SATURDAY, 8 AUGUST 2026 · Nº 220

Legal — Privacy

Privacy policy.

Effective: 8 July 2026Plain-English edition — the only edition

A privacy policy for an analytics company should be its proudest document or its most embarrassing one. We built RemNet so this could be the first kind: no cookies, no stored IP addresses on events, no fingerprinting, no data resale — and everything hosted in the EU. Here is the complete picture.

1. The short version

  • This marketing website runs no analytics and sets no cookies.
  • The RemNet tracker on our customers’ sites is cookieless and collects no personal data by default: random identifiers, page URLs, timings, scroll depth, click coordinates. No stored IPs, no typed text, no fingerprints.
  • Everything is stored on servers in the European Union.
  • We never sell or share data for advertising — not yours, not your visitors’.
  • Account holders can export and delete their data; deletion completes within 30 days.

2. Who we are

RemNet, a business registered in the Netherlands, KVK number 94695245, establishment number 000060149787, Verdunplein 17, Unit C8110, 5627 SZ Eindhoven, the Netherlands. Contact for anything in this policy: info@remnet.io. We have not appointed a dedicated data protection officer; privacy questions are handled directly by RemNet at that address.

3. Two hats: controller and processor

We handle personal data in two distinct roles:

  • As controller — for data about our own account holders, visitors to this website, and people who e-mail us. Sections 4, and 6–13 cover that.
  • As processor — for data our tracker collects from visitors to our customers’ websites, on those customers’ behalf and instructions. The customer whose site you visited is the controller of that data.

If you visited a website that uses RemNet and you have questions or requests about your data, contact the operator of that website first — they control it. If they refer you to us, or you can’t reach them, e-mail info@remnet.io and we will help.

4. Data about you (account holders & this site)

If you hold a RemNet account

  • Account data: e-mail address, a securely hashed password (we cannot read it), your organization/site settings, and short-lived two-factor authentication codes sent by e-mail.
  • Correspondence: e-mails you send us, kept as long as needed to help you.
  • Billing data (only once paid plans exist): handled by Shopify through the Shopify Billing API; we never see or store card numbers.
  • Technical logs: our servers keep short-lived operational logs (IP address, user agent, request path) for security and debugging, retained for up to 30 days.

If you just read this website

We run no analytics here and set no cookies. The web server processes your IP address transiently to deliver pages — that is a technical necessity (legitimate interest), covered by the same 30-day log window, and the end of the story.

5. Data the tracker collects (for our customers)

The tracker is deliberately minimal. On a customer’s site it records, per event:

DataDetail
Visitor & session IDsRandom UUIDs stored in the browser’s localStorage — no cookies. Not derived from you or your device; deleted when you clear site data. Session IDs expire after 30 minutes of inactivity.
Page URL & referrerThe address of the page viewed and the page that led there.
UTM parametersutm_source / medium / campaign, if present in the URL.
Timestamps & engagementWhen events happened, milliseconds the tab was actually visible, maximum scroll depth (a percentage).
CTA clicksThe link’s destination URL and up to 120 characters of its visible label (e.g. “Check availability”).
Click positionsCoordinates normalized to the page, viewport/page dimensions, and a short CSS selector of the element (e.g. div>a.buy) — never element contents.
Device classServer-side, the browser’s user-agent string is reduced to mobile / tablet / desktop; the string itself is not stored with events.

It does not collect:

  • anything you type — no form values, no text, no keystrokes;
  • IP addresses on events — the IP is used transiently to receive the request, and is not stored in the analytics data;
  • device fingerprints — no canvas, font or hardware enumeration tricks;
  • identifiers shared with ad networks or any third party.

We process this data solely on the customer’s documented instructions under a data processing agreement (available at info@remnet.io), and never for our own purposes.

6. Purposes & legal bases

PurposeDataLegal basis
Providing the service you signed up forAccount data, settingsContract (art. 6(1)(b) GDPR)
Sign-in security, incl. 2FA e-mailsE-mail, 2FA codes, logsContract; legitimate interest (security)
SupportCorrespondenceContract; legitimate interest
Service & beta announcementsE-mail addressLegitimate interest — sparing use, every e-mail has a working unsubscribe
Billing (when it exists)Billing data via ShopifyContract; legal obligation (tax law)
Abuse prevention, legal complianceLogs, account dataLegitimate interest; legal obligation

7. Subprocessors

We keep this list short on purpose. Providers who touch personal data on our behalf:

ProviderRoleLocation
Hetzner Online GmbHHosting — all servers and dataGermany / Finland (EU)
Brevo (Sendinblue SAS)Transactional e-mail (2FA codes, service mail)France (EU)
Shopify InternationalOnly if you connect a Shopify store — order and store data flow per your instruction, and any paid-plan charges are billed through ShopifyIreland / Canada

We announce material changes to this list to account holders before they take effect. There are no analytics or advertising vendors on it, and there never will be.

8. International transfers

Your data lives in the EU. Where a subprocessor involves a transfer outside the EEA (Shopify in Canada), that transfer is covered by an adequacy decision and/or the European Commission’s Standard Contractual Clauses.

9. How long we keep things

DataKept for
Account dataLife of the account + 30 days
Tracker events & derived statisticsWhile the customer’s account is active; deleted within 30 days after account deletion
Server logsUp to 30 days
Support correspondenceUp to 2 years after last contact
Invoices (when billing exists)7 years — Dutch fiscal retention duty

10. Security

Transport encryption (TLS) everywhere; passwords stored only as strong one-way hashes; optional two-factor authentication on sign-in; infrastructure access kept to a strict least-privilege basis; data in EU data centers. The tracker’s best security feature is what it never collects in the first place — you can’t leak what you don’t have.

If a breach affecting personal data ever occurs, we notify the Dutch supervisory authority and affected users as the GDPR requires — promptly and in plain language.

11. Your rights

Under the GDPR you can ask us for access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interest. E-mail info@remnet.io; we respond within 30 days, usually much faster. We may ask you to verify you are you — that is protection, not friction.

You can also complain to the Dutch supervisory authority: Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We would prefer you e-mail us first, but that is your right, not ours.

For data collected on a customer’s website, direct requests to that website’s operator (section 3) — we assist them in fulfilling every one.

12. Children

RemNet is a business tool and not directed at children. We do not knowingly collect data from anyone under 16; if you believe we have, tell us and it will be removed.

13. Changes to this policy

When the service changes, this policy changes with it — always published here with a new effective date, and announced by e-mail to account holders when the change is material.

14. Contact

RemNet · Verdunplein 17, Unit C8110, 5627 SZ Eindhoven, the Netherlands · info@remnet.io.

Registered business

RemNetKVK-nummer 94695245Verdunplein 17, Unit C8110Vestigingsnr. 0000601497875627 SZ Eindhoven, the Netherlandsinfo@remnet.io