

Sealmetrics measures websites without storing anything on the device or any data that identifies anyone: a small set of non-identifying fields per hit, nothing written to the visitor's device, no identifier carried across days or sessions, and all customer analytics data stored in Dublin, Ireland. Under the GDPR, the session identifier is pseudonymised data during the day, processed under legitimate interest (Art. 6(1)(f)); once the daily salt rotates it cannot be reconstructed, not even by Sealmetrics, and reports are always aggregated. For ePrivacy, nothing is stored on the device, and the tracker's reading of standard browser properties to compute its daily re-keyed session identifier relies on the audience-measurement exemption criteria — the reasoning is set out in full in What is Consentless Analytics?.

Sealmetrics holds no third-party security certification (no ISO 27001, no SOC 2), and no supervisory authority certifies analytics tools. The pages under compliance are our own self-assessments against published criteria. A Data Processing Agreement is included and ready to sign at sealmetrics.com/dpa; Annex 3 of that DPA is the authoritative subprocessor list.

Start here​

The consentless model​

Privacy practice​

Data, hosting and quality​

Account security​

Auditing someone else's tags​

In short
  • A small set of fields per hit (timestamp, user agent, URL, referrer, browser timezone, a session identifier re-keyed daily); no cookies, no IP stored, no persistent identifier.
  • All customer analytics data lives in Dublin, Ireland; retention is fixed at 1 day / 90 days / 24 months by aggregation level.
  • No certifications and no regulator approval exist; compliance pages are self-assessments, and the DPA's Annex 3 lists the subprocessors.
Written and maintained by the Sealmetrics Team