Skip to content
Sealmetrics

Industry · Banking, insurance and lending

The form is submitted.
The channel
is not on record.

A bank, insurer or lender sees every application in its own systems. The channel behind it comes from analytics that loses visitors at the consent banner, and every new tag has to pass a vendor review first. Sealmetrics measures lead forms and applications by channel and campaign without cookies or stored identifiers, and publishes the DPA, the data inventory and the security measures so the review starts from documents.

EU-hosted in Dublin · DPA included · last click per session · no ISO 27001 or SOC 2 claimed · not legal advice

Quick answer

Analytics for financial services is web measurement that credits applications, quote requests and lead forms to the channels that produced them, on data a compliance and procurement review can check. Two things usually break it. A consent-based tool does not record visitors who reject the banner, so channels are judged on part of the traffic. And every new tag reopens a vendor review, so measurement stops being added. Sealmetrics counts visits without cookies or device storage, stores no IP addresses or cross-session identifiers, processes visitor data in Dublin and credits each conversion to the last click of its session. The DPA lists the fields, retention periods, security measures and sub-processors. Whether a deployment needs consent still depends on its configuration and the national authority, the site's other tags keep their own requirements, and Sealmetrics holds no ISO 27001 or SOC 2 certification.

What a vendor review asks

Six questions.
Where each answer lives.

Procurement, the DPO and information security ask any analytics vendor roughly the same things. These are the answers Sealmetrics documents, next to the document that says it.

The questionWhat to ask any vendor forSealmetrics, as documentedWhere to verify
What is collected about visitors?A field-by-field inventory with retentionPage, referrer, campaign, device category, time zone and conversions; no IP, user ID, email or name stored; event rows purged after 1 day, aggregates kept 24 monthsWhat we track · DPA Annex 1
Is anything stored on the visitor's device?A statement you can check in the browserNo cookies, localStorage or sessionStorage; the session marker is pseudonymised server-side and expires after 2 hours of inactivityWhat we track · DPA Annex 2
Where is visitor data processed, and by whom?The sub-processor list and the transfer basisStored and processed in the EU; the only non-EU sub-processor sends account emails and receives no visitor dataDPA clause 7 · Annex 3
Who can reach the dashboard?Access controls and activity loggingRole-based access and two-factor authentication; audit logs from the Scale plan; IP allowlist on EnterpriseSecurity overview · pricing
What security evidence exists?Certifications or equivalent documentationNo ISO 27001 or SOC 2; security measures in DPA Annex 2, a TPSR package and assistance with impact assessmentsDPA Annex 2 · clause 4.6
What happens when the contract ends?Export and deletion terms30 days to export through the API or BigQuery, then deletion or return of the dataDPA clause 4.8

None of these answers approves a vendor on its own: your procurement, DPO and security teams still run their assessment. The field list is public in what we track, the contractual terms are in the DPA, and why a minimal dataset matters is explained under personal data in analytics.

What the current setup costs

Two gates.
Both cost data.

Consent loss and review friction never appear as a budget line. They appear as channels judged on part of the traffic, and as measurement nobody adds.

01

Channels judged on the visitors who accepted

A consent-based tool records only the visitors who accept its banner. The Sealmetrics documentation puts the loss at 15–60% of EU visitors depending on sector, brand strength and traffic mix; no figure for financial services has been published. Acquisition budgets for accounts, cards or policies are then split on a partial mix, the problem described under data loss in analytics.

02

Measurement that never gets added

A new tag, identifier or purpose changes the processing and can reopen the vendor review. When every addition costs a review, the quote calculator or the second step of an application simply goes unmeasured.

03

Applications credited to the wrong domain

Applications often finish on a separate onboarding, identity-verification or payment domain. Without configuration, the visit that returns from it is credited to that domain as a referral instead of the campaign that started it, as the external-domain guide explains.

From vendor review to reporting

Review first.
Then measure.

Five steps, in the order a regulated organisation usually needs them. The event-level detail for forms is in conversion tracking.

  1. Run the vendor review on documents

    Give procurement, the DPO and information security the DPA with its annexes (data processed, retention, security measures, sub-processors), the public field list and the TPSR package. Record the purposes you enable: aggregated audience measurement, and marketing attribution as a separate, optional purpose assessed on its own terms.

  2. Implement without personal data in what you send

    Install the tracker, which takes 5 to 30 minutes depending on the platform, and send completed lead forms, quote requests and applications as conversions with generic properties such as product line or form name. Never put names, emails, account or policy numbers in properties, URLs or campaign names: the DPA makes that the controller's obligation, and there is no server-side list of allowed properties.

  3. Keep the channel through onboarding domains

    If applications continue on an external onboarding, identity-verification or payment domain, register that domain as a passthrough referrer through the API, so the conversion keeps the campaign that started the session. Advertising pixels stay under your consent banner as before.

  4. Run it in parallel and reconcile with your own systems

    Keep the current analytics running for at least one full campaign cycle. Compare measured applications with the count in your CRM or core system for the same period, by total and by channel. Comparison is never record by record, because application and customer IDs are never sent to Sealmetrics.

  5. Report on the reconciled base

    Read applications and conversion rate by channel, campaign and landing page, and share the same numbers with marketing, compliance and management. On Scale and Enterprise, audit logs record who changed users, conversions, settings and API tokens.

