MetricFold analytics data policy
The exact default collection, identity, location, bot, retention, export and deletion boundaries for MetricFold customer analytics.
This policy describes the intended technical boundary for analytics collected by MetricFold on behalf of a customer. It complements the privacy notice: the privacy notice explains roles and purposes, while this document explains which analytics fields the default product accepts and deliberately excludes.
Default web and product events
The public tracker can send page views, navigation timing, active engagement, bounded scroll milestones, CTA exposure and activation, file or outbound-link actions, JavaScript error categories and Core Web Vitals. Product teams can add named events through a site tracking plan. Each plan entry defines whether the client or trusted server owns it and which property keys are permitted.
Properties should describe the action with stable machine identifiers such as pricing.primary or shipment.created. They must not contain names, email addresses, access tokens, free-form messages, form values, document content or other direct personal information. MetricFold rejects unknown client event names and drops properties outside the allowlist.
Trusted server adapters can add business outcomes such as signup completion, activation, subscription start, renewal, cancellation, failed payment, recovery, refund and dispute. Commercial outcomes should originate from a verified provider webhook or an equivalent authoritative backend transition.
Identity boundary
The default collector does not set an analytics cookie and does not write local storage or session storage. It does not assemble a device fingerprint. Short-lived privacy-safe session evidence can group activity inside a bounded window for visits, funnels and active-user reports. It is not intended to recognize a person permanently across devices or long periods.
A signed-in product may send an approved pseudonymous subject hash through a trusted route for account-level adoption or retention analysis. The product owns the mapping; MetricFold does not need the person's name or email. Public client code should never expose a stable internal user id as an event property.
Network and location data
An incoming network address is used transiently for transport, abuse prevention and coarse country derivation. The raw address is not stored in the analytics event. Infrastructure access logs may briefly contain network information for security and reliability under a shorter operational retention and restricted access policy.
Location reports use country-level values by default. The live map places a marker at a country centroid and explicitly does not claim precise visitor position. Location headers are accepted only from trusted edge infrastructure; a browser-supplied country is not treated as authoritative.
Sources, campaigns and URLs
MetricFold stores normalized host, path, entry and exit values. Query strings are removed unless a specific campaign parameter is allowlisted. Referrers are reduced to the information needed for source and channel classification rather than storing unrestricted full URLs that may contain identifiers.
UTM and equivalent campaign fields are bounded in length and cardinality. Direct traffic rules and attribution model are visible in reports. First-touch and last-touch values may be associated with a short-lived attribution token for a trusted payment handoff.
Automated traffic
Known search, social preview, uptime, SEO, AI answer, indexing and training user agents are separated before human analytics. The registry is paired with behavioral and request-quality rules because user-agent matching alone is incomplete. Excluded counts and reasons are retained as bounded diagnostics. Legitimate crawler activity can appear in a dedicated crawler view without inflating human visitors, sessions or conversion.
No classification system can guarantee that every sophisticated bot is detected or every unusual human is preserved. MetricFold exposes the policy and discrepancy evidence instead of presenting filtered totals as perfect ground truth.
Connected data
Custom API connectors store a configured numeric metric and observation time, not the provider's full response. Endpoints and bearer tokens remain encrypted and server-side. Social connectors store account label, provider, hashed account identity, normalized numeric snapshots and encrypted OAuth tokens. Raw provider documents are not sent to the dashboard or model.
Payment adapters store normalized provider event references, amount, currency, type, time and bounded properties. Full payment credentials are handled by the hosted payment provider. Advertising destination deliveries are separate, purpose-gated connections and are not part of default analytics collection.
Retention, export and deletion
Standard paid plans include three-year analytics retention unless the pricing page or order states otherwise. A customer may select a shorter operational period. Enterprise retention and region terms require a written order. Raw operational logs and live-window state use materially shorter periods than aggregate reports.
Authorized users can retrieve bounded JSON and CSV reports and use scoped REST or MCP access. A complete raw export is scheduled and access-controlled because an unbounded synchronous download can harm tenant isolation and service stability. Deletion requests remove workspace analytics and connections according to the documented process; encrypted backups expire on rotation.
Customer responsibilities
Customers must maintain an accurate privacy notice, choose appropriate event names and properties, avoid sending prohibited information, configure consent where required and independently authorize advertising destinations. Customers should test forms, error handling and dynamic UI after adding declarative CTA attributes so collection remains intentional.
MetricFold may suspend a collector that is used to capture sensitive content, evade legal requirements, attack another system or exceed safety bounds. The goal of the default policy is useful product evidence with a data surface small enough to understand and govern.