MetricFold privacy notice
How MetricFold handles account, billing, support, website and customer analytics data, including purposes, retention, subprocessors and user choices.
Effective date: 1 August 2026.
This notice explains how MetricFold handles personal information when someone visits metricfold.com, creates an account, buys a subscription, asks for support or uses MetricFold to measure a website or product. It describes the product's intended operating boundary and is not a promise that every customer's use of analytics is automatically lawful. Customers remain responsible for configuring their collection and notices for their own purposes and jurisdictions.
Who controls which data
MetricFold is the controller for account, security, billing, sales, support and first-party website information used to operate MetricFold itself. When a customer installs MetricFold on a site, that customer decides why the site is measured and which approved product events it sends. For that customer analytics data, the customer is generally the controller and MetricFold acts as processor under the applicable service agreement and data processing terms.
Questions or privacy requests can be sent to [email protected]. We may need to verify a request before disclosing, correcting or deleting information so that one person cannot obtain another person's data.
Information MetricFold receives
Account information includes name, email address, password hash, security settings, accepted workspace membership and authentication audit evidence. Billing information includes plan, provider customer and subscription references, payment status, currency and amounts. Hosted payment providers handle full card or bank credentials; MetricFold does not intentionally store them.
Service operation produces security and reliability logs such as timestamp, request route, response status, trusted proxy network information, rate-limit decisions and error identifiers. Raw logs have a shorter retention than analytics reports and access is restricted to operational need.
Customer analytics can include page path, source category, campaign fields, country code, device and browser family, approved event name and bounded properties, performance measures, privacy-safe session evidence and customer-provided pseudonymous account references. Trusted server integrations may add payment, subscription, refund, dispute, entitlement and lifecycle events.
The default public collector is designed not to store analytics cookies, browser local storage identifiers, fingerprints, DOM text, form values, full unrestricted query strings or raw IP addresses in analytics events. Customers should not send names, email addresses, message content, access tokens or other direct identifiers as event properties.
Purposes and legal bases
MetricFold uses account and service information to provide the contracted product, authenticate users, prevent abuse, secure tenant data, answer support requests, maintain reliability, invoice customers and comply with legal obligations. We use limited first-party measurement to understand whether our own product works and which improvements are useful. Where consent or another specific legal basis is required, the relevant collection or destination must remain disabled until that basis exists.
We do not sell customer analytics data. We do not use one customer's product events to advertise to another customer's visitors. Advertising destinations, if configured by a customer, are separate consent-aware integrations with their own provider terms and policy boundary.
Retention and deletion
Retention depends on the data category and plan. Standard analytics retention is described on the pricing and data-policy pages. Account and billing records are retained while an account is active and for the period needed for tax, dispute, fraud and contract requirements. Security logs are retained for a bounded operational period. Expired trials remain exportable for the stated grace period before scheduled deletion.
Workspace owners can request export or deletion. Deleting a workspace removes its sites, tracking plans, provider connections, dashboard views and customer analytics according to the documented deletion schedule, except data that must be preserved for legal obligations or a live dispute. Backups expire on their normal encrypted rotation rather than being selectively rewritten.
Providers and international transfers
MetricFold uses a limited set of infrastructure, email, authentication and merchant-of-record providers to operate the service. A current subprocessor list and data-region details will be maintained in the security documentation before general availability. Dodo Payments processes MetricFold subscription checkout as merchant of record. Customers connecting Google, Meta, X, LinkedIn or another provider also instruct MetricFold to exchange data with that provider under the provider's terms.
Where information crosses borders, MetricFold uses an applicable transfer mechanism and reviews the destination and provider safeguards. Enterprise data-region commitments apply only when written into the order, not by implication from a marketing page.
Individual choices and rights
Depending on location, a person may have rights to access, correct, delete, restrict or object to processing, receive portable information or complain to a regulator. Some requests about a customer's measured product must be directed to that customer because MetricFold cannot identify a visitor from a name or email it does not hold. We assist customers with verified processor requests.
People can disable JavaScript, use browser controls or contact the site they are visiting. MetricFold's default analytics does not rely on an opt-out cookie because it does not set an analytics cookie. A customer may still need a consent or preference interface for other technologies and destinations on the same site.
Security and changes
MetricFold uses tenant-scoped authorization, encryption for provider credentials, TLS in transit, secret hashing where recovery is unnecessary, signed billing webhooks, bounded APIs, rate limits and operational monitoring. No internet service can promise absolute security. Material incidents are handled under the documented response process and applicable notification requirements.
We may update this notice when product boundaries, providers or law change. The effective date will change and material updates will be communicated through the service or account email where appropriate.