Visitor Privacy Notice
Effective Date: August 5, 2026
You are probably reading this because you visited a public infrapage dashboard — a page showing someone's project metrics, either at infra.page/… or on a domain they connected themselves. This notice explains what is processed when you look at one.
It is written for visitors. If you have an infrapage account, the document you want is the Privacy Policy.
Who Is Responsible for What
Two different things happen when you open a public page, and they have different controllers. Stating this plainly matters, because it determines who you go to about your rights.
| Controller | What it covers | |
|---|---|---|
| The page and its content — which metrics are shown, the text, the links, any logo | The page owner (our customer) | They chose to publish it. We host it on their instructions. |
| Our own measurement of the visit — page views, referrer, country | infrapage (us) | We measure how our own product is used, on every page we serve. |
So for anything about the page's content, contact its owner. For anything about our analytics, contact us — details at the bottom.
What Is Processed When You Open a Page
Our analytics
We run Umami, self-hosted on our own infrastructure, on every page we serve. It records:
- The page you viewed and the referring URL
- Your approximate country and language
- Browser, operating system and screen size
- A visit counter
It is cookieless. It stores nothing on your device and keeps no persistent identifier: a visit is counted via a hash of your IP address, user agent and a salt that rotates daily, so the same person is not recognisable from one day to the next, and never across unrelated sites. Your raw IP address is not stored.
Legal basis: Article 6(1)(f) GDPR — our legitimate interest in knowing how our own service is used. Because nothing is stored on or read from your device, § 25 TDDDG does not apply and no consent banner is required.
Content delivery
Pages served on a connected custom domain are delivered through bunny.net, a content delivery network. To deliver the page it processes connection data including your IP address. bunny.net operates edge locations worldwide, so this specific processing may take place outside the EU — see International Transfers below.
Server logs
Our servers keep short-lived request logs — path, timestamp, response code — for operations and security. Legal basis: Article 6(1)(f) GDPR.
Feedback widget
Where it is enabled, a feedback button supplied by SeggWat may appear. It loads a script from seggwat.com, and it only processes anything if you choose to open it and submit something — the message you write, the page URL, and, if you attach one, a screenshot of the page you took deliberately. Simply ignoring the button leaves nothing to process.
What Is Not Processed
- ❌ No cookies are set on a public page. You only ever receive a cookie from us after signing in to an account.
- The only thing kept on your device is a light/dark theme preference, and only if you change the theme yourself. It is a display setting, not an identifier, and it is never sent to us. Details in the Cookie Policy.
- ❌ No advertising, no ad networks, no third-party marketing pixels, no session recording.
- ❌ No cross-site tracking. There is no identifier that could link your visit here to a visit anywhere else.
- ❌ No profiling and no automated decision-making in the sense of Article 22 GDPR.
- ❌ We do not sell your data. To anyone, ever.
Retention
| Data | Kept for |
|---|---|
| Analytics records (no raw IP, no identifier) | Aggregated statistics, retained indefinitely; nothing in them identifies you |
| Server logs | Up to 90 days |
| Feedback you deliberately submit | Until you or we delete it |
| CDN connection logs | Per bunny.net's own retention, which is short |
International Transfers
Our servers, database and analytics are in Germany. Transactional email is delivered from France.
The exception is content delivery: bunny.net has edge locations worldwide, so if you load a page on a connected custom domain, your connection may be handled outside the EU. This affects connection data for that page view only. Appropriate safeguards — Standard Contractual Clauses — are in place.
Your Rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and — because we rely on legitimate interests — the right to object (Art. 21).
Where to go:
- About the page's content — contact the page owner. They decide what it says.
- About our analytics, logs or this notice — contact us below.
In practice our analytics holds no identifier for you, so under Article 11 GDPR we cannot single out "your" records and are not required to collect more data in order to try. What we can do is explain exactly what is held and stop processing on request.
infrapage Data Protection
Hauke Jung
Hauptstr. 41
79199 Kirchzarten, Germany
Email: info@infra.page
You may also lodge a complaint with your supervisory authority. Ours is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI): baden-wuerttemberg.datenschutz.de.
For Page Owners
If you publish an infrapage dashboard, particularly on your own domain, link this notice from your own privacy page. It is written to be linked directly, and it covers the analytics we run on pages we serve for you — which is our processing under our own legal basis, not something you need a basis for.
Children
Public dashboards are not directed at children, and we collect no account, profile or contact detail from visitors of any age.
Changes
We may update this notice as the service changes. Material changes are posted here with a new effective date.
© 2026 Hauke Jung. All rights reserved.