Privacy Policy
Last updated: July 6, 2026
This Privacy Policy explains how Crafty Meerkat (“Crafty Meerkat,” “we,” “us”) handles information in connection with our website analytics service (the “Service”). It covers two distinct relationships: the information we collect about our own customers, and the visitor data we process on our customers’ behalf when they install our tracking snippet on their sites.
1. Our approach in brief
- Visitor tracking is first-party only. We do not track people across unrelated websites and we do not operate an advertising network.
- We do not collect visitors’ names, emails, or other directly identifying personal details through the tracker.
- Raw IP addresses are used at the moment of collection to derive approximate geography and are then discarded, never stored.
- We never sell or share customer or visitor data, and we do not use it to train advertising or third-party profiling systems.
2. Information we collect about customers
When you create an account or use the dashboard, we process:
- Account data — your name, email address, hashed password, and authentication metadata (including multi-factor settings).
- Site configuration — the domains you register, your business/site profile, goals, and settings.
- Billing data — plan, subscription status, and billing contact. Card details are handled directly by a PCI-compliant third-party payment processor; we do not store full card numbers.
- Communications — messages you send us through the contact form or email.
- Product usage — logs and diagnostics needed to operate, secure, and improve the Service.
3. Visitor data we process for customers
When a customer installs the tracking snippet, we act as a data processor on their behalf. The tracker records events such as page views, sessions, referrers, UTM parameters, scroll depth, approximate geography (country/region), device and browser type, and page-performance timings.
On Growth and Agency plans, a persistent first-party identifier scoped to the customer’s own domain is used to measure new-versus-returning visitors and multi-day journeys. On the Starter plan, visitors are identified only by a one-way hash of non-personal attributes (such as a coarse IP-derived value, user agent, and a daily-rotating salt) that resets every 24 hours. The hash cannot be reversed to identify an individual.
The customer who owns the site is the controller of this data and is responsible for providing any required notices and lawful basis to their visitors.
4. How we use information
- To provide, secure, and maintain the Service and your account.
- To generate analytics, reports, and AI-based recommendations for your sites.
- To process payments and manage subscriptions.
- To send service, security, and (where permitted) product communications.
- To detect, prevent, and investigate abuse, fraud, and technical issues.
- To comply with legal obligations.
5. AI processing
To produce weekly recommendations, Stats Chat answers, and Prompt Builder output, we send the relevant analytics summary and the business context you provide to Anthropic’s AI models, which power Crafty Meerkat. This data is transmitted for the purpose of generating your results and is not used by us to build advertising profiles. Anthropic processes it as our subprocessor under its own commercial terms and does not use business/API inputs to train its models.
6. Subprocessors and sharing
We share information only with service providers who help us run the Service, under contract and only as needed:
- Anthropic — AI analysis and chat.
- Email delivery provider — transactional and report emails.
- Payment processor — subscription billing.
- Infrastructure/hosting — running and securing the platform.
We may also disclose information if required by law, to enforce our terms, or to protect the rights and safety of users and the public. If we are ever involved in a merger or acquisition, we will provide notice before your information becomes subject to a different privacy policy.
7. Data retention
Analytics data is retained for as long as the customer’s account is active or as configured in their plan, and is deleted or anonymized when no longer needed. Account and billing records are kept as required for legal, tax, and accounting purposes. You can export or request deletion of your data at any time.
8. Security
We use industry-standard measures including encryption in transit, hashed passwords, optional multi-factor authentication, access controls, and regular backups. No system is perfectly secure, but we work to protect your data and to notify you of material incidents as required by law.
9. Your rights
Depending on where you live (including under the GDPR and CCPA/CPRA), you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. We do not sell personal information. To exercise any of these rights, contact us using the details below. Site visitors should direct requests to the site owner (our customer), who controls that data; we will assist our customers in responding.
10. International transfers
We and our subprocessors may process data in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.
11. Children
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by additional notice.
13. Contact
Questions about this policy or your data? Reach us through our contact page. See also our Terms of Service.