Docs/Privacy
.md

Privacy

What the SDK sends, how visitors are counted, and what you should never send.

What is stored in the browser#

Nothing. No cookies, localStorage, sessionStorage or IndexedDB. The session ID lives in memory only.

What the SDK sends#

The event name, your props, and coarse system info: locale, time zone, OS name and version, browser engine and major version, app version, SDK version, a debug flag, the page path (never the query string; IDs become :id on the server), and the traffic source of the page load (the utm_source parameter, or the referring site’s host, never a full URL). Visits from AI assistants such as ChatGPT, Perplexity or Claude are recognized automatically.

How visitors are counted#

IP addresses and User-Agents are never stored. The server uses them for a moment to derive a country and an anonymous visitor hash, sha256(daily_salt + app + ip + ua), then discards them.

  • The salt changes every day, so visitors can’t be followed from one day to the next.
  • The day is the visitor’s local day: they count once from their midnight to the next.
  • Over 7, 30 or 90 days, a visitor who comes back on another day counts again.

Nothing is stored on the visitor’s device, so this setup typically needs no cookie banner under the GDPR and ePrivacy rules. You stay responsible for what you send: keep props anonymous and Shipabase stays anonymous too. See Props & privacy.