How Dzati collects, uses, and protects personal data.
Dzati is built to be privacy-friendly by design. For the visitors of websites that use Dzati, we provide cookieless, first-party analytics: we do not use tracking cookies, we do not build cross-site advertising profiles, and we do not sell personal data. This policy explains what we collect as a company and how we handle it.
Account data. When you sign up we collect your name, email, password (hashed), and, if you subscribe, billing details handled by our payment processor (we never store full card numbers).
Usage data. We collect logs and diagnostics about how you use the dashboard (e.g. pages viewed, actions taken, IP, browser) to operate and secure the Service.
Analytics data we process for you. When your sites send events to Dzati, we receive data such as page URL, referrer, UTM parameters, approximate location derived from IP (the IP itself is not stored long-term), device/browser type, and any custom or revenue events you choose to send. This is processed on your behalf — see the DPA.
We use a small number of strictly necessary cookies for authentication and security in the dashboard. We do not use advertising or cross-site tracking cookies. The Dzati tracker on customer sites is cookieless.
Where the GDPR applies, we rely on: performance of our contract with you (to provide the Service), legitimate interests (to secure and improve the Service), consent (where required, e.g. some product emails), and legal obligation.
We share data with vetted sub-processors who help us run the Service — for example, hosting/infrastructure, our payment processor (Stripe), and email delivery. We require them to protect data consistently with this policy. We do not sell personal data.
We retain account data while your account is active and as needed for legal and accounting purposes. Analytics data is retained according to your plan's retention window; you can delete sites (and their data) at any time, and we delete data after account closure subject to legal requirements.
We use technical and organisational measures including encryption in transit, hashed credentials, access controls, and isolated event storage. No system is perfectly secure, but we work to protect your data and will notify you of incidents as required by law.
We may process data in countries other than yours. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object or withdraw consent. To exercise these rights, contact us at admin@dzati.com. If you are a visitor to a site using Dzati, please contact that site's operator, who is the controller of your data.
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
We may update this policy and will post the new version here with a revised date. Material changes will be communicated where appropriate.
Questions about privacy? Email admin@dzati.com.