Last updated: July 10, 2026
Taprun provides privacy-first website analytics: a small script that websites built with or connected to Taprun include to count visits. This page describes exactly what that script collects about a website’s visitors. It applies to any site carrying our tracking snippet, including our own.
utm_* campaign tags — and a bare ref= parameter, stored as the campaign source — survive), and page anchors are never sentBecause nothing identifies a person and nothing is stored on the device, sites using this analytics do not need a consent banner for it under GDPR/ePrivacy.
utm_* campaign tags, when present in the link you followedEurope/Warsaw), which is how we derive a country-level location — we never use your network address for geography. The timezone string itself is retained alongside the derived country so historical data can be re-mapped when timezone databases change; it is region-level information, and no finer location is ever derived from it.“Unique visitors” are estimated statelessly from the referrer of each landing — an approximation that requires no identifier at all. A returning visitor may be counted again.
Sites may report named events (for example signup_clicked) with small, flat metadata. Site owners are instructed not to place personal data in event metadata, and the pipeline enforces strict shape and size limits on it.
Individual pageview records are kept for up to 90 days on a rolling basis; only aggregate statistics (daily totals) are kept beyond that. Deleting a tracked site deletes its analytics data with it.
For websites our customers run, the site owner is the data controller of their visitor statistics and Taprun processes the data on their behalf, under this policy. For taprun.ai itself, Taprun is the controller. Transport-level server logs kept by our hosting providers (which, like all web infrastructure, briefly include network addresses) are outside the analytics pipeline and are never joined with it.
Contact us through the details on our Privacy Policy.