1. Privacy-first principles
VisitorPing gives website owners real-time awareness while collecting only what the product needs. We do not store raw IP addresses, use third-party or cross-site cookies, or perform cross-site fingerprinting.
This policy explains what the tracking script collects so you can make an informed decision about your own website’s consent requirements. It is not legal advice.
2. Browser identifier
VisitorPing does not set HTTP cookies or share an identifier across websites. It stores a randomly generated first-party identifier in the visitor’s browser using localStorage. This lets the same website recognize a returning visitor.
The identifier persists until the visitor clears browser storage. Many privacy rules treat browser storage used for analytics similarly to cookies, even when no literal cookie is used.
3. Information we collect
- Visitor identifier: a random first-party ID used to group activity into visits and recognize returns.
- Approximate location: country, region, and city derived from network metadata. Raw IP addresses are not stored.
- Acquisition information: referrer information and public campaign parameters such as UTM values.
- Page and engagement activity: visited paths, scroll milestones, phone-link clicks, and form-submission events. VisitorPing does not read or store what a visitor types into a form.
4. Consent responsibilities
Because the browser identifier is used to recognize returning visitors, consent requirements may apply under the EU ePrivacy rules, UK rules, and laws in other jurisdictions.
You are responsible for determining whether your website needs consent before loading VisitorPing. VisitorPing cannot determine the law that applies to your audience. Consult qualified legal counsel if you need advice for your situation.
5. Retention, export, and deletion
Active Starter, Pro, and Agency accounts retain 7, 30, and 90 days of visitor history respectively. Older visitor records, sessions, and events are removed in daily batches.
After paid or trial access ends, the dashboard remains available in read-only mode and retained visitor history can be exported. New tracking continues for a 30-day recovery period, then pauses. Visitor activity data is scheduled for deletion 90 days after access ends, with a warning sent at least seven days before automated deletion.
Connected-service credentials, imported reporting data, account configuration, billing records, and transaction records are retained while needed to provide the Service, secure the account, resolve disputes, or meet legal obligations. Deleting an eligible VisitorPing organization deletes its connected-service credentials and associated imported reporting data through our account-deletion process. You may also contact us to request support-assisted deletion of a connection and its imported data.
6. Product-update emails
The optional “Stay updated” form stores the email address you submit in a pending state and sends a time-limited confirmation link. Product updates begin only after you confirm the address.
Every product-update email includes an unsubscribe option. We retain an unsubscribed address as a suppression record so it is not accidentally added back without a new request and confirmation. Product-update consent does not affect essential account, billing, or security messages.
7. Affiliate program
A free affiliate account stores the account holder's name and email without creating a customer workspace or subscription. Affiliate applications also store a payout email, optional website, promotion description, approval status, and program acceptance date. Existing customers may connect the same affiliate account to their organization.
Approved links use a 30-day first-party cookie to attribute a new organization at signup. Link visits are kept only as daily aggregate counts; we do not retain an IP address or browser identifier for those clicks. Commission and payout ledgers retain transaction references needed to calculate, audit, reverse, and pay rewards.
8. Google API data
When you connect a Google service, VisitorPing accesses Google user data only after you authorize the requested OAuth permissions. For Google Ads, this can include accessible advertiser and campaign identifiers, resource status and verification information, campaign names and settings, advertisements, keywords, targeting, dates, currency, impressions, clicks, cost, conversions, and the provider responses needed to create, monitor, pause, or update a managed campaign. For Google Search Console, this includes accessible properties, permission levels, search queries, pages, countries, devices, impressions, clicks, click-through rates, positions, sitemap status, and URL Inspection results.
VisitorPing uses Google Ads data and credentials to provide the managed advertising actions you approve, enforce spending and policy safeguards, attribute and report results, reconcile provider spend, and maintain an audit history for you and authorized members of your VisitorPing organization. We do not sell Google user data, use it for unrelated personalized advertising, or share it with unrelated third parties. We may disclose data to service providers only when necessary to host, secure, and operate VisitorPing under confidentiality and security obligations, or when required by law.
Google OAuth access and refresh credentials are encrypted at rest and used only by VisitorPing's server-side services to maintain the connection you authorized. You can revoke VisitorPing's access at any time through your Google Account connections. Revoking access stops future Google API access but may leave an already-running campaign active at Google and does not automatically delete data already imported into VisitorPing. Use VisitorPing's pause controls when available and confirm provider status before revoking. Use the dashboard Disconnect control, contact us, or complete the applicable VisitorPing account-deletion process to remove stored credentials and imported Google data, subject to records we must retain for security, financial reconciliation, disputes, or legal obligations.
VisitorPing's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
9. Meta platform data
When you connect Meta Ads, VisitorPing receives the Meta user identifier associated with the authorization, accessible advertising-account identifiers and names, and campaign-level dates, currency, impressions, clicks, spend, and selected conversion-action totals. VisitorPing uses this data only to provide connected advertising reporting to your organization and does not use it to create or modify Meta campaigns.
Meta access credentials are encrypted at rest. You can remove a connection and its imported campaign data with the dashboard Disconnect control. If you remove VisitorPing through Meta, our deauthorization callback deletes Meta Ads connections associated with that Meta user. Meta data-deletion requests are processed through our deletion callback and return a confirmation code and status URL.
10. Aggregate research
VisitorPing publishes occasional research about small-business website traffic, built from grouped patterns across customer websites. A figure is published only when at least 20 websites belonging to at least 15 separate customers contribute to it, it rests on at least 1,000 observations, and no single website accounts for more than a quarter of the group. A group failing any of these is withheld entirely rather than published with a caveat.
Published figures contain no reference to a website, a customer, or a visitor. Automated traffic and internal or test sites are excluded before any of it is counted. The full method is described on our research page.
Customer websites are included by default, and any customer can opt out at any time from Settings in the dashboard. Opting out removes that customer's websites from every future aggregate and records the date it took effect. Because published figures retain nothing identifying, a figure already published cannot be traced to or removed for an individual customer.
11. Contact
Questions about this policy, connected-service data, or deletion requests can be sent to privacy@visitorping.com.