Trust & data protection

Your data stays in Europe. Your readers stay anonymous.

NowMetrix is built by a Swiss company, hosted in Frankfurt, and tracks without cookies or persistent identifiers. This page sums up what we store, where it lives, and who can access it.

Cookie-free by design

No cookies, no persistent identifiers, no cross-site profiles. Visitors are counted with a short-lived hash instead.

Hosted in Frankfurt

Analytics data runs on DigitalOcean and Hetzner infrastructure in Frankfurt. Backups stay in the EU as well.

IPs hashed in milliseconds

Raw IP addresses are hashed the moment a request arrives and are never written to disk — we keep no server logs of them.

Identifiers expire after 24 hours

Unique visitors are counted via a hash of IP, browser, and country. The resulting ID is deleted after 24 hours.

Long-term stats without identifiers

Recap stores monthly pageviews and visits as pure aggregates — no hashes, no IDs, nothing that could re-identify a reader.

Two people, 2FA, full deletion

Only two people — the CEO and the co-founder — can access customer data, always behind 2FA. When a contract ends, all data is deleted.


In plain terms

What we store — and what we never store.

We store

  • Pageviews and visits
  • Article context: URL, title, author, section
  • Traffic source, referrer, and campaign
  • Device class and country
  • Aggregated counts for long-term stats

We never store

  • ×Cookies or persistent identifiers
  • ×Raw IP addresses or server logs
  • ×Names, emails, or accounts of your readers
  • ×Cross-site profiles of any kind
  • ×Data for resale — your data is never sold or shared

Subprocessors

The services we rely on.

Provider Purpose
DigitalOceanHosting (Frankfurt)
HetznerHosting (Frankfurt)
CloudflareCDN and DDoS protection
SupabaseDashboard login (authentication)
PostmarkTransactional email
PaddlePayment processing
FeatureBaseProduct feedback portal
HyperpingUptime monitoring

The current list including locations and safeguards is part of our DPA.


Questions your DPO will ask

The answers, before the meeting.

Do we need a cookie banner for NowMetrix?

NowMetrix uses no cookies for tracking. Whether your site needs a consent banner depends on your jurisdiction and the other tools you run — we recommend confirming your setup with your legal team. They can reach us anytime at privacy@nowmetrix.com.

What exactly happens to IP addresses?

Incoming IP addresses are hashed immediately on arrival — they exist in memory for milliseconds and are never written to disk. We also keep no server logs that would contain them.

How do you count unique visitors without cookies?

We build a short-lived hash from IP address, browser, and country. That hash becomes a temporary ID used to count unique visitors — and is deleted after 24 hours. Long-term statistics are stored as pure aggregates without any identifiers.

Where is our data stored and processed?

On DigitalOcean and Hetzner infrastructure in Frankfurt, Germany, with backups in the EU. NowMetrix itself is a Swiss company based near Zurich.

Who at NowMetrix can access our data?

Two people: the CEO and the co-founder, both behind two-factor authentication. There is no broad internal access to customer data.

What happens when we cancel?

All your data is deleted at the end of the contract. The details — timelines, confirmation, backups — are governed by our DPA, which we are happy to provide.


Trust & data protection

Your DPO has more questions? Good.

Send them our way at privacy@nowmetrix.com — or request the DPA directly.