Privacy Policy
At Triangle Analytics, we believe privacy is a fundamental human right. Our telemetry infrastructure is engineered from the ground up to deliver actionable insights without intrusive tracking, persistent cookies, or cross-site profiling.
1. Overview & Core Commitments
This Privacy Policy applies to the services, website (the-triangle-analytics.web.app), and tracking APIs operated by Triangle Analytics ("we", "us", or "our").
Our service is architected to eliminate visitor surveillance. We do not store persistent identifiers on visitors' browsers, we do not perform cross-site tracking, and we never sell, monetize, or broker personal data to data brokers or advertising networks.
2. Data Collected from End-Users (Website Visitors)
When website owners install the lightweight Triangle Analytics script on their properties, our infrastructure processes strictly minimal, non-personally identifiable telemetry data:
- Page URL & Referrer: The page visited, query parameters (with sensitive auth tokens stripped), and referring website.
- Device & Browser Category: Coarse device type (desktop, tablet, mobile), operating system, browser engine, and screen viewport dimensions.
- Geographic Coarseness: Country and region derived from IP headers. Full IP addresses are discarded immediately and never written to permanent disk storage.
- Cookieless Session Hash: A cryptographically salted, daily-rotating hash generated from the visitor's IP, User-Agent, and site domain. This prevents tracking users across different calendar days or across unrelated sites.
document.cookie) or local storage tokens on visitors to your website. No cookie consent banners are required under GDPR, ePrivacy Directive, or PECR.3. Customer & Account Holder Information
When you create an account on Triangle Analytics to view telemetry dashboards or manage domains, we collect the necessary credentials to provide your service:
- Email Address & Name: Used for account identity, authentication, transactional security emails, and password recovery.
- Google Sign-In / OAuth Data: When you choose to authenticate via Google Sign-In, we receive your verified Google email address, display name, and avatar URL provided via Firebase Authentication. We use this data solely to authenticate your identity and provision your dashboard account.
- Site Metadata & API Keys: Domain names, tracked site identifiers, and encrypted API credentials generated to connect your telemetry endpoints.
We do not request or access your Google contacts, Google Drive files, or any external Google account data beyond basic authentication identity.
4. Legal Bases for Processing (GDPR & CCPA)
We process customer data under the following lawful bases:
- Contractual Necessity: To provide you with your requested analytics services, dashboard access, and account management.
- Legitimate Interests: To protect our network from denial-of-service abuse, ensure uptime, and prevent fraudulent signups.
- Consent: Where explicitly provided when enabling optional notifications or advanced telemetry features.
5. Third-Party Infrastructure & Subprocessors
We work with reputable cloud infrastructure providers with high security standards:
- Firebase (Google Cloud Platform): Frontend static hosting and identity management authentication services.
- Heroku / Salesforce: Backend application server runtime and isolated processing dynos.
- PostgreSQL: Encrypted persistent database storage for aggregated site metrics and user accounts.
6. Data Retention & Deletion
Aggregated analytics metrics are retained for as long as your account remains active. If you delete a domain or close your account:
- All associated domain telemetry and visitor cohorts are permanently purged from database tables.
- Your user account profile, email records, and authentication tokens are irrevocably deleted.
7. Security Standards
All data transmission between your browser, our tracking endpoints, and our databases is protected with industry-standard TLS 1.3 encryption. Passwords and credentials are cryptographically hashed using Argon2/bcrypt algorithms.
8. Contact Us & Data Protection Officer
If you have questions regarding this Privacy Policy, your rights under GDPR/CCPA, or wish to request data deletion, contact us at:
