Content Performance Tracking: Privacy and Data Policy

    How BlogPilot measures website visits without cookies and without storing visitors' IP addresses

    Last updated: 2026-09-29

    1. Overview

    BlogPilot's website tracking script is a lightweight, cookieless analytics tool that BlogPilot customers can add to their own websites to measure how their content performs. It is designed to collect as little as possible: it sets no cookies, stores nothing on the visitor's device, and does not store IP addresses or other direct identifiers.

    For visitors to a customer's website, the customer is the controller of the data and Data HQ acts as its processor. The processor terms are in the BlogPilot Data Processing Agreement, which also lists every field described below. If you visited a customer's website and have a question about this, please contact that business first.

    2. What We Collect

    For each page view, the script sends and we store:

    • The page address (its origin and path only, for example https://www.example.co.uk/blog/post) and the page title
    • The referring page (also its origin and path only), where the browser provides it
    • The utm_source, utm_medium and utm_campaign values, if present in the page address, each in its own field
    • The device type (mobile, tablet or desktop). The script works this out from the width of the browser window; only the device type is stored, not the width
    • A daily visitor identifier (see section 4)
    • The date and time

    While the page stays visible, the script also sends a short "heartbeat" message every 30 seconds, so that time on page can be estimated.

    Query strings and fragments (anything after "?" or "#" in an address) are removed before anything is stored. Only the three UTM values above are kept.

    3. What We Do NOT Collect

    We do not collect or store:

    • IP addresses
    • User-Agent strings
    • Query strings or fragments from page or referrer addresses (other than the three UTM values)
    • The visitor's country or location
    • Cookies or browser storage data
    • Names, email addresses, user IDs or form contents
    • Cross-site browsing data
    • Any identifier that lasts longer than a day

    Customers should make sure that personal data (such as names or email addresses) does not appear in the paths or titles of the pages on which they install the script.

    4. How We Count Unique Visitors

    We generate a daily visitor identifier using a one-way cryptographic hash:

    sha256(daily_random_value + tracking_key + IP_address + User_Agent)

    The daily random value is generated fresh each day and held only in server memory; it is never stored. The tracking key is the key for the customer's website.

    This identifier:

    • Cannot be reversed to recover the IP address or User-Agent
    • Changes every day, because the random value changes every day
    • Cannot be used to recognise a visitor on a different day
    • Cannot be used to follow a visitor across different customers' websites, because each website has its own tracking key

    The IP address (read in memory from the header added by our own web proxy) and the User-Agent string are used only to create this identifier, and the User-Agent also to filter out search engines, crawlers and other automated traffic. They are then discarded. They are never written to the tracking data, and our web proxy keeps no access logs.

    5. Location

    The script does not detect or record the visitor's country or location. No geolocation database or geolocation provider is used.

    6. No Cookies

    Our tracking script does not set any cookies, use localStorage, use sessionStorage, or store any data in the visitor's browser. There is no mechanism for recognising a visitor across days.

    7. Data Protection

    Because the script does not store IP addresses, User-Agent strings or any lasting identifier, much of the data it collects may not be personal data. Some of it may be, however (for example, the daily identifier within the day it is created, or information in a page path or title), and so we treat it as personal data where it is.

    The customer who installs the script is the controller and decides the lawful basis for measuring visits to its website, usually its legitimate interest in understanding how its website is used. Data HQ processes the data only on the customer's instructions, under the BlogPilot Data Processing Agreement. The customer should describe the script in its own website privacy information; we provide suggested wording on request.

    8. Electronic Communications (PECR)

    The script sets no cookies and stores nothing on the visitor's device. It does read some information from the browser in order to work (such as the page address, the referring page and the window width), and the ICO's guidance treats technologies of this kind as within the scope of PECR. Under the UK Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025, analytics used by a website operator to improve its own website can be exempt from the consent requirement, provided visitors are given clear information and a simple way to object.

    Whether PECR requires consent, or a notice and opt-out, for a particular website is a decision for the customer who installs the script, taking its own advice where needed. We do not give legal advice.

    9. Data Retention

    • Tracking data: kept for as long as the customer's BlogPilot account is open, so that performance can be compared over time.
    • Deletion on request: a customer can ask us at any time to delete all tracking data for its account, by emailing support@datahq.co.uk. We delete it from our live systems within 30 days and confirm when this has been done.
    • Account closure: when a customer's account is closed, all of its tracking data is deleted, after a 7-day grace period during which the closure can be cancelled. Copies in our backups are overwritten within a further 7 days.

    10. Data Storage & Security

    • Data is stored in Azure-hosted PostgreSQL databases in the UK South region
    • All data is encrypted at rest and in transit (TLS 1.2+)
    • Each customer's tracking data is shown only to that customer's users
    • Access to production systems is restricted to named Data HQ personnel, with multi-factor authentication
    • Tracking data is not sent to any AI provider
    • Data HQ holds a current Cyber Essentials (Basic) certificate

    11. Sub-Processors

    ProcessorPurposeLocation
    Microsoft AzureCloud hosting & databaseUK South

    No geolocation or other third-party provider receives tracking data. The full Data HQ Sub-processor List is published at vista.datahq.co.uk/legal/sub-processors.

    12. Customers' Choices

    As the controller for your website, you can:

    • See the collected data in BlogPilot's analytics
    • Ask us for a copy of the tracking data we hold for your account, by emailing support@datahq.co.uk before your account closes
    • Ask us to delete all tracking data for your account
    • Stop tracking at any time by removing the script from your website

    13. Contact

    For privacy-related questions: legal@datahq.co.uk

    Data HQ Limited, Saxon House, 27 Duke Street, Chelmsford, Essex CM1 1HT