Legal
Privacy Policy
Last updated: August 28, 2026
This Privacy Policy explains how Notion Analytics (“we”, “us”, or “our”) collects, uses, discloses, and safeguards your information when you use our website and analytics service (the “Service”). We are committed to protecting your privacy and being transparent about how your data is handled. Please read this policy carefully to understand our practices regarding your information.
1. Information We Collect
We collect information in the following categories to provide and improve the Service:
1.1 Account Information
When you create an account, we collect your name, email address, and a hashed password. If you sign up using Google OAuth, we receive the name and email address associated with your Google account. This information is used to identify you, communicate with you about your account, and provide access to the Service.
1.2 Workspace and Page Metadata
When you connect your Notion workspace through our official OAuth integration, we request read-only access to the metadata of the pages you choose to track. We receive the page title, page URL, and the parent workspace identifier. We do not read, store, or transmit the actual content of your Notion pages.
1.3 Visitor Analytics Data
When a visitor views one of your tracked Notion pages, our lightweight tracking widget records an anonymized page view event. The data we collect includes:
- The URL and identifier of the tracked page
- A cookieless visitor fingerprint derived from your visitor's IP address and user agent. The fingerprint is opaque and the raw IP address is never stored. IPs are truncated (last segment removed) before storage and displayed only in anonymized form
- Approximate geographic location (country-level, derived from IP address)
- Device type, operating system, and browser information (parsed from the user agent)
- Timestamp of the visit and time spent on the page
We do not collect visitor names, email addresses, or any personally identifiable information from page views. Visitor fingerprints cannot be reverse-engineered to identify an individual person.
1.4 Billing Information
When you subscribe to a paid plan, payment processing is handled entirely by Stripe. We never see or store your full credit card number, CVV, or other raw payment details. We retain only the last four digits of your card, the card brand, and the billing email address for receipt purposes.
1.5 Technical and Usage Data
We automatically collect technical information about how you interact with the Service, including your IP address, browser type, device information, the pages of our website you visit, the time and date of each visit, and similar diagnostic data. This information is used for security, abuse prevention, and aggregate analytics.
2. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, and maintain the Service, including tracking and reporting page analytics
- To create and manage your account and authenticate your identity
- To process payments and deliver invoices and receipts via Stripe
- To send you service-related communications such as weekly analytics reports, security alerts, and important product updates
- To respond to your comments, questions, and support requests
- To detect, prevent, and address technical issues, fraud, and abuse
- To improve and develop new features based on aggregate usage patterns
- To comply with our legal obligations and enforce our Terms of Service
3. Cookies and Local Storage
We use cookies and similar browser storage technologies (such as local storage and session storage) to operate and improve the Service. Specifically:
- Essential cookies: required to keep you logged in, remember your theme preference, and keep the Service secure. These cannot be disabled.
- Analytics cookies: used to understand aggregate usage patterns so we can improve the product. We use Google Analytics 4 for this purpose.
The tracking widget embedded on your Notion pages is cookieless. It does not set cookies in your visitors' browsers; visitor identification is derived from a short-lived fingerprint computed at request time.
You can control cookies through your browser settings. Most browsers allow you to refuse cookies or alert you when cookies are being sent. Disabling essential cookies will affect the functionality of the Service.
4. Data Sharing and Sub-Processors
We do not sell, rent, or trade your personal information. We share data only with the trusted third-party service providers we rely on to operate the Service (“sub-processors”). Each sub-processor is bound by contractual obligations to protect your data and process it only on our behalf.
- Supabase: provides our PostgreSQL database, authentication, and file storage. Stores account information, page metadata, and analytics events.
- Notion: receives OAuth requests to connect your workspace and read the metadata of pages you choose to track. We request only read-only access.
- Stripe: handles all payment processing. Receives your billing details when you subscribe to a paid plan.
- Resend: delivers transactional and report emails on our behalf (welcome emails, weekly reports, billing receipts).
- Google Analytics: receives aggregated, pseudonymous usage data from our marketing website.
- Sentry: receives error and performance telemetry so we can diagnose and fix bugs. Personal information is scrubbed before transmission.
We may also disclose information when required by law, court order, or governmental authority, or when we believe in good faith that disclosure is necessary to protect our rights, the safety of any person, or to investigate fraud or security issues.
5. Data Security
We take reasonable administrative, technical, and physical safeguards designed to protect your information. These include:
- Encryption of data in transit using TLS 1.2 or higher for all network connections
- Encryption of data at rest in our database and storage providers
- Row-level security policies enforced at the database layer so users can only access their own data
- Hashed passwords using industry-standard one-way hashing algorithms
- Strict access controls limiting database and infrastructure access to authorized personnel only
- Regular security reviews and prompt patching of identified vulnerabilities
No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Data Retention
We retain your data for as long as your account is active. Analytics events are retained according to your plan: the Free plan keeps 7 days of history, the Starter plan keeps 30 days, and the Pro plan retains unlimited history. When you delete your account, we permanently delete your account information, workspace connections, and associated analytics data within 30 days, except where retention is required by law.
7. Your Rights
7.1 GDPR (European Economic Area, United Kingdom, and Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):
- Access: request a copy of the personal data we hold about you
- Rectification: request correction of inaccurate or incomplete data
- Erasure: request deletion of your personal data (the “right to be forgotten”)
- Restriction: request that we limit processing of your data
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Withdrawal of consent: withdraw consent for any processing based on consent at any time
7.2 CCPA (California)
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the right to know what personal information we collect, request deletion of your personal information, opt out of the sale or sharing of your personal information, and not be discriminated against for exercising your rights. We do not sell personal information.
7.3 Exercising Your Rights
To exercise any of these rights, contact us at support@notionanalytics.app. We will respond to your request within 30 days. If you believe we have not resolved your concern, you have the right to lodge a complaint with your local data protection authority.
8. Children's Privacy
The Service is not directed to children under the age of 13 (or the minimum age required for consent under applicable law). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at support@notionanalytics.app and we will take steps to delete such information.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. Where required, we put in place appropriate safeguards such as Standard Contractual Clauses to ensure your data receives a level of protection consistent with applicable data protection laws.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. For material changes that affect your rights, we will provide a more prominent notice, such as by sending an email or displaying a notification in the Service. We encourage you to review this policy periodically to stay informed about how we protect your information.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: