ezStats Privacy Policy
This Privacy Policy explains how Cavendo Corporation ("ezStats," "we," "us," or "our") collects, uses, and protects information in connection with the ezStats website, applications, APIs, tracking code, integrations, and related services (the "Service").
ezStats was built to be privacy-first. Our analytics operate without cookies, without cross-site tracking, and without collecting personal data about the visitors of the websites we measure.
1. Two Roles: Controller and Processor
We handle information in two distinct capacities:
- Our customers (data controller). When you create an ezStats account, subscribe to a plan, connect an integration, or contact us, we act as the data controller for your account, billing, and integration information.
- Visitors to our customers' websites (data processor / service provider). When our tracking code runs on a customer's website, or when a customer imports analytics data from another provider, we process that analytics data on behalf of that customer. Our system is designed so that this data does not identify individual visitors. If you have questions about a specific website's data practices, contact the operator of that website.
2. Information We Collect from Customers
When you use the Service as a customer, we collect:
- Account information: name, email address, company name, and password (stored in hashed form)
- Billing information: plan, billing address, and payment details, which are processed by our payment processors. We do not store full payment card numbers.
- Configuration data: websites you add, goals, keywords, competitors, alerts, report settings, share links you create, and team member invitations
- Communications: messages you send to support and responses to surveys
- Service usage data: log data such as login timestamps, dashboard activity, feature usage, IP address, and browser type, used for security, troubleshooting, and product improvement
- Integration data: if you connect a third-party service, we receive only the data you authorize that service to share. Data we receive from Google services, including Google Analytics and Google Search Console, is described in detail in Section 4.
3. Visitor Analytics Data We Process for Customers
Our tracking code is designed to measure website usage without identifying individual people:
- No cookies. We do not set cookies or use similar identifiers in browsers for analytics tracking.
- No personal data stored about visitors. We do not store names, email addresses, precise locations, or persistent identifiers of website visitors.
- IP addresses are not stored. Visitor IP addresses are used transiently at the time of collection (for example, to derive coarse geographic region, filter bots, and, where the company identification feature is enabled, to match a visit to a company or organization) and are then discarded. They are not written to our analytics database.
- What we do record: aggregated and event-level analytics such as pages viewed, referring source, UTM parameters, browser and device type, screen size, country or region, visit duration, click and scroll behavior for heatmaps, and goal completions. This data is not linked to an identified or identifiable individual.
- Company identification: for customers using this feature, we associate visits with companies or organizations (firmographic data such as company name, industry, and size). This feature identifies organizations, not individual people.
- Bot filtering: we analyze traffic patterns to exclude bots and automated traffic from reports.
4. Google Analytics, Google Search Console, and Other Google User Data
This section describes how ezStats accesses, uses, stores, and shares data received from Google APIs ("Google user data"). Connecting any Google service is optional. ezStats works without it.
4.1 How you connect
You can connect Google Analytics 4 (GA4) or Google Search Console from your ezStats settings. You sign in through Google's own consent screen and choose which permissions to grant. We request read-only access and cannot create, change, or delete anything in your Google accounts.
4.2 Google Analytics (GA4) data we access
When you connect Google Analytics, we request the https://www.googleapis.com/auth/analytics.readonly scope. With your permission, we access:
- Account and property metadata: the list of GA4 accounts and properties your Google account can access, including property names, IDs, and time zones, so you can choose which property to use in ezStats
- Aggregated report data for the property you select, such as sessions, pageviews, users counts, engagement metrics, traffic sources and channels, landing and top pages, country or region, device category, events, and conversions or key events
We do not request or store user-level GA4 data such as User-ID values, client IDs, individual visitor records, or advertising identifiers. We do not access any Google data beyond the property you select.
4.3 How we use Google Analytics data
We use GA4 data only to provide features you choose to use in ezStats:
- Viewing GA4 reports in ezStats. In our simplified GA4 view, we retrieve report data from Google to display your metrics in the ezStats dashboard.
- Optional historical import. If you choose to import history, we copy aggregated report data for the property and date range you select (up to 12 months) into your ezStats account, so you can compare it with data collected by ezStats. Import is a separate, optional step that you start yourself.
- Reports and insights for you. Imported or retrieved GA4 data may appear in your dashboards, scheduled email reports, alerts, and AI-generated insights shown to you.
- Share links you create (see Section 4.6).
4.4 Google Search Console data
When you connect Google Search Console, we access the search performance data you authorize for the property you select, such as search queries, pages, clicks, impressions, click-through rate, and average position. We use it only to provide the SEO features in your ezStats account.
4.5 Limited Use commitment
ezStats's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features described above that you have chosen to use.
- We do not sell Google user data.
- We do not use or transfer Google user data for advertising, including personalized, retargeted, or interest-based advertising.
- We do not use Google user data to determine creditworthiness or for lending purposes.
- We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
- We do not transfer Google user data to others except as needed to provide the Service to you (for example, to our hosting and infrastructure providers under confidentiality obligations), to comply with applicable law, as part of a merger or acquisition with notice to you, or when you choose to share it yourself through a share link.
- Our staff do not read Google user data unless you give us permission (for example, to help with a support request), it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
4.6 Share links
You can create share links that let others view a dashboard or report without an ezStats account. A share link may include data from any source in that dashboard, including GA4 or Search Console data. Anyone who has the link can view the shared content, so share links only with people you trust. You control share links: you choose what is included, and you can set an expiration date and revoke a link at any time from your ezStats settings, after which it stops working. ezStats does not create or distribute share links on your behalf.
