Privacy Policy

Effective date: April 1, 2025


1. Overview

Gauss Lab ("we", "us", "our") provides a web analytics service available at gausslab.io. This privacy policy describes what data we collect, how we use it, and what rights you have as a user of our service.

By using Gauss Lab, you agree to the terms of this policy.


2. Data We Collect

2.1 Data about visitors of customer websites

When the gauss.js script is installed on a customer's website, we collect the following data about each visit:

  • Page URL and referrer
  • UTM parameters from the address bar
  • Device type, browser and operating system (from User-Agent)
  • Country based on IP address (the IP address itself is not stored)
  • Custom events sent via gauss.track()

We do not use cookies and do not store raw IP addresses. Session identification is performed through an anonymous hash computed from the IP address, User-Agent, and a daily-rotating salt. This makes it impossible to identify a specific individual.

2.2 Account data

When registering and using your account, we collect:

  • Email address
  • Name (optional)
  • Payment information (processed by payment provider, we do not store card details)
  • Information about projects and account settings

3. How We Use Data

Visitor data from customer websites is used solely to provide analytics to Gauss Lab customers. We do not sell, share, or use this data for advertising purposes.

Account data is used to:

  • Provide and improve the service
  • Issue invoices and process payments
  • Send service-related notifications
  • Respond to support requests

4. GDPR Compliance

Gauss Lab is designed with GDPR requirements in mind:

  • Cookie-free — we do not set cookies on customer websites
  • No consent required — analytics collection does not require a consent banner as personal data is not processed
  • IP anonymization — IP addresses are not stored in their original form
  • Data minimization — we only collect what is necessary for analytics

If you are a data subject in the EU and have questions about your rights, contact us at privacy@gausslab.io.


5. Data Retention and Deletion

Analytics data is stored according to the customer's subscription plan (from 30 days to 24 months). Upon account closure, all data is deleted within 30 days.

Account data is deleted immediately upon a deletion request.


6. Data Sharing with Third Parties

We may share data with the following categories of service providers:

  • Cloud providers for data storage and processing
  • Payment providers for transaction processing
  • Email services for sending notifications

All providers operate under data processing agreements (DPA) and comply with GDPR requirements.


7. Your Rights

You have the right to:

  • Receive a copy of your data
  • Correct inaccurate data
  • Delete your data
  • Object to processing
  • Port your data to another service

To exercise your rights, contact privacy@gausslab.io.


8. Policy Changes

We may update this policy. For material changes, we will notify you by email or through the service interface. Continued use of the service after notification constitutes acceptance of the updated policy.


9. Contact

For privacy inquiries: privacy@gausslab.io

Gauss Lab, gausslab.io