Privacy policy
Last updated July 7, 2026. RevSonar is built to answer business questions without surveilling people. This page explains exactly what we collect, in plain language.
Who we are
RevSonar ("we") is a web analytics service operated from the Netherlands. Questions about this policy or your data: support@revsonar.com.
We wear two hats. For visitors of websites that use RevSonar, we process data on behalf of the site owner (they are the controller, we are the processor). For our own website and your RevSonar account, we are the controller.
What the tracker collects on our customers' sites
- Page URL and referrer
- Marketing labels present in the URL (UTM parameters and
ref) - Browser, operating system, and device type
- Viewport size
- Country, region, and city (derived at the network edge)
- Goal events and payment attribution the site owner sets up (for example a Stripe payment amount linked to the session that produced it)
What we never collect: we do not store IP addresses, we do not fingerprint devices, we do not track people across different websites, and we never sell or share analytics data with advertisers or data brokers. IP addresses are used transiently to derive an approximate location and (in cookieless mode) a short-lived identifier, then discarded.
How visitors are identified
In the default mode the tracker sets two first-party cookies on the customer's domain: revsonar_visitor_id (2 years) and revsonar_session_id (30 minutes). They contain random identifiers and nothing else.
In cookieless mode nothing is stored in the browser. Visitors are counted using a hash of the site, the IP address, and the browser, salted with a secret that rotates every day. The same person therefore cannot be recognized from one day to the next, and never across different sites.
Site owners can additionally link a visitor to a user of their own product (for example an account id or name) via the identify API. That data belongs to the site owner and is only shown to them.
Your RevSonar account
When you create an account we store your name, email address, and workspace membership through our authentication provider (Clerk). Billing is handled by Clerk Billing and Stripe; we never see your card number. We use RevSonar itself on revsonar.com, subject to everything described above.
Where data lives and who touches it
Analytics data is stored in the European Union (Neon, PostgreSQL, AWS Frankfurt). The application runs on Vercel. Subprocessors we rely on:
- Vercel (hosting and edge network)
- Neon (database, EU region)
- Clerk (authentication and billing)
- Stripe (payments and payment attribution)
- Vercel AI Gateway (powers the optional AI assistant; only questions account holders type are sent, never raw visitor data feeds)
Retention
Analytics data is kept for the retention period of your plan (see pricing) and deleted when a site or workspace is deleted. Account data is kept until you delete your account.
Your rights
Under the GDPR you can request access to, correction of, or deletion of your personal data, and you can lodge a complaint with your supervisory authority (in the Netherlands: Autoriteit Persoonsgegevens). If you are a visitor of a site that uses RevSonar, direct requests to that site's owner; we will assist them. For anything else, email support@revsonar.com.
Data processing agreement
If your use of RevSonar requires a signed DPA, email us and we will provide one.
Changes
If this policy changes in a way that matters, we will note it here and email account holders. The date at the top always reflects the latest revision.