Privacy Policy
Last updated: 2026-07-27
Vinktar provides product analytics and error tracking. This policy covers two very different kinds of data, and we play a different role for each:
- Your account data — the information you give us to run your account (name, email, workspace details, billing status). For this data we are the controller.
- Your event data — the analytics events and error reports your applications send us about your own users. For this data we are a processor acting on your instructions; you are the controller.
Account data we collect
- Email address and name, used for sign-in, verification codes and service emails.
- If you sign in with Google: your Google account email and name. We never see your Google password.
- Workspace and project names, membership and roles.
- Billing state. Payments are handled by Stripe; we never see or store card numbers.
Event data we process on your behalf
- Events and error reports your applications send to our ingest API, including any identifiers and properties you choose to include.
- We never store raw IP addresses of your end users. IPs on the ingest path are reduced to a non-reversible keyed hash before storage; coarse geolocation comes from edge headers, not from stored IPs. Where an event or error arrives with no identifier at all — no user id and no device id — that hash is used as a last-resort grouping key, so those records count as a cohort rather than as one undifferentiated blob. It is never used to identify a person, and never reveals the address it came from.
- A scrubber masks common credential-shaped fields (passwords, tokens, secrets) in error payloads before they are stored.
- Event data is retained for your plan's history window and then deleted by a daily trimming job. Deleting a project or workspace propagates deletion to the event warehouse.
Cookies
The application uses a single first-party, httpOnly session cookie for sign-in. The marketing site sets no analytics or advertising cookies from third parties.
Where data lives
Our infrastructure runs in the European Union. The services we use to run Vinktar are listed on the subprocessors page.
Your rights
You can access, correct or delete your account data at any time from the product, or by contacting us. Deleting a workspace deletes its event data. If you are an end user of one of our customers' applications, contact that customer — they control the data and we act on their instructions.
Contact
Privacy questions: ops@vinktar.com.