Updated 4 October 2026
GDPR and analytics, in plain words
No tool is compliant by itself. Compliance is how you use it. Here is what the GDPR asks of your analytics, and which parts a tool can take off your hands.
In short
- The GDPR applies to analytics when you process personal data: an IP address, a cookie id or anything that singles out a person can count.
- A tool can make the rules easier to meet: collect less, keep less, send nothing to third parties, answer data requests. It cannot decide your lawful basis for you.
- trckable is built for this: no IP address stored, nothing loaded from another company, retention you set, data requests built in, a published DPA on Cloud. The rest is yours.
What the GDPR asks of analytics#
Seven questions cover most of it.
- Lawful basis. You need a reason to process the data. For analytics that is usually legitimate interest or consent, and the choice is yours.
- Minimisation. Collect what you need and no more.
- Transparency. Tell people what you collect, in your privacy policy.
- Storage limits. Do not keep data longer than needed.
- Processors. If a company handles the data for you, you need a data processing agreement with it.
- Transfers. Data leaving the EU needs a legal mechanism.
- People's rights. Visitors can ask what you hold about them, and ask for it to be erased.
Separately, the ePrivacy rules decide whether you ask before reading or storing anything on the device. That is the cookie-banner question, covered in Do I need a cookie banner for analytics?.
What trckable does#
- No IP address is stored. It is used in memory to work out a country, to tell robots from people and, in cookieless mode, to make a daily hash. It is not written to a log, the database or the disk.
- Nothing from another company. No fonts, CDN, pixels, tag managers or error reporting, and no telemetry. A visitor's browser talks only to your server.
- Cookieless mode. One switch stores nothing in the browser, drops the region and city, and honours Do Not Track and Global Privacy Control.
- Retention you control. From 30 days to 3 years per site, pruned daily.
- Data requests. Find, export or erase everything held about one visitor id or one email address.
- EU hosting on Cloud, with backups in the EU, and a published data processing agreement.
- A privacy paragraph written from your settings, which changes when you turn a module off.
- Open source, so anyone can read what the code does.
What stays with you#
- Your lawful basis, and whether you need consent in the countries you serve.
- Your banner and your policy: making refusing as easy as agreeing, and covering everything else on your pages. The generated paragraph is a starting point from people who are not your lawyers.
- What you send: goal properties hold whatever you put in them. Do not put names or email addresses there.
- Your own server, if you self-host: updates, access and backups are your processing, and you are the controller.
Is a daily hash anonymous?#
Do not assume so. The visitor is a hash of IP address and browser, salted with a value that changes every day, and only today's and yesterday's salts are kept. It cannot be recomputed later from an address, and it cannot follow someone from day to day or from site to site. Even so, regulators may treat a hash as personal data while it exists. We keep our claims modest for that reason: this lowers your risk, it does not remove your duties.
More on how the numbers work without a cookie is in cookieless analytics and GDPR and the privacy docs.
Questions#
- Does trckable make me compliant with the GDPR?
- Compliance belongs to how you use a tool, not to the tool. trckable is built so that you can meet the GDPR: no IP address stored, no third parties, retention and data requests built in. We do not promise that your use is compliant, and this is not legal advice.
- Do I need a data processing agreement?
- On Cloud, trckable handles visitor data for you, so yes, and a DPA is published. If you self-host, nobody else processes the data and there is no processor.
- How do I answer a visitor who asks what I hold about them?
- Open Settings → Data & privacy → Data request, find everything held for one visitor id or one email address, export it as JSON, or erase it.