Privacy Policy
How we protect your privacy, what data we collect, and your rights over your information. Your data always belongs to you, not us.
Data controller
Datrika is provided by Konstantin Pankratov, OSVČ, IČO 23231181, based at Argentinská 868/5, Holešovice, 170 00 Praha 7, Czech Republic. For anything about this policy, reach us at support@datrika.app.
Depending on whose data is involved, we act either as the controller (for our own account holders) or as a processor (for your website's visitors, on your behalf) - see our GDPR page for how that split works.
As a visitor to our website
We track visits to this marketing site with our own cookie-less analytics - the same product we sell you. We don't set any cookies here and don't store any personal data about you; our legal basis is legitimate interest, so no cookie banner is required.
If you log in to the dashboard, we set one strictly necessary cookie - a session token that keeps you signed in. It's required for the login to work at all, so it doesn't need your consent.
As a customer and subscriber
Once you create a Datrika account, here's what we hold about you:
| Data | Why we have it |
|---|---|
| To create your account and let you sign in (one-time codes sent by email). | |
| Name, avatar | Optional, if you choose to add them. |
| IP address and browser of each login | To protect your account against unauthorized access. |
| Payment details | Handled entirely by Stripe - your card details never reach our servers. We keep only the amount, currency, status, and Stripe transaction ID. |
We keep this for as long as your account is active. If you delete your account, your email and name are anonymized immediately, and your sites and their analytics are deleted immediately and permanently - there's no waiting period. The one exception is payment records, which EU accounting rules require us to keep for 5-10 years even after your account is gone.
Datrika isn't intended for anyone under 16, and we don't knowingly collect data about children.
What we collect and why
For the visitors of the websites you track with Datrika, we don't use cookies at all. Instead, each visitor gets a pseudonymous ID. We compute it as a keyed one-way hash (HMAC-SHA256) of a truncated IP address, the browser, and your site's ID, keyed with a random salt that rotates every 24 hours. Only the network part of the IP goes into the hash: we drop the last octet of an IPv4 address and the entire second half of an IPv6 one. The IP and browser details themselves are never stored, the same visitor can't be linked across different days, and because the site ID is part of the input, they can't be linked across sites either.
Beyond that hash, we record technical details (browser, OS, device, screen size), coarse location (country, region, city), traffic source (referrer, UTM tags), and behavior (page visited, duration, bounce). Because none of this can be tied back to a person, sites using Datrika can typically rely on legitimate interest as the legal basis, without needing a cookie banner. For the full technical detail, see our Data policy.
Your rights
As an account holder, you can ask us to access, correct, export, or delete your data, or object to how we process it, at any time - just email support@datrika.app. See the full breakdown on our GDPR page.
As a visitor of a site that uses Datrika, we can't identify you individually - there's no IP address or cookie to look you up by. A request to remove your data is handled by deleting the relevant site's analytics entirely; see Handling visitor data requests for how that works.
Third-party services
We keep the list of companies that touch any Datrika data short:
| Service | What it's for | Location |
|---|---|---|
| Hetzner | Hosts our infrastructure and all analytics data | EU (Germany) |
| MaxMind | Local GeoIP lookup, run entirely on our own servers | Database downloaded from the US; no visitor data sent |
| Resend | Sends the login codes for your account | US, covered by Standard Contractual Clauses and the EU-US Data Privacy Framework |
| Stripe | Processes payments for your subscription | EU contracting entity; some processing in the US, covered by Standard Contractual Clauses and the Data Privacy Framework |
The legally binding version of this list - and our commitments around it - lives in our Data Processing Agreement.
Changes and questions
We'll update the date at the top of this page whenever this policy changes, and email you directly about anything material.
We haven't appointed a formal Data Protection Officer - at our current scale, with no large-scale systematic monitoring and no special category data, one isn't required under Art. 37 GDPR.
Questions about this policy: support@datrika.app.