Counter Privacy Notice
Version 2026-07-31-2
Operator and contact
Counter is operated in Canada by the registrant and administrator of webcounter.ca. Privacy, access, correction, deletion, abuse, and support requests can be sent to smagik@beava.ca.
Account and analytics data
We store account email, password and credential hashes, MFA security records, policy-acceptance evidence, site configuration, quotas, lifecycle audit records, and analytics events submitted by configured sites. Raw visitor IP addresses are used transiently for coarse location, rate limiting, and keyed daily identifiers; they are not stored in analytics event records.
Purposes and disclosure
Data is used to provide and secure the service, enforce limits, prevent abuse, deliver account messages, answer support requests, and meet legal obligations. It is not sold. Verification and recovery mail is processed by the operator’s shared first-party email service. Infrastructure providers necessarily process hosted data. Dashboard maps use the configured tile provider; the default external OpenStreetMap tile service can learn the map region viewed and the signed-in operator’s network address.
Retention and deletion
Raw analytics event retention is configured by the service and currently defaults to 400 days; aggregate rollups may be retained longer. Sensitive account mail is untracked and retained for no more than seven days. Account and site deletion is recoverable for 30 days, followed by verified purge. Encrypted local backups expire after 14 days, making the maximum expected erasure window 44 days.
Control and rights
Account owners can change their email and password, manage MFA and sessions, export analytics, delete sites, and delete the account. Requests that cannot be completed in the product may be sent to the contact above. We may need to verify identity before disclosing or changing account data. Applicable law may provide additional access, correction, deletion, objection, portability, or complaint rights.
Roles and safeguards
Site owners decide what sites send and remain responsible for their visitor notices and lawful basis. Operational security and abuse logs contain bounded metadata rather than customer analytics payloads. Platform operators may manage lifecycle metadata but cannot impersonate customers or open their analytics. We use access controls, hashed credentials, MFA, encrypted backups, and bounded retention, but no online service can promise absolute security.