Last updated: 6 August 2026
This agreement applies automatically to every customer who sends visitor data to UsageStory, and forms part of the Terms of Service. No signature is required. A countersigned copy for procurement is available on request through the contact form.
The customer is the data controller for visitor data collected through their projects. UsageStory is the data processor. UsageStory processes that data only on the customer's documented instructions, which the Terms of Service, this agreement, and the project's own settings together constitute. UsageStory does not process visitor data for its own purposes and does not sell it or use it to train models.
Subject matter: providing web analytics and session replay. Duration: for as long as the customer's account remains open, plus the retention and backup periods in section 6.
Data subjects: visitors to the customer's websites and apps, and the customer's own team members who use the dashboard.
Personal data: IP address (truncated when the project enables anonymisation), country, page and referrer URLs, device, operating system, browser, screen size, time on page, a randomly generated visitor and session identifier, session recordings with form input masked by default, and any account identifier or event data the customer chooses to send.
UsageStory does not require special-category data and asks customers not to send it. What reaches UsageStory through identify(), track(), or an unmasked recording is determined by the customer.
The customer gives general authorisation for the sub-processors below. UsageStory will give at least 30 days' notice by email before adding or replacing one, and the customer may object; if the objection cannot be resolved, the customer may terminate and receive a pro-rata refund of any prepaid fees.
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean | Server and database hosting | London, United Kingdom |
| Cloudflare | Encrypted off-site backups | Per bucket jurisdiction |
| Postmark | Account email (password resets) | United States |
Each sub-processor is bound by data protection obligations no less protective than these.
Session recordings are deleted automatically once they pass the project's retention period, 30 days by default. Pageviews and events are kept until the customer deletes the project or closes the account. Deleting a project removes its data from the live database immediately.
Encrypted backups are retained for up to 5 weeks and then overwritten, so deleted data can survive in backups until that cycle completes. On termination, live data is deleted within 30 days and backup copies expire on the same cycle. A written confirmation of deletion is available on request.
UsageStory is in beta and holds no independent security certification such as ISO 27001 or SOC 2. Customers requiring certified processors should factor this in.
Primary storage is in London, United Kingdom. Transfers from the EEA to the United Kingdom rely on the European Commission's adequacy decision for the UK. Where a sub-processor places data outside the UK or EEA, that transfer relies on the Standard Contractual Clauses together with the UK Addendum where relevant.
On reasonable written notice, and no more than once a year unless a regulator requires otherwise, UsageStory will answer reasonable questions about its processing and provide documentation of the measures in section 7.
The customer is responsible for having a lawful basis for collection, for giving visitors the notice their law requires, for obtaining consent where it is required, and for what they choose to send through identify(), track(), and unmasked recordings.
Data protection questions, sub-processor objections, audit requests, and deletion confirmations go through the contact form, choosing the "Data & privacy" topic.