Tracking and privacy
What we measure on Not Bastards and TCF websites and in our apps, and what we do not. This page is the internal source for a later public page on notbastards.com (a privacy statement or transparency report). It builds on the definition of creepy tracking.
Status: internal draft. Check the points under Verify before publishing before any of this goes public.
In one sentence
We measure how our websites and apps are used, never who uses them, unless you create an account and log in.
Plain-language summary (draft for publication)
We do some tracking. We don’t do creepy tracking.
We count visits. We can see that someone visited conveniencefactory.com after clicking a link on notbastards.com. We cannot see that you did.
We don’t use cookies to follow you, we don’t build profiles, and we don’t sell or share data about you. No ad networks, no tracking pixels.
The only moment we know who you are is when you create an account and log in. Then we know it’s you, inside that product, because you told us.
What we measure and what we do not
| We know | We do not know |
|---|---|
| A visitor viewed a page on one of our websites | Who that visitor is |
| A visitor came from a link on another of our sites, from an app, from the App Store or from a search ad | Whether the same person visited our other sites or used our other apps |
| Aggregated counts: pages, referring sites, countries, browser types, device types | A history of one person’s visits across sites, over time |
| Which campaign or link a click came from (UTM tags) | Anything about the person behind the click |
Example: we see “a visitor reached conveniencefactory.com by clicking a link on notbastards.com”. We never see “person X visited notbastards.com and then conveniencefactory.com”.
How we measure
Websites
- Umami, self-hosted on our own server (Hetzner VPS). The tracker is served from
a.notb.st; the admin site isumami.hitb.it. See Hosting and Domains.- No cookies and no local storage.
- IP addresses are not stored.
- Umami groups page views into a visit with an anonymous session value per website. Because the website is part of that value, the same person gets a different value on each of our websites. We cannot connect visits to different websites to one person.
- Cloudflare, which hosts the websites, keeps aggregated, cookieless statistics (Cloudflare Web Analytics).
- UTM tags in links say which campaign, site or app a click came from. They are the same for every visitor and contain nothing about a person or a device.
Apps
- Links from our apps to our websites carry UTM tags. They are the same for every user of a build and contain no user, device, install or license ID.
- Our apps do not send usage data to us. Graphic iDraw Rescue, for example, has the App Store privacy label “Data Not Collected”.
- Apple shows us aggregated App Store figures in App Store Connect: impressions, product page views and downloads. We receive no information about individual buyers.
Accounts
- The only time we identify a user is when they create an account and log in to a product.
- What we know then stays inside that product. We do not combine account data from different products into one profile, unless the user knowingly chooses to connect them.
What we never do
- Use third-party tracking pixels or ad-network scripts (Meta Pixel, LinkedIn Insight Tag, Google Ads conversion tags).
- Use cookies or local storage to recognise a visitor on other sites.
- Fingerprint browsers or devices.
- Put user, device, install or license IDs in links.
- Build profiles of people, within one product or across products.
- Sell or share data about people.
Advertising
We advertise on platforms such as Google Ads and LinkedIn. What those platforms know about their own users is their business and falls under their privacy policies. On our side we place no pixels or conversion tags. An ad click reaches us with the same UTM tags as any other campaign link.
Verify before publishing
- Google Ads auto-tagging. By default Google adds a
gclidto every ad click. That is a click ID that Google can link to a person. Either switch auto-tagging off in Google Ads, or make sure Umami and our logs stripgclidfrom URLs. Until then, the Advertising section above is not fully true. - Umami details. Check the Umami version and settings: no cookies, IP not stored, how the session value is made and how often its salt rotates, and whether “heartbeat” requests change any of this.
- Server location. Record in which country the Hetzner server stands.
- Cloudflare. Cloudflare necessarily sees IP addresses to deliver the sites. Describe what Cloudflare stores and for how long.
- Accounts. List which products have accounts, what they store, and how a user can delete their account.
- Scope. Decide whether the public page covers only Not Bastards, or also conveniencefactory.com and the campaign sites.