Data Processing Agreement
When you measure a website with DataStated, you are the controller of your visitors' data and KAMKR LLC is the processor. This agreement covers that relationship. It applies automatically to every customer as part of the Terms of Service; there is nothing to sign.
Roles
- You, the controller. You decide to measure your site, and you are responsible for the legal basis for doing so, including any notice or consent your visitors are owed.
- KAMKR LLC, the processor. We process visitor data only to provide the service to you, on the instructions this agreement and the product's controls express, and for no purpose of our own.
What is processed
Exactly what the privacy policy describes: page URLs, referrers, campaign tags, click identifiers, viewport and language, a random first-party visitor identifier, daily-salted IP hashes with the raw address discarded in-request, a country code and, where our edge supplies them, a region and city; the order and goal values your site chooses to send; and, if you send them, your own user id, up to ten properties, and a SHA-256 hash of a buyer's email. No names or contact details in the clear, and no identifier shared across customers.
Confidentiality and instructions
We process visitor data only as needed to run the service. The small number of people who operate DataStated are bound to confidentiality, and access data only when running the service or helping you requires it.
Subprocessors
These vendors process data on our behalf. Each publishes its own GDPR data processing terms, including standard contractual clauses for international transfers:
- Railway (United States): application hosting and the database where event data lives.
- Cloudflare: network security and content delivery in front of the application.
- Resend: customer emails, including optional weekly summaries and order or goal alerts sent to the customer's chosen recipients. Alerts can include an amount or goal name, time, source and daily count; weekly summaries contain aggregate analytics.
- Stripe: billing for customer subscriptions. Stripe never sees visitor data.
If this list changes in a way that affects visitor data, the date at the top changes and account holders are emailed.
Security measures
- All traffic is encrypted in transit with HTTPS.
- Raw IP addresses are never stored; only a hash salted with a secret that changes daily.
- Passwords are hashed with scrypt; sessions are stored as verifiers.
- Connected store access tokens are encrypted at rest.
- Access to production systems is limited to the people who operate the service.
If something goes wrong
If we become aware of a breach affecting your data, we will tell you without undue delay, with what we know and what we are doing about it.
Data subject requests
Your visitors' requests are yours to answer, since you are the
controller. If you need our help to answer one, ask and we will
assist. Records can include a visitor identifier, your user id,
an email hash and properties you supplied. Deleting the
_dsv cookie does not delete stored history.
A later identify call with the same user id can join a new
browser identifier to that history.
Deletion and return
Contact us to request deletion or help with a data request. Closing your account deletes sites only you own; sites with another owner remain with them. While access is active, you can retrieve the records exposed by our API; its documented endpoints describe the available data.
The hosted service applies the three- or five-year history window described in the privacy policy through a nightly sweep. This includes event and imported history, crawls, search data, annotations, alert-send records and supporting Stripe history. Identities needed for retained data or ongoing subscriptions, the latest MRR observation at or before the cutoff for each retained subscription, and the crawler usage counter for the boundary month remain for operational use.
When every owner's access has been lapsed for 90 days, the sweep removes all site analytics, including spend, financial ledgers, reports, subscriptions and their MRR history. Account records, site settings, memberships and connection configuration remain. The privacy policy gives the full scope and the 30-day recording grace period.
Transfers
Processing happens in the United States. Where a customer's visitors are elsewhere, the transfer mechanisms are the subprocessors' standard contractual clauses referenced above.
California (CCPA/CPRA) service provider terms
For personal information of California residents that you send us or that the tag collects on your site, you are the business and KAMKR LLC is your service provider under the California Consumer Privacy Act as amended by the California Privacy Rights Act. In that role:
- We process that personal information only to provide the service to you under this agreement, and for no other purpose.
- We do not sell it, and we do not share it for cross-context behavioural advertising.
- We do not retain, use or disclose it outside our direct business relationship with you, or for any purpose other than the service, except as the CCPA permits.
- We do not combine it with personal information we receive from anyone else or collect ourselves, except as the CCPA permits a service provider to do.
- We will tell you if we decide we can no longer meet these obligations.
- You may take reasonable and appropriate steps to make sure we use the personal information in a way that is consistent with your own obligations, and to stop and fix any unauthorised use.
- When you forward a consumer request to access, delete or correct personal information we hold for you, we will act on it or help you act on it.
We certify that we understand these restrictions and will comply with them.
Term and law
This agreement runs as long as you have an account and follows the same governing law and venue as the Terms of Service.
Questions about this agreement? Email us at legal@datastated.com.