Security & Privacy
Sealmetrics measures websites without storing anything on the device or any data that identifies anyone: a small set of non-identifying fields per hit, nothing written to the visitor's device, no identifier carried across days or sessions, and all customer analytics data stored in Dublin, Ireland. Under the GDPR, the session identifier is pseudonymised data during the day, processed under legitimate interest (Art. 6(1)(f)); once the daily salt rotates it cannot be reconstructed, not even by Sealmetrics, and reports are always aggregated. For ePrivacy, nothing is stored on the device, and the tracker's reading of standard browser properties to compute its daily re-keyed session identifier relies on the audience-measurement exemption criteria — the reasoning is set out in full in What is Consentless Analytics?.
Sealmetrics holds no third-party security certification (no ISO 27001, no SOC 2), and no supervisory authority certifies analytics tools. The pages under compliance are our own self-assessments against published criteria. A Data Processing Agreement is included and ready to sign at sealmetrics.com/dpa; Annex 3 of that DPA is the authoritative subprocessor list.
Start here
- What is Consentless Analytics? — the concept, the GDPR and ePrivacy reasoning, and what the model can and cannot measure
- What We Track vs What We Don't — the field-by-field list, with retention for each field
The consentless model
- How Consentless Tracking Works — the technical mechanics, step by step
- Why Sealmetrics Can Measure Without Consent — the short answer on consent
- Benefits of Consentless Tracking — what measuring without a consent gap changes in practice
- How Attribution Works Without a User-ID — last-click attribution without identifiers
Privacy practice
- How Sealmetrics Protects User Privacy — the concrete protections
- Privacy by Design Principles — the seven principles mapped to architecture
- How Sealmetrics determines the country without using IP addresses — timezone-based geolocation
Data, hosting and quality
- Data Location & Retention — EU hosting, retention schedule, encryption, deletion and export
- Bot Detection & Traffic Quality — how automated traffic is filtered out of reports
- How Sealmetrics Reduces AdBlocker Data Loss — first-party delivery and why filter lists do not match
Account security
Auditing someone else's tags
- What Is This Domain in My Cookie Audit? — lookup table of external analytics domains
- What Is demdex.net? — Adobe's Experience Cloud ID cookies
- What Is omtrdc.net? — Adobe Analytics' collection domain
- A small set of fields per hit (timestamp, user agent, URL, referrer, browser timezone, a session identifier re-keyed daily); no cookies, no IP stored, no persistent identifier.
- All customer analytics data lives in Dublin, Ireland; retention is fixed at 1 day / 90 days / 24 months by aggregation level.
- No certifications and no regulator approval exist; compliance pages are self-assessments, and the DPA's Annex 3 lists the subprocessors.
Related documentation
- Compliance self-assessments — GDPR, ePrivacy, CNIL, AEPD, PECR analysed one by one
- Data Subject Rights (DSAR) — how access and erasure requests work
- Subprocessors — who touches customer analytics data