Last updated: August 10, 2026

Privacy Policy

How we protect your privacy, what data we collect, and your rights over your information. Your data always belongs to you, not us.

Data controller

Datrika is provided by Konstantin Pankratov, OSVČ, IČO 23231181, based at Argentinská 868/5, Holešovice, 170 00 Praha 7, Czech Republic. For anything about this policy, reach us at support@datrika.app.

Depending on whose data is involved, we act either as the controller (for our own account holders) or as a processor (for your website's visitors, on your behalf) - see our GDPR page for how that split works.

As a visitor to our website

We track visits to this marketing site with our own cookie-less analytics - the same product we sell you. We don't set any cookies here and don't store any personal data about you; our legal basis is legitimate interest, so no cookie banner is required.

If you log in to the dashboard, we set one strictly necessary cookie - a session token that keeps you signed in. It's required for the login to work at all, so it doesn't need your consent.

As a customer and subscriber

Once you create a Datrika account, here's what we hold about you:

DataWhy we have it
EmailTo create your account and let you sign in (one-time codes sent by email).
Name, avatarOptional, if you choose to add them.
IP address and browser of each loginTo protect your account against unauthorized access.
Payment detailsHandled entirely by Stripe - your card details never reach our servers. We keep only the amount, currency, status, and Stripe transaction ID.

We keep this for as long as your account is active. If you delete your account, your email and name are anonymized immediately, and your sites and their analytics are deleted immediately and permanently - there's no waiting period. The one exception is payment records, which EU accounting rules require us to keep for 5-10 years even after your account is gone.

Datrika isn't intended for anyone under 16, and we don't knowingly collect data about children.

What we collect and why

For the visitors of the websites you track with Datrika, we don't use cookies at all. Instead, each visitor gets a pseudonymous ID. We compute it as a keyed one-way hash (HMAC-SHA256) of a truncated IP address, the browser, and your site's ID, keyed with a random salt that rotates every 24 hours. Only the network part of the IP goes into the hash: we drop the last octet of an IPv4 address and the entire second half of an IPv6 one. The IP and browser details themselves are never stored, the same visitor can't be linked across different days, and because the site ID is part of the input, they can't be linked across sites either.

Beyond that hash, we record technical details (browser, OS, device, screen size), coarse location (country, region, city), traffic source (referrer, UTM tags), and behavior (page visited, duration, bounce). Because none of this can be tied back to a person, sites using Datrika can typically rely on legitimate interest as the legal basis, without needing a cookie banner. For the full technical detail, see our Data policy.

Your rights

As an account holder, you can ask us to access, correct, export, or delete your data, or object to how we process it, at any time - just email support@datrika.app. See the full breakdown on our GDPR page.

As a visitor of a site that uses Datrika, we can't identify you individually - there's no IP address or cookie to look you up by. A request to remove your data is handled by deleting the relevant site's analytics entirely; see Handling visitor data requests for how that works.

Third-party services

We keep the list of companies that touch any Datrika data short:

ServiceWhat it's forLocation
HetznerHosts our infrastructure and all analytics dataEU (Germany)
MaxMindLocal GeoIP lookup, run entirely on our own serversDatabase downloaded from the US; no visitor data sent
ResendSends the login codes for your accountUS, covered by Standard Contractual Clauses and the EU-US Data Privacy Framework
StripeProcesses payments for your subscriptionEU contracting entity; some processing in the US, covered by Standard Contractual Clauses and the Data Privacy Framework

The legally binding version of this list - and our commitments around it - lives in our Data Processing Agreement.

Changes and questions

We'll update the date at the top of this page whenever this policy changes, and email you directly about anything material.

We haven't appointed a formal Data Protection Officer - at our current scale, with no large-scale systematic monitoring and no special category data, one isn't required under Art. 37 GDPR.

Questions about this policy: support@datrika.app.