Who signs off, who uses it

Four reviewers.
One set of documents.

Each function asks a different question of the same deployment, and each has a document or a report that answers it.

Marketing and acquisition

Know which channels and campaigns bring applications, not just clicks.

Applications and lead forms by source, medium and campaign, credited to the last click of each session, without consent loss.

Revenue attribution

DPO and compliance

Document what is processed, for which purpose and where.

The Article 28 DPA with its data inventory and sub-processors, assistance with impact assessments, and country analyses that are self-assessments, not certifications.

Analytics for DPOs

Information security

Assess access, encryption and the vendor's own controls.

TLS in transit and AES-256 at rest, role-based access and 2FA, audit logs from Scale, IP allowlist and isolated processing on Enterprise.

Security overview

Management

One acquisition number that marketing and compliance both accept.

Measured totals reconciled with the applications your own systems booked, before any channel is compared.

Single source of truth

Evidence, not a sector case

Sealmetrics has no published case study from a bank, insurer or lender, and does not present one. What a financial services review can read today are the documents below. The one measured figure comes from an eCommerce parallel run and is shown as context for how consent loss behaves, not as a financial services result.

Annex 2

security measures: encryption, pseudonymisation, per-client isolation, retention by TTL and logged access

Data Processing AgreementOpen
0

security certifications claimed: no ISO 27001, no SOC 2; the controls are documented instead

Security overviewOpen
29%

of visits GA4 did not record over 48 days on a Shopify store; eCommerce context, not a finance result

Incapto · eCommerceOpen

What it does not do

It measures channels.
It does not know the applicant.

These limits follow from measuring without identifying anyone, and from what a vendor can and cannot settle for you. Attribution is last click within each session, by design.

No applicant-level analysis

No customer IDs, individual journeys or returning-visitor recognition. A person who starts an application today and finishes it next week is a new visit.

Last click per session

No lookback across sessions, no view-through and no multi-touch model. A long consideration cycle is credited to the session in which the application is completed.

Other tags keep their own obligations

Advertising pixels, chat widgets and A/B testing tools that store or read data on the device keep their own consent requirements, whatever the analytics does.

It does not replace your assessments

The DPA, the TPSR package and the self-assessments are material for your DPIA, vendor risk review and legal analysis. They do not replace them, and none of this is legal advice.

No sector certification

No ISO 27001 or SOC 2, and no claim about DORA, EBA outsourcing guidelines or other financial-sector rules. Assess those against your own obligations.

It does not feed ad platforms

Sealmetrics sends no conversions to Google Ads or Meta and imports no spend. Keep their own tags for bidding.

Questions financial services teams ask

Before the tag
goes to review.

Does Sealmetrics need a cookie banner on a bank or insurer's website?

For the analytics itself, Sealmetrics sets no cookie, stores nothing on the visitor's device and stores no IP address or cross-session identifier. Whether a specific deployment is exempt from consent depends on its configuration, the purposes you enable and your national authority's criteria. The site's other tags, such as advertising pixels, keep their own consent requirements, so a banner may still be needed for them.

What documentation can procurement and the DPO get?

The Article 28 DPA with its annexes: data processed and retention, security measures, sub-processors and the transfer framework. Also the public field list in the documentation and a TPSR package for technical, privacy and security review; impact assessment and legitimate interest documentation are available on request. Sealmetrics assists with DPIAs under clause 4.6 of the DPA, and customers have audit rights under clause 4.7.

Which certifications does Sealmetrics hold, including ISO 27001 and SOC 2?

None. Sealmetrics holds no ISO 27001 or SOC 2 certification and claims no financial-sector certification. Its security measures are listed in Annex 2 of the DPA: encryption in transit and at rest, server-side pseudonymisation of the session marker, per-client isolation, retention enforced by database TTLs, and role-based access with multi-factor authentication.

Where is visitor data processed, and are there sub-processors outside the EU?

Visitor data is stored and processed in Dublin, Ireland. Annex 3 of the DPA lists the sub-processors: infrastructure hosting in Ireland, AI inference in Paris, and Resend in the US for service emails to account users, under SCCs and the Data Privacy Framework. That US sub-processor receives no visitor data.

Can we measure lead forms and applications without sending personal data?

Yes. Send each completed form or application as a conversion, for example a lead with a form name and a product line, and never the applicant's name, email, account number or any other personal data. The same applies to URLs and campaign names. There is no server-side list of allowed properties and they can be read back by anyone with access to the site's reports, so what you send is your responsibility as controller.

Who can access the data, and is that access logged?

Access follows the roles in your organization, and two-factor authentication is available to every user. On Scale and Enterprise, audit logs record logins, user and invitation changes, conversion and settings changes, and API token activity, with the actor, the time and the IP address. Viewing a report is not among the logged actions. IP allowlists and isolated processing are available on Enterprise.

How is an application credited when it finishes on another domain?

Sealmetrics credits each conversion to the last click of its session, which closes after 2 hours of inactivity. If the application moves to an external onboarding, identity-verification or payment domain, register that domain as a passthrough referrer through the API; otherwise the returning visit is credited to that domain as a referral. There is no attribution across sessions.

Vendor review walkthrough

Bring procurement.
We bring the documents.

Thirty minutes with the person responsible for the implementation: the data inventory, the DPA and its annexes, access controls by plan, and how lead forms are measured without personal data.