Datenschutzerklärung · Last updated: July 30, 2026
This English version is authoritative. A German translation is planned; until then, please contact us if anything is unclear.
The controller responsible for the processing described here, within the meaning of Art. 4(7) GDPR, is:
Stefan Rosanitsch
Kriegerdankstr. 14
96450 Coburg
Germany
Email: stefanrows@gmail.com
Contact form: xpmetric.com/contact
Full provider details are in our Impressum.
Data protection officer: We have not appointed a data protection officer. XPmetric is operated by a single person and does not meet the thresholds of Art. 37(1) GDPR or § 38(1) BDSG. You can raise any data protection matter directly with the controller above.
XPmetric processes personal data in two distinct roles, and your rights differ depending on which one applies to you.
Email address, display name, profile image (only if you sign in with Google), timezone, notification preferences, subscription status and billing identifiers. Purpose: providing the service you signed up for and administering the contract. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Payment status, amounts, currency and the customer and subscription IDs assigned by our payment provider. We never see or store your full card number. Purpose: taking payment and issuing invoices. Legal basis: Art. 6(1)(b) GDPR for the payment itself, and Art. 6(1)(c) GDPR for retaining accounting records as required by § 147 AO and § 257 HGB.
Cloudflare Turnstile on the login and contact forms, rate limiting, and server logs. Purpose: keeping the service available and defending against spam, credential stuffing and denial-of-service attacks. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is operating a secure service. Balancing: the data involved is limited to what a web server necessarily receives, it is not used to profile anyone and it is not combined with your account activity, so we consider your interests not to override ours.
When something breaks we record the error message, stack trace, the URL involved and — if you were signed in — your user ID. Purpose: finding and fixing faults. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is a working product. Balancing: logs are internal, access is limited to the controller, and they are not used for any decision about you.
We use Google Analytics 4 on this website only. It is not loaded at all unless you opt in — no Google script is requested and no identifier is stored before your consent. Purpose: understanding which pages and campaigns work. Legal basis: Art. 6(1)(a) GDPR and, for the storage of and access to information on your device, § 25(1) TDDDG. Advertising features, Google Signals and ad personalisation are switched off; the corresponding Google Consent Mode signals stay denied even if you accept analytics.
Our testimonial widget is provided by ProofSwap. It is replaced by a placeholder until you actively choose to load it, because loading it discloses your IP address to the provider. Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG.
Sign-in links, billing notices, daily digests and weekly recaps. Legal basis: Art. 6(1)(b) GDPR for emails necessary to run your account, and Art. 6(1)(f) GDPR for onboarding and product emails to existing customers (§ 7(3) UWG). Every non-essential email carries a one-click unsubscribe link, and you can turn digests and recaps off in your settings at any time.
For customers on the Growth plan we retrieve public posts on X that mention their tracked domain, together with the author’s handle, display name and avatar, and show them on that customer’s traffic chart. Legal basis: Art. 6(1)(f) GDPR — the legitimate interest of a site owner in knowing who is talking about their site publicly. Only content the author published publicly is used. If you are an author and object to this, contact us and we will remove and suppress your posts.
This is the data we process as a processor (see section 2). For each pageview we receive: page URL and path, referrer, UTM campaign parameters, device type, browser, operating system, country and city derived from the IP address, and any custom events or revenue the site owner configures.
We do not store raw IP addresses in our analytics databases. In the default cookieless mode, visitor identity is a non-reversible hash computed on our servers from the visitor’s IP address, browser and the tracked site, salted with random bytes that rotate every 24 hours and are then deleted. The same person therefore gets a new, unlinkable identifier every day, and past visitors cannot be re-identified, even by us. The hash is scoped per site, so visitors are never linked across websites. IP addresses are used transiently to compute that hash and to look up an approximate location using a local database, and are then discarded.
One exception to be transparent about: our web server currently writes IP addresses to its access log, which is kept for troubleshooting and is separate from the analytics databases described above. We are in the process of removing them from that log.
The table below lists everything set on this website. Names shown without a prefix additionally carry the __Secure- or __Host- prefix when served over HTTPS.
