Customer account and dashboard
Account email, authentication metadata, website domains, plan and billing state, support messages, and operational logs needed to run the dashboard.
Legal and trust
heatmapp is designed as a cookieless UX analytics layer. This page summarizes our processor terms, privacy guardrails, subprocessors, retention schedule, data-location notes, and a customer privacy notice starter.
Agreement
For end-visitor analytics collected through the heatmapp snippet, the customer is the controller and Slickful Group LLC acts as the processor. We process personal data, if any, only to provide, secure, maintain, and improve the Service under the customer's documented instructions and applicable law.
We maintain appropriate technical and organizational measures, including access controls, transport encryption, data minimization, retention limits, and separation between customer snippet analytics and heatm.app marketing analytics. We will assist customers with reasonable data subject requests, security inquiries, and deletion workflows where the requested data can be located from customer website, path, time range, and ephemeral session context.
Customers remain responsible for their own legal basis, website privacy notice, consent configuration where required, and ensuring the Service is not installed on pages that collect sensitive data unless appropriate safeguards are in place.
Minimization
Data categories
Account email, authentication metadata, website domains, plan and billing state, support messages, and operational logs needed to run the dashboard.
Page path, device category, viewport dimensions, scroll depth, click coordinates, rage-click signals, timing, and structural element metadata such as tag name, input type, field order, and form order.
Hosting and security providers may process HTTP metadata such as IP addresses for delivery, abuse prevention, rate limiting, and auditing.
The tracking snippet does not set cookies, use browser storage, collect form values, send readable page copy, send raw mouse trails, or create a persistent visitor ID. heatmapp analytics storage is designed not to persist full visitor IP addresses.
Lifecycle
| Data category | Retention |
|---|---|
| Raw minimized processing rows | Maximum 72 hours for aggregation, debug, and backfill |
| Trial and unknown plan aggregates | 30 days |
| Starter aggregates | 90 days |
| Pro aggregates | 12 months |
| Account and billing records | As needed for service, legal, tax, and dispute obligations |
Vendors
Provider
Purpose
Website hosting, CDN, edge/functions runtime, and operational logs
Data processed
HTTP metadata, account and app traffic needed to deliver the Service
Location / transfer posture
Global edge network for delivery; operational processing under Netlify transfer safeguards
Provider
Purpose
Application database, authentication, and account data storage
Data processed
Customer account data, website configuration, subscription state, and app metadata
Location / transfer posture
EU project region for primary application database and authentication data
Provider
Purpose
Short-lived analytics processing and aggregate reporting queries
Data processed
Minimized processing rows and aggregate UX counts without full visitor IP addresses, full user agents, cookies, or replay data
Location / transfer posture
EU, Google Cloud europe-west2, for event ingest, processing, and query storage
Provider
Purpose
Payments, invoices, tax, and subscription lifecycle
Data processed
Billing contact, payment status, invoices, and Stripe customer identifiers
Location / transfer posture
Stripe payment infrastructure, with EU/UK transfer safeguards where billing data leaves the EEA
Provider
Purpose
Screenshot and privacy checker infrastructure
Data processed
Public page URLs and screenshot/checker processing metadata
Location / transfer posture
EU deployment region for screenshot and privacy-checker processing where configured
Provider
Purpose
Transactional email delivery
Data processed
Customer email address and transactional email metadata
Location / transfer posture
Email delivery infrastructure with vendor transfer safeguards for delivery outside the EEA
Provider
Purpose
Optional AI insights generated from aggregated UX patterns
Data processed
Aggregated interaction summaries, not raw form values or visitor profiles
Location / transfer posture
Europe only when requests are sent through an OpenAI API project configured for European data residency; otherwise subject to OpenAI API data processing terms
Residency
We aim to keep primary application and analytics processing in EU regions where our providers support that configuration. Some providers use global infrastructure for delivery, payment, email, security, support, or abuse-prevention operations.
Where data is transferred outside the EEA, we rely on vendor data processing terms, Standard Contractual Clauses, adequacy decisions, or other lawful transfer mechanisms made available by those providers.
OpenAI residency note
OpenAI API requests are EU-resident only when sent through a new API project configured for European data residency. OpenAI says eligible API requests through those projects are handled in-region with zero data retention, meaning model requests and responses are not stored at rest on OpenAI servers. Existing API projects cannot be converted after creation according to OpenAI's current public residency page.
OpenAI data residency informationCustomer copy
Paste-ready starting point for customer sites. Customers should adapt this with counsel to match their jurisdiction and legal basis:
We use heatmapp to understand aggregate interaction patterns on our website, such as clicks, scroll depth, page paths, device category, and rage-click signals. heatmapp's customer tracking snippet does not use cookies or localStorage, does not record sessions, does not collect form field values or keystrokes, and does not create a persistent cross-device visitor profile. Interaction data is used to improve our website experience and is retained according to our analytics retention settings.
Assessment
Customers relying on legitimate interests should document the purpose of UX improvement, necessity of minimized heatmap analytics, and balancing safeguards: no cookies, no replay, no form values, no persistent visitor ID, shortened retention, and clear privacy notice disclosure.
Requests
End visitors should contact the website owner first because the customer controls the relationship and legal basis. Customers can then contact support@heatm.app with the website, approximate time range, page path, and request type. Because heatmapp intentionally avoids persistent visitor identity, requests are handled by deletion or narrowing based on available event context rather than by a cross-site visitor profile.