Who this applies to
This policy covers three different groups of people, and treats them differently because their relationship to Thexly is different:
Account holders: people who sign up for a Thexly account to use the product themselves.
Website visitors: people who visit a website that has installed an account holder's Thexly tracking script. These people never interact with Thexly directly and never create an account.
Google account data: if an account holder connects Google Search Console, Thexly accesses a limited set of search-performance data from Google on their behalf, described below.
Legal basis for processing
Under GDPR, we rely on different legal bases depending on the activity: processing an account holder's account, billing, and the core analytics/attribution service relies on contract, since it's necessary to provide the service they signed up for. Website-visitor session data (referrer, browser, approximate location) is processed under our and our customers' legitimate interest in understanding traffic and revenue, balanced against the minimal privacy impact of not using cookies or persistent identifiers. Billing and invoice records are retained under legal obligation (tax law). Where a customer chooses to pass identifying information via the tracking script's identify() function, that rests on the consent or other lawful basis the website owner establishes with their own visitor.
Data from website visitors (the tracking script)
The tracking script does not use cookies and does not collect personally identifiable information. It records: page URLs visited, referrer, browser, operating system, device type, and a session identifier that rotates monthly and cannot be linked back to a real person.
IP addresses. A visitor's IP address is read from the request only to do two things in-memory, and is never written to our database: deriving an approximate location (country/region/city, via our hosting provider's geolocation headers or a local MaxMind lookup), and, for a small number of server-side requests without a client-generated session, computing a one-way salted hash used as a session identifier. The salt rotates monthly, so the same visitor cannot be linked across months from this identifier. The raw IP address itself is discarded once these two operations complete.
If a website owner enables custom events, those events (e.g. "signed up," "clicked pricing") and any properties attached to them are recorded the same way.
If a website owner enables session replay, additional detail is captured for that site: a recording of the visitor's on-page interactions (clicks, scrolling, form-field focus) reconstructed from DOM structure, not a video or screenshot. Website owners are responsible for configuring input masking so sensitive form fields (passwords, payment details) are excluded before enabling this.
The identify() function. If a customer's website calls the tracking script's identify() function after a visitor logs in, whatever identifier or properties that site owner chooses to pass (e.g. a customer ID, plan, or email) are stored so future payments from that person can be matched to their session. This is controlled entirely by the website owner rather than by Thexly. The website owner is responsible for having a lawful basis to pass that data about their own visitor.
Cross-site tracking: Thexly does not track a visitor across different websites or apps, and does not build advertising profiles.
Revenue attribution data
When an account holder connects a payment provider (Stripe, Lemon Squeezy, Polar, Dodo Payments, or Yolfi, or records revenue manually via our API), Thexly reads transaction data using a read-only, restricted API key: payment and subscription status, amount, currency, and the provider's own transaction/customer identifiers. We never receive card numbers or bank credentials, which stay entirely inside the processor's own PCI-compliant systems. Where a processor exposes the payer's email address, we convert it to a one-way hash before storing it, never the plaintext address, and use that hash only to match a payment to the visitor session that produced it. Thexly cannot move money, issue refunds, or change account settings on a connected provider.
Google user data (Search Console)
If a customer connects Google Search Console, Thexly accesses the following on their behalf, using Google's read-only webmasters.readonly scope, the minimum Google's API requires for this feature:
Search query, clicks, impressions, average position, and the page/date each applies to: aggregate performance data, not tied to any individual searcher's identity, which Google does not provide.
How we use it: solely to model which search queries are associated with revenue on the connected site, shown back to that customer in their own dashboard, clearly labeled as a directional estimate rather than exact attribution.
What we don't do with it: we do not use Google user data for advertising or ad-related purposes, we do not sell it, we do not use it to train generalized AI/ML models, and we do not share it with any third party except the infrastructure providers needed to run the feature (see Subprocessors below).
Retention: retained for as long as the integration stays connected; deleted within 30 days after a customer disconnects it or closes their account.
Revocation: a customer can disconnect Search Console at any time from Settings, and can separately revoke Thexly's access from their own Google Account permissions page at myaccount.google.com/permissions.
This section is written to satisfy Google's API Services User Data Policy, including the Limited Use requirements.
Historical data import
During setup, a customer can import historical traffic data by uploading an export from Plausible or Umami, or restoring a previous Thexly backup file. This is a one-time file upload the customer initiates and controls. Thexly does not connect to or pull data from those other services' APIs.
Data from account holders
Creating an account collects your email address and authentication details (handled by our authentication provider, Clerk) and, if you subscribe to a paid plan, billing information handled directly by our payment processor (Stripe). Thexly does not store your card details. We also keep basic product-usage data (e.g. which features you use), and any support or sales communications you send us.
Cookies
The Thexly tracking script, which is what runs on our customers' websites, does not use cookies. Separately, our own dashboard app uses one strictly necessary session cookie (set by Clerk, our authentication provider) to keep you signed in. That cookie is functional, not used for tracking or advertising, and is not shared with the analytics data described above.
Subprocessors
We use data processors for: application hosting, database hosting, authentication, payment processing for your Thexly subscription, and transactional/support email delivery. We don't publish the names of these providers, to protect details of our own infrastructure. Each operates under its own data processing terms with us, and none of them use your data for any purpose beyond providing that specific service to Thexly.
If you connect a payment provider (Stripe, Lemon Squeezy, Polar, Dodo Payments, Yolfi) or Google Search Console, that provider processes data as directed by you, the customer, not by Thexly, and is covered by your own agreement with them, not this list.
We'll notify customers of material changes to how we use data processors, and if you rely on our DPA for your own compliance obligations, you'll get notice per the DPA's subprocessor-change clause.
Where data is stored
Thexly's infrastructure is being migrated to an EU region (West Europe) ahead of this policy going live; this section will name the confirmed hosting location once that move is complete. If any data ends up processed outside the EU/UK/EEA, this section will describe the safeguard used for that transfer (typically Standard Contractual Clauses).
Data retention
Analytics and account data is retained for the duration of an active account, and deleted within 30 days of account closure or cancellation. Billing records are kept for the duration of the subscription plus the period required for tax/accounting records. Support communications are kept for up to 2 years.
Your rights
If you're in the EU/UK/EEA (GDPR) or California (CCPA), you have the right to access, correct, delete, or export your data, object to or restrict certain processing, and lodge a complaint with your local data protection authority. Website visitors who want to exercise these rights should contact the website they visited directly, since Thexly processes that data on the website owner's behalf, not its own. Account holders can contact us directly at the address below. We aim to respond within 30 days.
Security
We use encryption in transit and at rest, and restrict access to personal data to what's needed to operate the service. We don't claim any third-party security certification (e.g. SOC 2) unless it's genuinely obtained. Any such claim will only appear here once true.
Children's privacy
Thexly is not directed at children, and we do not knowingly collect personal data from anyone under 16.
Changes to this policy
We'll update the date at the top of this page when this policy changes, and notify account holders of material changes by email.
Contact
Questions about this policy, or to exercise your data rights, contact support@thexly.com. Thexly is operated by Thexly Limited, based in Limerick, Ireland.