Analytics Glossary

GDPR / CCPA Compliance

What the privacy laws ask of your analytics — and how this design keeps it simple.

GDPR (General Data Protection Regulation) is a European Union law that governs how personal data is collected, stored, and processed; CCPA (California Consumer Privacy Act) provides similar protections for California residents. For website analytics, both laws come down to the same questions: what data about visitors do you collect, can it identify them, and what happens to it afterward.

For most small-business owners the goal is straightforward — keep growing the business with good data while keeping the compliance surface as small as possible. The most reliable way to do that is to collect less identifying data in the first place, which is exactly how Crafty Meerkat is designed.

Crafty Meerkat is built for compliance: everything is first-party (your visitors are never tracked across websites), no names, emails, or other personal details are collected, raw IP addresses are used only for geolocation at collection time and never stored, and your data is never sold or shared. One honest nuance remains: Crafty Meerkat uses a persistent first-party identifier, and depending on your audience and jurisdiction, your site’s consent policy may need to cover it.

How it works

GDPR regulates “personal data” — information relating to an identifiable person. Crafty Meerkat’s design minimizes what falls in scope: the data collected describes visits (pages, sources, countries, devices), not people, and visitor identifiers are anonymous — a persistent first-party ID on Growth and Agency plans, or a one-way fingerprint hash that rotates daily on Starter. Nothing collected includes names, emails, or other personal details, and the raw IP address that briefly feeds geolocation is never stored.

Because privacy regulation treats persistent identifiers cautiously even when they are anonymous, the safest practice is transparency: mention your analytics in your privacy policy, and if your audience or jurisdiction requires consent for persistent identifiers, include it in your consent flow. Crafty Meerkat cannot give legal advice — for questions specific to your business, a qualified professional in your jurisdiction is the right resource.

How to put it to work

  1. 1

    Describe your analytics in your privacy policy

    State what is collected (anonymous visit data: pages, sources, devices, country/city) and what is not (names, emails, or other personal details; raw IP addresses are never stored).

  2. 2

    Decide whether your consent flow should cover the identifier

    Crafty Meerkat uses a persistent first-party identifier. Depending on your audience and jurisdiction, your existing consent policy may need to cover it — when in doubt, ask a professional familiar with your market.

  3. 3

    Keep control of your data

    You can export your analytics anytime in CSV, JSON, or Google Analytics-compatible format, and exclude your own traffic by IP so the data stays clean.

Tips from the den

  • Compliance gets easier the less identifying data you hold — an analytics tool that never collects personal details shrinks the problem before it starts.
  • Keep your privacy policy specific: “our analytics collects no names, emails, or personal details, and raw IP addresses are never stored” is clearer and more credible than boilerplate.
  • If you serve EU or California audiences, review your consent flow once when you install analytics, then revisit it only when your tools or audience change.

See it live — no signup

The demo dashboard runs on a real site with real traffic.

Open the live demo →

Common questions

Is Crafty Meerkat GDPR compliant?

Crafty Meerkat is built with compliance in mind: all tracking is first-party (visitors are never tracked across websites), no names, emails, or other personal details are collected, raw IP addresses are never stored, and your data is never shared, sold, or used for advertising or profiling. Crafty Meerkat uses a persistent first-party identifier, which your site’s existing consent policy may need to cover depending on your jurisdiction.

Do I need a cookie consent banner to use Crafty Meerkat?

It depends on your audience and jurisdiction. Because Crafty Meerkat collects no personal details, the compliance surface is small — but privacy regulations in some jurisdictions treat persistent identifiers cautiously, so your consent policy may need to cover the first-party identifier. Review your setup against the rules that apply to your market, ideally with a qualified professional.

What visitor data does Crafty Meerkat actually store?

Anonymous visit data: pages viewed, referrer, campaign tags, country and city (derived from the IP at collection time — the raw IP itself is never stored), device type, browser, operating system, scroll depth, and events. Visitors are identified by an anonymous first-party ID or a daily rotating hash — never by name, email, or any other personal detail.

Does CCPA apply to my small business?

CCPA applies to businesses above certain thresholds of revenue or data volume, so many small businesses fall outside it — but its principles (tell people what you collect, do not sell their data) are good practice for everyone. Since Crafty Meerkat never sells or shares your visitor data and collects no personal details, aligning with those principles takes little effort.

Keep reading

Try it on your own website

Every account starts with a full-featured 30-day free trial. No credit card, set up in 2 minutes.

Start free trial