Legal and trust

DPA, subprocessors, and data map

heatmapp is designed as a cookieless UX analytics layer. This page summarizes our processor terms, privacy guardrails, subprocessors, retention schedule, data-location notes, and a customer privacy notice starter.

Agreement

Data Processing Agreement

For end-visitor analytics collected through the heatmapp snippet, the customer is the controller and Slickful Group LLC acts as the processor. We process personal data, if any, only to provide, secure, maintain, and improve the Service under the customer's documented instructions and applicable law.

We maintain appropriate technical and organizational measures, including access controls, transport encryption, data minimization, retention limits, and separation between customer snippet analytics and heatm.app marketing analytics. We will assist customers with reasonable data subject requests, security inquiries, and deletion workflows where the requested data can be located from customer website, path, time range, and ephemeral session context.

Customers remain responsible for their own legal basis, website privacy notice, consent configuration where required, and ensuring the Service is not installed on pages that collect sensitive data unless appropriate safeguards are in place.

Minimization

Product guardrails

  • No session replay, DOM recording, keystroke capture, or video.
  • No cookies or localStorage in the customer tracking snippet.
  • No cross-session or cross-device visitor identity.
  • No form values, query-string referrers, full user agents, or full IP addresses in analytics storage.
  • Dashboards focus on population-level UX patterns, not individual visitor dossiers.

Data categories

Data map

Customer account and dashboard

Account email, authentication metadata, website domains, plan and billing state, support messages, and operational logs needed to run the dashboard.

Customer tracking snippet

Page path, device category, viewport dimensions, scroll depth, click coordinates, rage-click signals, timing, and structural element metadata such as tag name, input type, field order, and form order.

Infrastructure

Hosting and security providers may process HTTP metadata such as IP addresses for delivery, abuse prevention, rate limiting, and auditing.

The tracking snippet does not set cookies, use browser storage, collect form values, send readable page copy, send raw mouse trails, or create a persistent visitor ID. heatmapp analytics storage is designed not to persist full visitor IP addresses.

Lifecycle

Retention schedule

Data categoryRetention
Raw minimized processing rowsMaximum 72 hours for aggregation, debug, and backfill
Trial and unknown plan aggregates30 days
Starter aggregates90 days
Pro aggregates12 months
Account and billing recordsAs needed for service, legal, tax, and dispute obligations

Vendors

Subprocessors

Provider

Netlify

Purpose

Website hosting, CDN, edge/functions runtime, and operational logs

Data processed

HTTP metadata, account and app traffic needed to deliver the Service

Location / transfer posture

Global edge network for delivery; operational processing under Netlify transfer safeguards

Provider

Supabase

Purpose

Application database, authentication, and account data storage

Data processed

Customer account data, website configuration, subscription state, and app metadata

Location / transfer posture

EU project region for primary application database and authentication data

Provider

Tinybird

Purpose

Short-lived analytics processing and aggregate reporting queries

Data processed

Minimized processing rows and aggregate UX counts without full visitor IP addresses, full user agents, cookies, or replay data

Location / transfer posture

EU, Google Cloud europe-west2, for event ingest, processing, and query storage

Provider

Stripe

Purpose

Payments, invoices, tax, and subscription lifecycle

Data processed

Billing contact, payment status, invoices, and Stripe customer identifiers

Location / transfer posture

Stripe payment infrastructure, with EU/UK transfer safeguards where billing data leaves the EEA

Provider

Railway

Purpose

Screenshot and privacy checker infrastructure

Data processed

Public page URLs and screenshot/checker processing metadata

Location / transfer posture

EU deployment region for screenshot and privacy-checker processing where configured

Provider

Resend

Purpose

Transactional email delivery

Data processed

Customer email address and transactional email metadata

Location / transfer posture

Email delivery infrastructure with vendor transfer safeguards for delivery outside the EEA

Provider

OpenAI

Purpose

Optional AI insights generated from aggregated UX patterns

Data processed

Aggregated interaction summaries, not raw form values or visitor profiles

Location / transfer posture

Europe only when requests are sent through an OpenAI API project configured for European data residency; otherwise subject to OpenAI API data processing terms

Residency

International transfers and data location

We aim to keep primary application and analytics processing in EU regions where our providers support that configuration. Some providers use global infrastructure for delivery, payment, email, security, support, or abuse-prevention operations.

Where data is transferred outside the EEA, we rely on vendor data processing terms, Standard Contractual Clauses, adequacy decisions, or other lawful transfer mechanisms made available by those providers.

OpenAI residency note

OpenAI API requests are EU-resident only when sent through a new API project configured for European data residency. OpenAI says eligible API requests through those projects are handled in-region with zero data retention, meaning model requests and responses are not stored at rest on OpenAI servers. Existing API projects cannot be converted after creation according to OpenAI's current public residency page.

OpenAI data residency information

Customer copy

Customer privacy notice template

Paste-ready starting point for customer sites. Customers should adapt this with counsel to match their jurisdiction and legal basis:

We use heatmapp to understand aggregate interaction patterns on our website, such as clicks, scroll depth, page paths, device category, and rage-click signals. heatmapp's customer tracking snippet does not use cookies or localStorage, does not record sessions, does not collect form field values or keystrokes, and does not create a persistent cross-device visitor profile. Interaction data is used to improve our website experience and is retained according to our analytics retention settings.

Assessment

Legitimate Interest Assessment starter

Customers relying on legitimate interests should document the purpose of UX improvement, necessity of minimized heatmap analytics, and balancing safeguards: no cookies, no replay, no form values, no persistent visitor ID, shortened retention, and clear privacy notice disclosure.

Requests

End-visitor rights process

End visitors should contact the website owner first because the customer controls the relationship and legal basis. Customers can then contact support@heatm.app with the website, approximate time range, page path, and request type. Because heatmapp intentionally avoids persistent visitor identity, requests are handled by deletion or narrowing based on available event context rather than by a cross-site visitor profile.