4.7 How we store and protect Google user data
- OAuth access and refresh tokens are encrypted at rest and used only to retrieve the data you authorized.
- Imported and cached Google data is stored with your other ezStats data under the regional data residency rules in Section 8 and protected by the safeguards in Section 10.
- Google data is transmitted using encryption in transit (TLS).
4.8 Disconnecting and deleting Google data
- You can disconnect Google Analytics or Search Console at any time in ezStats settings, or by removing ezStats from your Google Account permissions at https://myaccount.google.com/permissions.
- When you disconnect, we delete your stored OAuth tokens and stop retrieving new data. Cached report data retrieved from Google is deleted within 30 days.
- Previously imported historical data remains in your ezStats account until you delete it, delete the website, or close your account. You can delete imported GA4 data at any time from your settings or by contacting [email protected].
- When you close your account, all Google user data is deleted within 30 days, except where retention is required by law.
5. How We Use Information
We use customer information to:
- Provide, operate, maintain, and secure the Service
- Process payments and manage subscriptions
- Send transactional communications, such as receipts, alerts, scheduled analytics reports, and service announcements
- Provide customer support
- Send product updates and marketing communications, which you can opt out of at any time
- Monitor, analyze, and improve the Service, including developing new features
- Detect, prevent, and investigate fraud, abuse, and security incidents
- Comply with legal obligations
We use visitor analytics data only to provide the Service to the customer whose website generated it, and to maintain the security and integrity of the Service. Google user data is used only as described in Section 4.
AI features. Some features use artificial intelligence to generate insights and recommendations from your analytics data, which may include imported GA4 or Search Console data. These insights are generated for your account only. Your data, including Google user data, is not used to train generalized AI models.
No selling of data. We do not sell personal information, visitor analytics data, or Google user data, and we do not use analytics data for advertising or share it with ad networks or data brokers.
6. Legal Bases for Processing (GDPR/UK GDPR)
Where European data protection law applies, we rely on the following legal bases:
- Contract: to provide the Service you signed up for, including integrations you choose to connect
- Legitimate interests: to secure and improve the Service, prevent abuse, and, for our cookieless visitor analytics, to measure aggregate website usage in a manner designed to minimize any privacy impact (Article 6(1)(f))
- Consent: for optional marketing communications and for connecting third-party integrations such as Google services, which you may withdraw at any time by disconnecting
- Legal obligation: to comply with accounting, tax, and other legal requirements
7. How We Share Information
We share information only with:
- Service providers that help us operate the Service, such as cloud hosting, payment processing, email delivery, and customer support tools, under contracts that restrict their use of the data
- Integration partners you choose to connect, such as Google Analytics and Google Search Console, as directed by you
- People you choose to share with through share links, team invitations, or client access features you control
- Professional advisors such as auditors and lawyers, where necessary
- Authorities when required by law, subpoena, or legal process, or to protect the rights, safety, or property of ezStats, our customers, or others
- A successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to this Privacy Policy
Agency and white-label customers may share dashboards and reports with their own clients; that sharing is controlled by the customer, not by ezStats. Sharing of Google user data is always subject to Section 4.5.
8. Data Residency and International Transfers
Customer analytics data, including imported Google data, is stored based on region: data for EU customers is stored on servers located in the EU, and data for US customers is stored on servers located in the US. Where personal data is transferred across borders, we use appropriate safeguards such as Standard Contractual Clauses where required.
9. Data Retention
- Analytics data: retained according to the retention period of your plan, or until you delete a website or your account
- Google user data: retained as described in Section 4.8
- Share links: retained until you revoke them, they expire, or you delete the related website or account
- Account and billing records: retained for the life of your account and afterward as required for legal, tax, and accounting purposes
- Support communications: retained as needed to provide support and improve the Service
When you close your account, we delete or anonymize your analytics data within a reasonable period, except where retention is required by law.
10. Security
We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit, encryption of integration credentials at rest, access controls, and monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and regulators as required by applicable law.
11. Your Rights and Choices
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Delete your personal data
- Export your data in a portable format
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent, including by disconnecting Google integrations
- Opt out of marketing emails using the unsubscribe link or your account settings
To exercise these rights, email [email protected]. We will respond within the timeframe required by applicable law. We will not discriminate against you for exercising your rights. If you are in the EU, UK, or a similar jurisdiction, you also have the right to lodge a complaint with your local supervisory authority.
US state privacy laws. Residents of California, Virginia, Colorado, and other states with comprehensive privacy laws may exercise the rights above. We do not sell personal information or share it for cross-context behavioral advertising as defined by those laws.
Website visitors. Because our analytics do not store personal data about visitors, we generally cannot locate any record tied to an individual visitor. Requests concerning a specific website should be directed to that website's operator.
12. Cookies on ezStats Properties
Our analytics tracking code does not use cookies on customer websites. On our own website and application (ezstats.io), we use only essential cookies needed for functions such as login sessions and security. We use our own product, ezStats, to measure traffic on our website, which operates without cookies.
13. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us at [email protected] and we will delete it.
14. Data Processing Addendum
For customers that require a GDPR Article 28 data processing agreement, our Data Processing Addendum is available for eligible plans. Contact [email protected] to request one.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service before the changes take effect. If we change how we use Google user data, we will notify you and ask for your consent before using that data in a new way. The effective date at the top of this page indicates when the policy was last revised.
16. Contact Us
For privacy questions or requests:
