No visitor storage
The measurement pixel writes no cookie, localStorage, sessionStorage or IndexedDB entry to the visitor device.
Trust center · security posture
SealMetrics begins with data minimisation, then applies encryption, isolation and automatic retention to the aggregate evidence that remains.
GDPR by architecture · ePrivacy · Schrems II clean · Dublin, Ireland
Four structural controls
Security is easier to inspect when each control has a narrow job. The first four remove data and identity paths conventional analytics normally creates.
The measurement pixel writes no cookie, localStorage, sessionStorage or IndexedDB entry to the visitor device.
Visitor IP addresses have no analytics-database column. Any network handling is transient and is not retained as analytics data.
Every data path is scoped to an account. Requests are checked against that boundary before analytics records are read.
Reports use aggregate commercial events, without names, emails or identifiers designed to follow a person across websites.
Inspect the data path
Visitor measurement and the service databases operate in Dublin, Ireland. Each stage narrows what can proceed to the next one.
The browser sends the page or commercial event without writing an identifier to the device.
Domain checks and expiring signed tokens reduce unauthorised event injection.
Operational records are separated by account and converted into reporting aggregates.
Retention is enforced by the data layer instead of relying on a manual deletion calendar.
Technical and organisational measures
The summary below is aligned with the DPA. When a contractual detail and this page differ, the signed DPA prevails.
| Control | Applied measure | Evidence boundary |
|---|---|---|
| Transport | TLS 1.2+ | Service communications |
| Data at rest | AES-256 | Service databases and encrypted backups |
| Access | RBAC, MFA and least privilege | User and administrative access |
| Customer isolation | Account-scoped keys and query validation | All analytics storage layers |
| Secrets | Managed outside source code | Platform credentials and customer BYOK keys |
| Administrative activity | Logged access | Privileged service operations |
Retention is a control
Analytics retention does not depend on someone remembering to run a deletion process. Database-level TTLs enforce the operating periods.
| Data class | Maximum operating period |
|---|---|
| Event-level technical log | 1 day |
| Hourly aggregates | 90 days |
| Daily aggregates and conversions | 24 months |
| Active session state | 2 hours |
Procurement evidence
SealMetrics documents the architecture, contractual measures and subprocessors without presenting a certification the company does not hold.
Data minimisation, purpose restriction and an Article 28 DPA.
No visitor-device storage is required for measurement.
Visitor analytics data remains in Dublin, Ireland.
Technical and organisational measures and audit rights are documented.
A structured package for technical, privacy and security review.
SealMetrics does not currently claim ISO 27001 or SOC 2 certification.
Review the source documents
Use the DPA for contractual controls, the privacy policy for processing disclosures and the Trust Center for the wider assurance surface.
Security review
Walk through retention, isolation, the Dublin data boundary and the DPA with the person responsible for the implementation.