Privacy Policy
GhostStat is analytics built the other way round: measure the traffic, not the person. No cookies, no fingerprinting, and no IP address ever written to disk.
Last updated: August 2026
- What we collect
- What we never collect
- Counting without cookies
- Account data
- Retention
- Sub-processors
- Public & global stats
- Your rights
- Contact
This policy covers two groups of people: visitors to any website that runs the GhostStat tracking script, and customers who hold a GhostStat account. Where the two differ, we say so.
1. What we collect from visitors
When a page carrying the GhostStat script loads, we record only what is needed to produce aggregate traffic statistics for that one site:
- The page URL, page title, and the referring host (for example google.com, not a full query string).
- Device type, screen size, browser and operating system, and the browser's language — read from the request, not from a device fingerprint.
- Approximate location — country, region, city and network (ASN/ISP) — derived from the IP address at the moment of the request and then discarded (see below).
- UTM campaign parameters when present in the URL, and custom events a site owner chooses to send.
- Plugin-specific signals a site owner enables — for example scroll depth, clicks or form interactions. These are behavioural, never identifying.
2. What we never collect
- No cookies. GhostStat sets none, and uses no
localStorageorsessionStorage. That is why sites running it do not need a cookie-consent banner for analytics. - No stored IP addresses. The IP is used in memory to look up country/region/city/ASN and to compute a daily hash, then it is dropped. It is never written to the database or to logs.
- No fingerprinting. We do not combine signals to build a stable cross-visit device identifier.
- No cross-site tracking. Visitor identifiers are salted per site, so the same person on two different GhostStat sites cannot be linked. This is by design and cannot be switched on.
- No selling of data. We do not sell, rent or share visitor data with advertisers or data brokers.
3. How we count visitors without cookies
To tell repeat pageviews within a day apart from brand-new ones, GhostStat derives a short-lived hash from the site, the network, the browser, the calendar day and a secret per-site salt. Because the day is part of the input, the hash rotates automatically every 24 hours and cannot be used to follow anyone across days. It is a one-way hash: the original IP or browser string cannot be recovered from it.
4. Account data (customers)
For people who hold a GhostStat account we store the account email, a hashed password, plan and billing status, the sites you register, and your settings. We use this to run your account, send the reports and notifications you ask for, and handle billing. Payment card details are handled by our payment providers — we never see or store full card numbers.
5. Retention
Raw event data is retained for a rolling window and then rolled up into daily aggregates; the retention period is configurable and defaults to a limited window. Aggregated statistics may be kept longer because they contain no identifiers. Account data is kept while your account is active and removed after closure, subject to any legal record-keeping we are required to perform.
6. Sub-processors
We keep the list short. We use a payment processor (Stripe and/or PayPal) to take payments, and an email provider to deliver transactional mail and the reports you request. GhostStat also shares a single account system with two sister products, Rent-An-Ad and Tossit; if you use them, the relevant account data is shared across the three. Geographic and network look-ups use offline databases, not third-party API calls that would forward a visitor's IP.
7. Public and global statistics
A site owner can make a site's stats public. Public pages show aggregates only — top pages, referrers, devices, countries and totals — never individual visitors, recordings or heatmaps. Our global market-share view at gs.ghoststat.me is anonymised and aggregated across all sites; no individual site or account is ever identified there.
8. Your rights
Because we do not store IP addresses and identifiers rotate daily and are salted per site, we usually cannot connect a stored record back to a named individual — which is the strongest privacy protection there is. For account data, you can access, correct, export or delete it from your settings or by contacting us, consistent with the GDPR, UK GDPR and CCPA. We do not run behavioural advertising and there is nothing to opt out of on that front.
9. Contact & changes
Questions about privacy, or a request about your data? Email privacy@ghoststat.me. If we make a material change to this policy we will update this page and, for account holders, note it in-app or by email.
See also our Terms of Service and Copyright & Licensing.