Legal · Last updated 1 September 2026
Privacy policy
Three separate things get confused in most privacy policies: the marketing site, the customer account, and the data the product processes for customers. They are kept apart here.
1. This website
This site is static and measures itself with Pear Metrics, the product it describes. That measurement sets no cookies, writes nothing to your device, and stores no IP address; sessions are counted with a server-side hash whose key rotates daily, so there is no identifier that survives until tomorrow. It records pages viewed, the referrer, and coarse device and country information, in our own database, shared with nobody. There is no tag manager, no chat widget, no advertising pixel and no embedded third-party content, and nothing here needs a consent banner.
The web server keeps standard request logs, including IP addresses, for up to 14 days for security and debugging. They are not used for analytics and are not combined with anything else.
2. If you contact us or become a customer
We are the controller for this. We process your name, email address, company name and billing details in order to reply to you, provide the service and take payment. The legal basis is the performance of a contract, or our legitimate interest in responding to an enquiry.
Correspondence is kept for as long as the relationship lasts and for two years afterwards. Billing records are kept for as long as tax law requires, currently six years in most jurisdictions we operate in.
We do not sell it, share it for advertising, or use it to train anything.
3. Data we process for you
For everything collected from your visitors, you are the controller and we are the processor. What we may do with it is set by the data processing agreement, not by this policy.
In practice the question rarely arises, because of what is collected. There is no cookie, no device storage, no stored IP address, no persistent visitor identifier, and no click ID. The session identifier is a hash computed in memory from connection data with a salt that rotates daily and is then discarded, so it cannot be reversed and cannot be matched across days.
The full list of what is and is not processed is on the privacy page, written to be read rather than to be complied with.
One exception, and it is yours to manage: custom event properties are whatever you choose to send. If you put personal data in one, it is in your database, and the guarantees above no longer describe your deployment.
4. Sub-processors
Two, both infrastructure, both listed in full. Google and Meta are not among them: campaign totals are read from their APIs and nothing is sent to them.
5. Where data is held
San Francisco, in the United States, on DigitalOcean. Backups are held in the same region. There is no cookie, no fingerprint, no stored IP address and no identifier that survives the day, so there is no record of an individual visitor held anywhere.
6. Your rights
If you are in the EU, the UK, or a US state with a comprehensive privacy law, you have rights of access, correction, deletion, portability and objection over the personal data we hold about you as a customer or enquirer. Write to privacy@pearmetrics.com and we will respond within 30 days.
For requests about your visitors’ data, you are the controller and the request comes to you. We will assist as the DPA requires. Be aware that with no identifier of any kind, a visitor cannot be located in the data, and a deletion request usually has nothing to act on. That is the intended outcome rather than an evasion.
You may also complain to your supervisory authority.
7. Security
Data in transit is encrypted with TLS. Backups are encrypted at rest and pruned after 30 days. Ad platform credentials stored per account are encrypted with an instance secret, so a database dump is not a set of live credentials. Access to production is limited to people who need it and is logged.
8. Changes
Material changes are notified by email to customers at least 30 days in advance. The date at the top of this page is authoritative.