Privacy Policy
Last updated: July 1, 2026
- We never store raw IP addresses — network addresses are one-way hashed.
- We don’t sell your data, and we don’t build cross-site advertising profiles.
- Visitor data is scoped to the site that installed our tag — never pooled across customers.
- You can have a visitor’s data permanently erased, on request.
01Who this covers
ValidVisit is a traffic-quality intelligence service. Advertisers (“customers”) add a lightweight tag to their sites, and we score each paid visit 0–100 so they can tell real visitors from bots and invalid traffic. This policy explains how we handle data for two groups: the visitors to a customer’s site whose visits we score, and the customers who use our dashboard.
For visitor data, the customer is the data controller and ValidVisit is a data processor acting on their behalf. For customer-account data, ValidVisit is the controller.
02Visitor data we process
When a page carrying a customer’s tag loads, we process a minimal set of signals to judge whether the visit is genuine:
- Technical characteristics of the request, such as browser and device type.
- Coarse, city-level geography derived from the network address.
- A one-way hashed representation of the network address — we never keep the raw IP.
- On-page interaction timing (for example, how a click relates to the page load), used only to distinguish human behavior from automated behavior.
- The ad-network tracking tokens already present in the campaign URL (such as campaign, publisher and placement IDs), so a scored visit can be attributed to its source.
We do not ask for or collect names, emails, or other directly identifying details from visitors, and we don’t use this data to track individuals across unrelated sites or to target advertising.
04How we use the data
We use visitor signals for one purpose: to produce a 0–100 quality score for each visit and attribute it to the campaign, publisher and placement that sent it, so our customer can see which sources send real traffic. Aggregated reports hold counts and scores only — they contain no per-visitor identifiers.
05Retention and your rights
Raw per-visit records are retained for a limited window tied to the customer’s plan and then dropped; aggregated rollups, which carry no per-visitor identifiers, may be kept longer.
If you are a visitor and want your data removed, contact the site you visited (the controller); they can trigger a permanent, irreversible erasure of every raw event tied to your visitor identifier for that site. Depending on where you live, you may have rights under the GDPR, UK GDPR or CCPA/CPRA to access, correct or delete your data, or to object to processing.
06Customer-account data
When you create a ValidVisit account we store the details you provide — such as your email and workspace settings — to run your account. Payments are handled by our billing provider, Polar, which processes card details directly; we do not see or store your full card number.
08Security
We hash network addresses before storage, scope data to each site, encrypt data in transit, and restrict access to the people who need it to operate the service.
09Changes and contact
We may update this policy as the product evolves; the “last updated” date above reflects the current version. Questions or requests about your data can be sent to hello@validvisit.com.
See also the product overview.