Who we are
This policy describes how Uplitycs (“we”, “us”) handles personal data when you use uplytics.space and related services: the dashboard, the tracking script, uptime checks, and public status pages.
Questions: privacy@uplytics.space. Legal notices: legal@uplytics.space.
Two roles
Your Uplitycs account. We are the controller of account data (email, name, authentication, billing metadata, workspace membership).
Analytics on sites you add. When you install the tracker or configure uptime checks, you are the controller of that site’s visitor and availability data. We process it on your instructions as a processor. The Data Processing Addendum applies to that processing.
Account data we collect
To run the product we process:
- Email address, name, a password hash, and an authenticator secret if you turn that on.
- Workspace, site, and membership records tied to your account id.
- Plan, event caps, and checkout metadata (handled with Dodo Payments).
- Invite emails and uptime alert emails.
- Support messages you send to privacy@uplytics.space, legal@uplytics.space, or billing@uplytics.space.
We do not sell account data. We use it to provide the service, enforce plan limits, send transactional mail, prevent abuse, and meet legal duties.
What the tracker sends
The script on a customer site posts pageviews and custom events to /api/collect. A typical event includes:
- Event name (pageview or a custom name) and timestamp.
- Path and referrer.
- Anonymous visitor id and session id.
- Device class (mobile / tablet / desktop), browser family, OS family, screen size.
- Optional UTM fields and optional custom properties you attach in code.
The tracker stores an anonymous id in first-party localStorage (upl_vid) and a session id in sessionStorage (upl_sid). It does not set an HTTP cookie. See the Cookie & storage notice.
We use the connection only to derive a country for the map. We do not store visitor IP addresses, and we do not show IPs in the dashboard.
Custom event properties are under your control. Do not send names, emails, passwords, or other direct identifiers in those fields.
How analytics are stored
We store hourly counts for pages, referrers, countries, devices, browsers, operating systems, campaigns, and custom event names, plus a short-lived live signal for Here now. We do not keep a profile of each visitor.
We do not build a cross-site profile, do not use a third-party cookie graph, and do not sell visitor data.
Uptime and status pages
If you add health-check URLs, we periodically request those URLs and store up or down results, status codes, latency, and incident times. Down and recovery mail goes to the addresses you configure. Public status pages show the availability history you choose to publish.
Processors
We use the vendors listed on Subprocessors to host and operate the service. Current list:
- Resend — Workspace invites, uptime alerts, and account recovery email
- Dodo Payments — Paid plan checkout and billing
- Neon — Analytics data
- Turso — Accounts, websites, and dashboard data
Retention
- Account and workspace data: while the account is open, then deleted on request where we are not required to keep it.
- Hourly visit counts: while the site remains on the service.
- Health-check history: about 90 days on the public status page.
- Transactional email: retained by our email vendor per their policy.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, to object or restrict certain processing, and to withdraw consent. Account holders can close the account and email privacy@uplytics.space. End visitors of a customer site should contact that site’s operator; we will assist the customer as processor.
If you are in the EEA, UK, or Switzerland, you may also lodge a complaint with your local supervisory authority.
Children
The service is not directed at children under 16. Do not use Uplitycs to profile children or to track services aimed at them.
Changes
We will post updates on this page and change the date above. Material changes to how we process personal data will be announced in the product or by email where appropriate.