Privacy Policy

Last updated: September 2026. This policy covers how sub.analytics handles data — both data from customers who use our service, and data from visitors to websites that use our tracking script.

1. Who we are

sub.analytics is operated by Tilman Richter, Auf den Häfen 5, 28203 Bremen, Germany. We are the data controller for account data. For website visitor data, we act as a data processor on behalf of our customers (website owners).

Contact: hello@subnodes.net

2. No cookies — ever

sub.analytics does not set any cookies in visitors’ browsers. Our tracking script does not read or write browser storage of any kind. No consent banner is required to use sub.analytics on your website.

3. Visitor data (website analytics)

When a visitor loads a page tracked by sub.analytics, our servers receive the following technical request data:

  • IP address (used only for the hash below — never stored raw)
  • User-agent string (browser and device type)
  • Referrer URL
  • Requested page URL
  • Timestamp

To count unique daily visitors without identifying individuals, we compute a one-way hash: SHA-256(daily_salt + site + ip + user_agent). The daily salt is a random value created for each calendar day (UTC). When the day ends it is deleted — at the latest within one hour — and it is never included in backups. Once it is gone, nobody, including us, can recompute a stored hash from an IP address, and hashes from different days cannot be linked to each other. The raw IP address is discarded immediately after hashing.

Hashes stored before 19 September 2026 were created with a long-lived key. On that date every one of them was re-encoded with a random value that was discarded at once, so they can no longer be traced back to an IP address either.

What we store permanently: page URL, referrer, country (derived from IP via GeoIP lookup before hashing), browser family, device type, and the daily hash. No personally identifiable information is retained.

Legal basis (GDPR Art. 6(1)(f)): legitimate interest of the website owner in understanding their traffic, balanced against the minimal privacy impact — since no personal data is stored and no cross-site tracking is possible.

4. Account data (customers)

When you create a sub.analytics account, we collect and store your e-mail address and a hashed version of your password. We use your e-mail to send billing receipts, service notices, password-reset links, and — with your consent — product updates. These e-mails are delivered by Strato AG (Germany), our e-mail provider.

Legal basis: GDPR Art. 6(1)(b) (performance of a contract) for account-related communications; Art. 6(1)(a) (consent) for marketing e-mails.

5. Payment data

Payments are processed by Stripe, Inc. We do not store card numbers or payment details. Stripe acts as an independent data controller for payment processing; their privacy policy is available at stripe.com/privacy. We receive and store a Stripe customer ID and subscription status for billing management.

6. Sub-processors and data location

We use the following sub-processors:

  • Hetzner Online GmbH — servers and encrypted off-site backups, located in Germany (EU)
  • Stripe, Inc. — payment processing
  • Strato AG — delivery of account e-mails (receipts, password resets), located in Germany (EU)

All analytics data is stored on servers in Germany. No data is transferred outside the European Economic Area as part of the analytics service.

7. Data retention

Aggregated analytics data is retained for as long as your account is active. Account data (e-mail, subscription status) is retained for the duration of the contractual relationship. After account deletion, both are removed from the live system within 30 days, and from our encrypted backups as they rotate out — within 12 months at the latest.

8. Your rights (GDPR)

As a data subject, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure (“right to be forgotten”); object to processing; and request data portability. To exercise any of these rights, contact us at hello@subnodes.net.

You also have the right to lodge a complaint with the supervisory authority. The competent authority for Bremen, Germany is the Landesbeauftragte für Datenschutz und Informationsfreiheit Bremen.

9. Cookies on this website

analytics.subnodes.net (the sub.analytics web app) uses one functional cookie: a session cookie set by NextAuth to keep you logged in. This cookie is strictly necessary for the service to function and does not require consent under GDPR Recital 47. It is deleted when your session expires or you sign out.

No advertising, analytics, or third-party cookies are set on this domain.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified by e-mail at least 14 days in advance. The date at the top of this page always reflects the most recent revision.