How OriginStats collects, uses, and protects your data.
We collect information you give us — your email address, name if provided, password credentials, and subscription status — and information generated by your use of the service, including page views, feature and signal interactions, device and browser details, and IP address. When you arrive from a marketing link we also capture campaign parameters and advertising click IDs (such as utm_* values, gclid, fbclid, ttclid, twclid, and msclkid) together with the referring site and landing page. If you choose "Continue with Google", Google sends us your Google account identifier, your email address and whether Google has verified it, and your name and profile picture where available; we store the identifier and your email address so the same Google account signs you back in to the same OriginStats account. Payment details are handled by our payment processors — Stripe, and for some accounts, Coinflow; we do not intentionally store full card numbers.
We use data to provide and secure the service, manage accounts and subscriptions, send transactional emails, respond to support requests, operate analytics, measure our marketing campaigns, and improve product quality.
We use Google Sign-In as an optional way to create an account and log in; Google acts as an identity provider and tells us only the details listed in section 1. It is not used for advertising or measurement. We use Google Analytics and PostHog for product and site analytics, and Meta (Facebook) Pixel, TikTok Pixel, X (Twitter) conversion tracking, and Google Ads conversion tracking for marketing measurement. We also send conversion events to Meta and TikTok server-side (Conversions/Events API); those events can include a hashed (SHA-256) version of your email address, your IP address, and your browser user agent. When you are signed in, the conversion events we send to Google Ads from your browser can also include a hashed (SHA-256) version of your email address; Google calls this "enhanced conversions" and uses it to match the conversion to a Google account. That hashed address is attached only to those Google Ads conversion events, not to our general analytics. We do not intentionally send raw email addresses, reset tokens, or verification codes to analytics or advertising tools, and analytics page-view URLs are stripped of parameters we have not allow-listed.
We use a session cookie to keep you signed in. Signing in with Google sets one further short-lived cookie, for up to ten minutes, that carries the security tokens protecting that sign-in; it is removed as soon as the sign-in finishes. The analytics and advertising tools above set their own cookies or identifiers; our PostHog analytics runs in memory-only mode and does not set cookies. We store marketing attribution (campaign parameters and click IDs) in your browser's local storage for up to 90 days so a later registration can be attributed to the campaign that brought you here, and short-lived flags in session storage.
We share data with service providers who help us run OriginStats, including our payment processors (Stripe, and for some accounts, Coinflow), Google where you choose to sign in with it, and the analytics and advertising platforms listed above. We do not sell personal data for money. Some privacy laws treat sending data to advertising platforms as a "sale" or "sharing" of personal data — you can object to this at any time by contacting [email protected].
You may request deletion of your account and data from your account page. We aim to delete personal data within 30 days of a verified request unless we need to retain limited records for security, legal, tax, billing, dispute, or compliance purposes. Deleting your account also removes the link to your Google account; you can disconnect Google at any time from your account page without deleting anything, provided you have set a password to log in with.
Privacy questions: [email protected]