Jolt's privacy policy

Last updated on July 20, 2025

At Jolt, your privacy — and that of your visitors — is our top priority. Our goal is simple: collect as little personal information as possible and give you full transparency over what’s stored, how it’s used, and who (if anyone) it's shared with.

This Privacy Policy explains what data we collect, how we process it, and your rights.

What We Don’t Do

  • We don’t store personal data from your visitors by default.
  • We don’t use cookies for tracking.
  • We don’t share visitor data with third parties.
  • We don’t sell or monetize any data.

What We Collect About Your Visitors

Jolt is built to provide privacy-friendly analytics. Here's exactly what gets stored in our database:

  • 🔒 Unique Hash — generated using a salted hash function: hash(domain, ip, userAgent, dailySalt). The salt changes daily per domain. This allows us to count daily uniques without cookies and without storing IP addresses.
  • 🏳️ Country — we do not store or look up IP addresses.
  • 🖥️ User Agent — only the browser, OS, and device type are extracted. We do not store the full user agent string.
  • 🔗 Referrer — if available, the referring website is recorded.
  • 🏷️ UTM Parameters — we store any UTM tags (source, medium, campaign, etc.) present in URLs.
  • 👀 Page Views — standard page view tracking is logged.

No personal information is stored by default.

Why This Approach?

  • It’s GDPR-compliant by design: no identifiers, no cookies, no fingerprinting.
  • Daily hash rotation ensures no historical visitor can be reverse-engineered — even by us.

If you’d like technical documentation on how our hashing and salting work, we’re happy to share it. Just reach out.

What We Collect About You (Our Clients)

To operate the Jolt platform, we only collect a small amount of client data:

  • Email address — required to create an account and send essential service updates
  • Billing details — stored and processed via our payment provider, LemonSqueezy
  • Transactional emails — sent through Resend, a secure and privacy-respecting email provider

We never send marketing emails or share your contact data with third parties for advertising purposes.

Cookies

We only use one essential, first-party session cookie — it keeps you logged into your account. It contains no tracking or personal data. This cookie is only used for authenticated user sessions and is not accessible by third parties. You can delete it at any time via your browser settings.

Hosting & Data Security

All data is securely hosted in the European Union using privacy-conscious providers: Hetzner as backend infrastructure and ClickHouse and PostgreSQL as databases. Our systems follow best practices in encryption, access control, and audit logging.

Your Rights

Depending on your location and local regulations, you may have the right to:

  • Access, correct, or delete your personal data
  • Object to data processing
  • Request data portability

Please contact us if you'd like to exercise any of these rights.

❓ Questions

If you have any questions about privacy or data processing, reach out anytime at email: support@usejolt.io