GDPR and privacy
Last updated 9 September 2026. This page explains how Seean is built for the GDPR and where your responsibilities as a website owner begin.
Who plays which role
For your account data (your email address, sign-in method, plan and invoices) NesDesign LLC is the controller.
For the analytics data of your websites you are the controller and NesDesign LLC is the processor: we process it only to provide Seean and only on your instructions. That relationship is set out in our data processing agreement, which forms part of the terms and needs no separate signature, although we will sign a copy for your records on request.
Data minimisation by default
Seean limits the data used for analytics, but random identifiers and associated activity may still be personal data:
- the tracker uses localStorage and sessionStorage rather than cookies for visitor and session identifiers;
- analytics records do not include a visitor IP field; network services may still process IP addresses;
- no device fingerprinting;
- country estimated from a reported value, browser timezone or language region, without IP geolocation;
- referrers reduced to a hostname, so query strings and paths of the referring page are never kept;
- the visitor ID has no automatic expiry in the tracker and may persist across visits.
Recognised bot user agents and common automation clients are filtered before analytics storage and usage accounting. This basic filtering does not establish that every accepted visit is human.
What may still be processed
Two things deserve care, because they are under your control rather than ours.
Custom events and properties. If you send properties with an event, you decide what is in them. Do not put names, email addresses, order details tied to a person, or anything else that identifies a visitor into an event property.
Revenue attribution. If you post orders to Seean, you choose which identifiers travel with them. Use your own opaque order identifiers rather than customer identifiers.
If you do send personal data through these features, you are the controller of it and you need a legal basis for it. Seean will process it as your processor under the DPA.
Cookies, storage and consent
The tracker reads and writes visitor and session identifiers in browser storage. Cookie and similar-technology rules can apply to this storage even though no cookies are set. Whether consent, an opt-out or another requirement applies depends on the jurisdiction and use. Seean does not claim a universal exemption for analytics.
The tracker stops analytics collection for Do Not Track, Global Privacy Control, or a browser opt-out set with localStorage.seean_ignore = "true". Configure your consent mechanism to control whether the script loads, including applicable opt-out choices. See the ICO guidance on storage and access technologies for the scope of the UK rules.
Your responsibilities as a customer
- Tell your visitors, in your own privacy notice, that you measure traffic with Seean and what that involves.
- Only install the tracker on sites you control and are entitled to measure.
- Keep personal data out of custom events and order payloads.
- Handle requests from your visitors as controller; we will help you answer them.
International transfers
We are a United States company. Our providers may process data internationally. See the DPA for transfer terms and contact hello@seean.io for current processing locations or a specific data-residency requirement.
Data processing terms
Our data processing agreement sets out the subject matter and duration of processing, the categories of data and data subjects, security measures, sub-processors, transfer mechanisms, breach notification, audit rights and deletion. It is incorporated into the terms of service.
Contact
NesDesign LLC · Wyoming, United States · hello@seean.io