| Name | Provider | Purpose | Category | Lifetime |
|---|---|---|---|---|
cc_cookie | XPmetric | Stores your consent choice and the consent ID, so we can prove and honour it (Art. 7(1) GDPR) | Strictly necessary | 6 months |
authjs.session-token | XPmetric | Keeps you signed in | Strictly necessary | 30 days |
authjs.csrf-token | XPmetric | Protects sign-in forms against cross-site request forgery | Strictly necessary | Session |
authjs.callback-url | XPmetric | Returns you to the right page after sign-in | Strictly necessary | Session |
xpm_pending_domain | XPmetric | Remembers the domain you typed on the homepage so it survives opening a sign-in link in a new tab | Strictly necessary | 1 hour |
_xpm (sessionStorage) | XPmetric | Our own tracking script measuring this website, so a visit is counted once per session | Strictly necessary | Until the tab is closed |
xpm:* (local/session storage) | XPmetric | Interface preferences, for example whether a coach mark has been dismissed or the live map sound is on | Strictly necessary | Until you clear site data |
_ga, _ga_* | Distinguishes visitors for Google Analytics statistics | Analytics (consent) | Up to 2 years | |
| ProofSwap widget storage | ProofSwap | Set only after you click to load the testimonial widget | Embeds (consent) | Set by the provider |
cf_clearance, __cf_bm | Cloudflare | Set only if Cloudflare issues a security challenge, to record that it was passed | Strictly necessary | Up to 30 minutes / 1 year |
Withdrawing your consent (Art. 7(3) GDPR): you can change or withdraw your choice at any time via in the footer of any page. Withdrawal takes effect immediately and is as easy as giving consent, but it does not affect the lawfulness of processing carried out before you withdrew.
We do not sell, rent or trade personal data. We use the following service providers, each bound by a data processing agreement where they act on our behalf:
| Recipient | Purpose | Location | Transfer basis |
|---|---|---|---|
| Hetzner Online GmbH | Servers and databases | Germany (Nuremberg) | EU — none needed |
| Cloudflare, Inc. | CDN, DDoS protection, Turnstile | USA / global edge | SCCs; DPF certified |
| Stripe Payments Europe, Ltd. (with Stripe, Inc.) | Payment processing | Ireland / USA | SCCs; DPF certified |
| Google Ireland Ltd. (with Google LLC) | Google Analytics on this website; Google sign-in if you choose it | Ireland / USA | SCCs; DPF certified |
| Resend, Inc. | Sending transactional email | USA | SCCs; DPF certified |
| ProofSwap | Testimonial widget (only after you load it) | See provider | Your consent, Art. 49(1)(a) GDPR |
| X Corp. | Retrieving public posts mentioning a tracked domain | USA | SCCs |
Transfers to the USA carry the residual risk that public authorities there may access data under local law, and that the available legal remedies may not match those in the EU. Where a provider is certified under the EU-US Data Privacy Framework, the transfer is covered by the Commission’s adequacy decision; otherwise it relies on Standard Contractual Clauses.
All servers holding your account and analytics data are located in Germany. Data is encrypted in transit using TLS.
| Category | Retention |
|---|---|
| Analytics events (pageviews, custom events) | 2 years from the event, then deleted automatically by the database |
| Account data and site configuration | Until you delete your account |
| Analytics data after a subscription lapses | Deleted at the end of the grace period; the account and site configuration are kept |
| Invoices and accounting records | 10 years (§ 147 AO, § 257 HGB) — these survive account deletion because the law requires it |
| Consent records | Kept as proof under Art. 7(1) GDPR while the consent is current, and afterwards for as long as needed to demonstrate compliance |
| Error logs | Deleted once resolved and no longer needed for debugging |
| Email delivery logs | Kept to prevent duplicate sends and to honour unsubscribes |
| Web server access logs | Short-term, for troubleshooting and abuse defence |
You have the right to:
Right to object (Art. 21 GDPR)
Where we rely on legitimate interests (Art. 6(1)(f)) — security, error logging, product emails and public X mentions — you have the right to object at any time on grounds relating to your particular situation. We will then stop that processing unless we can demonstrate compelling legitimate grounds that override your interests. Where data is processed for direct marketing, you can object at any time and we will stop unconditionally.
You can exercise several rights yourself from your Settings: “Export My Data” downloads your profile, sites, event summaries, achievements and usage history as JSON, and “Delete My Account” removes your data. For anything else, email us — we respond within one month (Art. 12(3) GDPR).
Right to lodge a complaint (Art. 77 GDPR): you may complain to a supervisory authority, in particular in the member state of your residence, place of work or of the alleged infringement. The authority competent for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27, 91522 Ansbach, Germany
www.lda.bayern.de
We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.
Providing an email address is necessary to create an account and use the service — without it we cannot enter into the contract. Everything else is optional. Consent-based processing is entirely voluntary and refusing it has no consequence beyond the specific feature not loading.
Our tracking script honours the Do Not Track browser signal. When DNT is enabled, no analytics data is collected from that visitor.
We may update this policy as the service changes. If we make significant changes we will notify you by email or in the app, and where the change concerns consent we will ask for it again.
For privacy questions or to exercise your rights, email stefanrows@gmail.com or use the contact form.