Legal — Privacy
Privacy policy.
A privacy policy for an analytics company should be its proudest document or its most embarrassing one. We built RemNet so this could be the first kind: no cookies, no stored IP addresses on events, no fingerprinting, no data resale — and everything hosted in the EU. Here is the complete picture.
1. The short version
- This marketing website runs no analytics and sets no cookies.
- The RemNet tracker on our customers’ sites is cookieless and collects no personal data by default: random identifiers, page URLs, timings, scroll depth, click coordinates. No stored IPs, no typed text, no fingerprints.
- Everything is stored on servers in the European Union.
- We never sell or share data for advertising — not yours, not your visitors’.
- Account holders can export and delete their data; deletion completes within 30 days.
2. Who we are
RemNet, a business registered in the Netherlands, KVK number 94695245, establishment number 000060149787, Verdunplein 17, Unit C8110, 5627 SZ Eindhoven, the Netherlands. Contact for anything in this policy: info@remnet.io. We have not appointed a dedicated data protection officer; privacy questions are handled directly by RemNet at that address.
3. Two hats: controller and processor
We handle personal data in two distinct roles:
- As controller — for data about our own account holders, visitors to this website, and people who e-mail us. Sections 4, and 6–13 cover that.
- As processor — for data our tracker collects from visitors to our customers’ websites, on those customers’ behalf and instructions. The customer whose site you visited is the controller of that data.
If you visited a website that uses RemNet and you have questions or requests about your data, contact the operator of that website first — they control it. If they refer you to us, or you can’t reach them, e-mail info@remnet.io and we will help.
4. Data about you (account holders & this site)
If you hold a RemNet account
- Account data: e-mail address, a securely hashed password (we cannot read it), your organization/site settings, and short-lived two-factor authentication codes sent by e-mail.
- Correspondence: e-mails you send us, kept as long as needed to help you.
- Billing data (only once paid plans exist): handled by Shopify through the Shopify Billing API; we never see or store card numbers.
- Technical logs: our servers keep short-lived operational logs (IP address, user agent, request path) for security and debugging, retained for up to 30 days.
If you just read this website
We run no analytics here and set no cookies. The web server processes your IP address transiently to deliver pages — that is a technical necessity (legitimate interest), covered by the same 30-day log window, and the end of the story.
5. Data the tracker collects (for our customers)
The tracker is deliberately minimal. On a customer’s site it records, per event:
| Data | Detail |
|---|---|
| Visitor & session IDs | Random UUIDs stored in the browser’s localStorage — no cookies. Not derived from you or your device; deleted when you clear site data. Session IDs expire after 30 minutes of inactivity. |
| Page URL & referrer | The address of the page viewed and the page that led there. |
| UTM parameters | utm_source / medium / campaign, if present in the URL. |
| Timestamps & engagement | When events happened, milliseconds the tab was actually visible, maximum scroll depth (a percentage). |
| CTA clicks | The link’s destination URL and up to 120 characters of its visible label (e.g. “Check availability”). |
| Click positions | Coordinates normalized to the page, viewport/page dimensions, and a short CSS selector of the element (e.g. div>a.buy) — never element contents. |
| Device class | Server-side, the browser’s user-agent string is reduced to mobile / tablet / desktop; the string itself is not stored with events. |
It does not collect:
- anything you type — no form values, no text, no keystrokes;
- IP addresses on events — the IP is used transiently to receive the request, and is not stored in the analytics data;
- device fingerprints — no canvas, font or hardware enumeration tricks;
- identifiers shared with ad networks or any third party.
We process this data solely on the customer’s documented instructions under a data processing agreement (available at info@remnet.io), and never for our own purposes.
6. Purposes & legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service you signed up for | Account data, settings | Contract (art. 6(1)(b) GDPR) |
| Sign-in security, incl. 2FA e-mails | E-mail, 2FA codes, logs | Contract; legitimate interest (security) |
| Support | Correspondence | Contract; legitimate interest |
| Service & beta announcements | E-mail address | Legitimate interest — sparing use, every e-mail has a working unsubscribe |
| Billing (when it exists) | Billing data via Shopify | Contract; legal obligation (tax law) |
| Abuse prevention, legal compliance | Logs, account data | Legitimate interest; legal obligation |
7. Subprocessors
We keep this list short on purpose. Providers who touch personal data on our behalf:
| Provider | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting — all servers and data | Germany / Finland (EU) |
| Brevo (Sendinblue SAS) | Transactional e-mail (2FA codes, service mail) | France (EU) |
| Shopify International | Only if you connect a Shopify store — order and store data flow per your instruction, and any paid-plan charges are billed through Shopify | Ireland / Canada |
We announce material changes to this list to account holders before they take effect. There are no analytics or advertising vendors on it, and there never will be.
8. International transfers
Your data lives in the EU. Where a subprocessor involves a transfer outside the EEA (Shopify in Canada), that transfer is covered by an adequacy decision and/or the European Commission’s Standard Contractual Clauses.
9. How long we keep things
| Data | Kept for |
|---|---|
| Account data | Life of the account + 30 days |
| Tracker events & derived statistics | While the customer’s account is active; deleted within 30 days after account deletion |
| Server logs | Up to 30 days |
| Support correspondence | Up to 2 years after last contact |
| Invoices (when billing exists) | 7 years — Dutch fiscal retention duty |
10. Security
Transport encryption (TLS) everywhere; passwords stored only as strong one-way hashes; optional two-factor authentication on sign-in; infrastructure access kept to a strict least-privilege basis; data in EU data centers. The tracker’s best security feature is what it never collects in the first place — you can’t leak what you don’t have.
If a breach affecting personal data ever occurs, we notify the Dutch supervisory authority and affected users as the GDPR requires — promptly and in plain language.
11. Your rights
Under the GDPR you can ask us for access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interest. E-mail info@remnet.io; we respond within 30 days, usually much faster. We may ask you to verify you are you — that is protection, not friction.
You can also complain to the Dutch supervisory authority: Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We would prefer you e-mail us first, but that is your right, not ours.
For data collected on a customer’s website, direct requests to that website’s operator (section 3) — we assist them in fulfilling every one.
12. Children
RemNet is a business tool and not directed at children. We do not knowingly collect data from anyone under 16; if you believe we have, tell us and it will be removed.
13. Changes to this policy
When the service changes, this policy changes with it — always published here with a new effective date, and announced by e-mail to account holders when the change is material.
14. Contact
RemNet · Verdunplein 17, Unit C8110, 5627 SZ Eindhoven, the Netherlands · info@remnet.io.
Registered business