Legal
Privacy Policy
This policy explains how [LEGAL ENTITY NAME] ("FunnelSplit", "we") handles personal data. It covers three situations: when you visit this website, when you hold a FunnelSplit account, and when you visit pages our customers publish with FunnelSplit.
1. The short version
- We use one first-party cookie for analytics and test assignment. No third-party trackers, no ad pixels of our own, no cross-site anything.
- We never store raw IP addresses — only salted one-way hashes. Country-level geo is derived at ingest, then the IP is discarded.
- Data submitted through a customer's form belongs to that customer's workspace; we process it on their instructions.
- Export and deletion are built into the product, not a support ticket.
2. When you visit funnelsplit.com or a page published with FunnelSplit
What we collect
- fs_vid cookie — a random first-party identifier (13-month lifetime) used to count unique visitors, keep A/B test assignments stable, and attribute conversions. It contains no personal details and is never shared across unrelated sites.
- Usage events — pageviews, test exposures, clicks and scroll depth, with coarse device info (browser, OS, screen class) and country derived from your IP. The IP itself is immediately reduced to a salted hash used only for rate limiting and abuse prevention.
- Form submissions — whatever you type into a form is stored for the workspace that owns the page (see §3).
Legal basis
Legitimate interest (Art. 6(1)(f) GDPR) for aggregate, privacy-preserving analytics and fraud prevention; consent where a page's form requests it (e.g. marketing opt-in, double opt-in confirmation).
3. Data submitted to our customers ("their contacts")
For pages, forms and automations published by a FunnelSplit customer, the customer is the data controller and FunnelSplit is a processor acting on their instructions. Requests about that data (access, correction, deletion) should go to the business whose page you visited; we support them with built-in tools: consent tracking, double opt-in, machine-readable export, and hard deletion that also unlinks analytics identifiers. Our data-processing agreement is available on request at support@funnelsplit.com.
4. When you hold a FunnelSplit account
- Account data: name, email, hashed password (argon2id), optional 2FA secrets, workspace membership and roles.
- Billing data (when checkout launches): handled by Paddle as merchant of record; we receive subscription status, not card numbers.
- Operational logs: security-relevant actions are recorded in your workspace's audit log (actor, action, salted IP hash).
- Email provider credentials you connect are encrypted at rest with AES-256-GCM and used only to send the messages you configure.
5. Retention
- Raw analytics events: 13 months, then deleted automatically.
- Aggregated statistics (daily rollups, heatmap grids): up to 24 months.
- Contacts, submissions, pages: for the life of the workspace, or until the workspace deletes them.
- Deleted workspaces: purged within [30 days], except where law requires longer.
6. Sharing
We do not sell personal data. We share it only with: infrastructure subprocessors (hosting at [hosting provider, location]), Paddle for payments, and the email provider you connect (which receives the messages you send). A current subprocessor list is available on request.
7. International transfers
Data is hosted in [server location / country]. Where personal data is transferred outside the EEA/UK, we rely on adequacy decisions or Standard Contractual Clauses.
8. Your rights
Depending on your location you may have rights to access, rectify, erase, restrict, port, or object to processing of your personal data, and to lodge a complaint with a supervisory authority. Account holders can exercise most of these directly in the product; for anything else, email support@funnelsplit.com. For data submitted to a customer's page, contact that customer (see §3) — we'll assist them.
9. Security
TLS everywhere (including automatic certificates for customer domains), encrypted credentials at rest, salted IP hashing, role-based access within workspaces, tenant isolation enforced at the data layer, nightly backups, and audit logging. No system is perfectly secure; we notify affected controllers and authorities of breaches as required by law.
10. Children
The Service is not directed at children under 16 and customers may not use it to knowingly collect their data.
11. Changes
We'll post updates here and, for material changes, notify account holders by email or in-app at least 14 days in advance.
12. Contact
Controller for this website and account data: [LEGAL ENTITY NAME], [address] · support@funnelsplit.com[ · DPO / EU representative if applicable]