Trust & data protection
NowMetrix is built by a Swiss company, hosted in Frankfurt, and tracks without cookies or persistent identifiers. This page sums up what we store, where it lives, and who can access it.
No cookies, no persistent identifiers, no cross-site profiles. Visitors are counted with a short-lived hash instead.
Analytics data runs on DigitalOcean and Hetzner infrastructure in Frankfurt. Backups stay in the EU as well.
Raw IP addresses are hashed the moment a request arrives and are never written to disk — we keep no server logs of them.
Unique visitors are counted via a hash of IP, browser, and country. The resulting ID is deleted after 24 hours.
Recap stores monthly pageviews and visits as pure aggregates — no hashes, no IDs, nothing that could re-identify a reader.
Only two people — the CEO and the co-founder — can access customer data, always behind 2FA. When a contract ends, all data is deleted.
In plain terms
Subprocessors
| Provider | Purpose |
|---|---|
| DigitalOcean | Hosting (Frankfurt) |
| Hetzner | Hosting (Frankfurt) |
| Cloudflare | CDN and DDoS protection |
| Supabase | Dashboard login (authentication) |
| Postmark | Transactional email |
| Paddle | Payment processing |
| FeatureBase | Product feedback portal |
| Hyperping | Uptime monitoring |
The current list including locations and safeguards is part of our DPA.
Questions your DPO will ask
NowMetrix uses no cookies for tracking. Whether your site needs a consent banner depends on your jurisdiction and the other tools you run — we recommend confirming your setup with your legal team. They can reach us anytime at privacy@nowmetrix.com.
Incoming IP addresses are hashed immediately on arrival — they exist in memory for milliseconds and are never written to disk. We also keep no server logs that would contain them.
We build a short-lived hash from IP address, browser, and country. That hash becomes a temporary ID used to count unique visitors — and is deleted after 24 hours. Long-term statistics are stored as pure aggregates without any identifiers.
On DigitalOcean and Hetzner infrastructure in Frankfurt, Germany, with backups in the EU. NowMetrix itself is a Swiss company based near Zurich.
Two people: the CEO and the co-founder, both behind two-factor authentication. There is no broad internal access to customer data.
All your data is deleted at the end of the contract. The details — timelines, confirmation, backups — are governed by our DPA, which we are happy to provide.
Trust & data protection
Send them our way at privacy@nowmetrix.com — or request the DPA directly.