Trust / Privacy
Privacy policy
Effective 25 August 2026
Abnio Analytics (“Abnio”, “we”, “us”) provides privacy-minded analytics services and this public website. This policy explains what we process, why we process it, and the choices available to people whose information may be involved.
1. Scope and roles
This policy covers www.abnio.com, customer accounts at dash.abnio.com, and the Abnio analytics service. When a customer uses Abnio on its own website, that customer decides the purpose and configuration of collection and acts as the data controller (or equivalent role); Abnio processes that analytics data on the customer’s behalf. Questions about a specific customer website should first be directed to that website’s operator.
2. Our public website
We do not use advertising cookies or sell visitor information. Our hosting and security infrastructure may temporarily process standard request data, such as IP address, timestamp, requested path, response status and browser information, to deliver the site, prevent abuse and diagnose failures. Infrastructure logs are access-restricted and retained only as long as reasonably required for those purposes.
If you contact us, we process the details and content you choose to provide so we can reply and maintain a record of the relationship.
3. Customer accounts
To provide and secure an account, we process:
- name, email address, organization and site memberships;
- password hashes, session records, TOTP enrollment state and one-way hashes of recovery codes;
- role, permissions, login and security events; and
- support, onboarding and operational correspondence.
Authentication secrets are protected and are not displayed back after enrollment. Staff access is restricted and administrative changes are audit-logged.
4. Analytics processed for customers
First-party web analytics
Depending on the customer’s configuration, the browser beacon may process page paths and titles, referrers and campaign parameters, timestamps, pageviews, sessions, engagement and scroll metrics, interactions such as downloads and forms, custom events and properties, goals, funnels, revenue values, Web Vitals, JavaScript errors, and derived country/region/city, device, browser and operating-system categories.
No cookie or persistent client identifier is set. The IP address and limited request signals are used transiently to create a salted rotating identifier; the raw IP address is then discarded. The beacon does not store the raw User-Agent string. The identifier is specific to the customer site and rotates, limiting durable identification and cross-site tracking. Requests carrying a recognised Do Not Track signal are dropped.
Optional server-log analytics
If a customer enables Log Intelligence, Abnio processes normalized edge or origin requests, including timestamp, requested host/path, method, status, bytes, referrer, cache/CDN fields and a hashed IP value. The raw IP address is not stored. The raw User-Agent string is retained in this pipeline because it is necessary for crawler and bot classification and request-level investigation. The customer is responsible for disclosing this use on its own site.
Search and generative-engine visibility
Where enabled, Abnio processes Google Search Console query and page performance data, customer-defined prompts and brands, engine responses, detected mentions and citations, and aggregate measurements. OAuth refresh tokens used to retrieve Search Console data are encrypted at rest.
5. Why and how we use information
We use information to provide contracted services; authenticate users; enforce tenant and role boundaries; collect, aggregate and display analytics; verify installations; communicate about service and security; prevent abuse; troubleshoot and improve reliability; meet legal duties; and protect Abnio, customers and users.
We do not sell personal information, build cross-customer visitor profiles, or use customer analytics data for third-party advertising.
6. Sharing and service providers
We disclose information only to service providers needed to operate Abnio (such as hosting, email delivery and security infrastructure), under appropriate confidentiality and data-protection obligations; when a customer directs us to; when required by law; or to protect rights, safety and service integrity. We do not permit service providers to use customer analytics data for their own advertising.
7. Retention and deletion
Retention depends on the data category, the customer agreement and the service configuration. We keep account and security records while an account is active and for a limited period afterwards when needed for security, dispute resolution or legal obligations. Analytics data is retained according to the customer’s configured or contracted window. Backups may persist for a limited recovery cycle before being overwritten.
Customers can request export or deletion of their account and site data, subject to security, legal and backup limitations.
8. Security and international processing
We use technical and organizational safeguards including encryption in transit, password hashing, app-native two-factor authentication, server-side sessions, scoped authorization, audit logging and protected credentials. No system is perfectly secure, but we design controls to reduce both likelihood and impact. See our security page for more detail.
Early access currently operates from one primary analytics region, with region-coded infrastructure designed for additive global expansion. Service providers may process limited account, support or delivery metadata from other locations under applicable safeguards. See data residency and regional compliance.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete or receive information; object to or restrict certain processing; withdraw consent where consent is relied upon; and complain to an appropriate authority. We may need to verify your identity before acting. If the request concerns a customer’s website, contact that customer first; we assist customers with verified requests.
You can enable Do Not Track in a supported browser to prevent Abnio’s first-party beacon from recording the visit. Blocking JavaScript also prevents beacon collection, though it does not prevent a website’s normal server logs.
10. Children
Abnio is a business service and is not directed to children. We do not knowingly create accounts for children or intentionally collect their personal information through this website.
11. Changes
We may update this policy as the service or law changes. We will publish the revised date here and provide additional notice when a change materially affects customer rights or processing.
12. Contact
For privacy questions or requests, contact Abnio using the address below. Please do not include sensitive credentials or authentication codes.