← Back to ARISA Visitor Visual

Privacy Policy

Last updated 1 August 2026

ARISA Visitor Visual ("we", "us") provides website analytics rendered as a live 3D city. This policy covers two different kinds of data: your own account data as a customer, and the visitor data your tracker script collects about people browsing your website.

1. Account data

When you sign up we store your email address, a hashed password (we never store your plain-text password), your referral code and who referred you (if anyone), and your billing relationship with Stripe (see §4). We never see or store your card details — Stripe Checkout and the Stripe Customer Portal handle those directly.

2. Visitor data (collected on your behalf, about your site's visitors)

Our tracker script (one line added to your site) assigns each visitor an anonymous identifier and records: pages viewed, referrer, approximate location derived from IP address (country and city), internet provider/organisation, browser/device/viewport/language, and, only if you add the optional purchase-tracking call yourself, purchase events. We do not collect names, emails, or any other directly-identifying information about your visitors unless your own site's chat feature is used and a visitor types something identifying into it.

You control two things that affect this: IP anonymization (an on/off toggle per site — when on, we keep the country but stop deriving city/ISP/organisation from new visits) and right to erasure (a one-click action to permanently delete one visitor's data). Data is also automatically purged after your plan's retention window (14/90/365 days depending on plan).

3. Cookies

Our own dashboard sets one cookie (vv_session) to keep you logged in. The tracker script sets one first-party cookie (vv_id) on your domain, not ours, purely to recognise a returning visitor to your site — it carries no personal information by itself.

4. Third parties we use

Stripe for payment processing (they handle your card, we never do). SendGrid for transactional email (verification, password reset, invoices, support replies, digests). ip-api.com to derive a visitor's approximate location from their IP address. Anthropic to generate the AI-written Mayor's Report and weekly digest text (Pro plan) — only aggregate stats are sent, never raw visitor identities. Slack, only if you configure your own webhook URL, to receive real-time alerts you opted into.

5. Your rights

If you're in the UK/EEA, you have the usual GDPR rights over your own account data (access, correction, deletion, portability) — email us to exercise any of them. For data about your site's visitors, you (the site owner) are the data controller for that data; we're your processor, and the in-dashboard anonymization/erasure tools are how you exercise those rights on your visitors' behalf.

6. Contact

Questions about this policy: visuals@arisa-receptionist.co.uk.