whovisited.Back to home

YOUR DATA, EXPLAINED

Privacy Policy

Last updated September 24, 2026

WhoVisited provides website activity analytics for businesses. This policy explains the information we use to operate WhoVisited and how account holders and visitors to customer websites can make choices.

Account and sign-in information

When you use a WhoVisited account, we store your email address, display name, account and workspace membership, and sign-in history. Passwords for email sign-in are stored as hashes. If you sign in with Google or GitHub, we use the identity and email address returned by that provider to create or access your account. For Google sign-in, we request basic profile and email information only. We store the provider name and its account identifier, but do not retain the provider access token. We do not request access to your Google Drive or Gmail.

Activity collected on customer websites

A customer may place our tracker on a website they control. When it is enabled, the tracker sends a random visitor identifier, a session identifier, page path and title, referring site origin, event name, limited custom event properties, and timestamps. It stores the visitor identifier in the browser's local storage and session information in session storage. The tracker does not automatically read form contents or email addresses, and it respects browser Do Not Track and Global Privacy Control settings. Customers are responsible for deciding when collection is permitted on their sites and for avoiding sensitive data in page URLs, titles, and custom events.

Payments and service operation

Stripe and PayPal host their respective payment flows. We store the identifiers and subscription status needed to manage access and renewals; we do not store complete payment-card details. Our server may also process technical request information to operate and protect the service.

Use, sharing, and retention

We use this information to provide account access, show website activity to the relevant workspace, enforce plan limits, and operate payments. We do not sell Google sign-in data. Authentication and payment providers process information needed for their services. Website activity is available only to authorized members of the customer workspace. We do not currently apply a fixed automatic deletion period to stored activity; it remains until an authorized operator removes it.

Your choices

Account holders can revoke WhoVisited's authorization in their sign-in provider settings. A website visitor can use browser privacy settings, and participating customer websites can use the tracker's consent controls. For access, account-link removal, or deletion requests, contact us using the address below. We may need to confirm your relationship to the account or website before acting on a request.

Contact

Privacy questions and requests: support@whovisited.net.

© 2026 WhoVisited
Privacy PolicyTerms of Service