Last updated 23 September 2026
Privacy policy
What we collect, why we collect it, who processes it, how long we keep it and how to use your rights.
Who we are
Realanalytics (“we”, “us”) provides reporting software that connects ad spend to leads, bookings, customers and revenue. This policy explains what personal data we handle, why, and your choices.
Questions about this policy: hello@realanalytics.dev.
What this policy covers
This policy covers three situations:
- You visit this website.
- You have an account or someone invites you to a project.
- A business uses Realanalytics to measure its advertising. If you visited that business’s website or became its lead, the business decides how your data is used, and we process it for them.
When you visit this website
This website does not run analytics unless you agree to it, and it does not currently ask for that agreement. So we do not collect analytics about your visit. We load no advertising scripts, embeds or third-party trackers.
Each page checks whether you are signed in. To prevent abuse, our sign-in service can record the IP address and page path of these requests, to limit how many it accepts. Our hosting provider also processes technical data, such as your IP address and browser details, to deliver the site and keep it secure.
If you email us, we keep the message and your contact details to reply.
When you create an account
You sign in with Google or GitHub. We ask them only for your basic profile and email address. We store:
- your name, email address, profile image and whether your email is verified;
- the sign-in details your provider returns, including account IDs and access tokens;
- session records, including the IP address and browser details of each session;
- your plan, number of seats and, for paid plans, your Stripe customer and subscription IDs;
- your projects, their settings, the team members you add and the email addresses of people you invite.
- access tokens you create for the command-line tool.
We do not send marketing email. Invitations are links that you share yourself.
Stripe processes paid plans. Stripe receives your email address and handles your card details; we never see or store your full card number.
Data we process for our customers
Our customers are businesses and the agencies that work for them. When a customer adds Realanalytics to a website, or connects its CRM, payment or ad accounts, we process data about that website’s visitors and leads on the customer’s behalf. The customer is responsible for telling you how it uses your data and for asking for any consent needed. If you have a question about this data, contact the business whose website you visited.
Website activity
Events such as page views and form submissions, with random identifiers for the browser and visit, the page address (its path and campaign tags, without other query details), the referring page, and the consent choices recorded at the time. We add an approximate location (country, region and city) based on the request. Our browser library drops values that look like email addresses, phone numbers, card numbers or passwords.
Ad data, only when ad data is allowed
Advertising click identifiers (for example from Meta or Google), and the IP address and browser details needed to send a conversion to an ad platform. These are collected only when the consent settings on the customer’s website allow ad data.
Conversions
When a lead qualifies, books a call or buys, the customer’s own systems (such as Attio or Stripe) tell us. When ad data is allowed, this can include the lead’s email address, phone number and name. We store these as received. If the customer switches on sending to Meta or Google, we hash the email address, phone number and name before we send them. The IP address, browser details and click identifiers are sent as received, because the ad platform needs them to match the conversion.
Ad account and CRM data
Campaign, ad set and ad names, spend and platform results from Meta Ads or Google Ads, lead stages and values from Attio, and payment and refund records from Stripe.
Our legal reasons
Where data protection law applies, including the UK GDPR and the EU GDPR, we rely on these reasons:
- Contract: to create and run your account and provide the service.
- Legitimate interests: to keep the service secure, prevent abuse, fix problems and reply to messages.
- Legal obligation: to keep billing and tax records.
For data we process for customers, we act on the customer’s instructions, and the customer chooses the legal reason.
International transfers
Some providers process data outside the UK and the European Economic Area, including in the United States. Their terms include safeguards for international transfers, such as standard contractual clauses.
How long we keep data
- Accounts: while your account exists. To delete your account, email hello@realanalytics.dev.
- Sign-in sessions: 7 days after last use. Invitation links expire after 7 days.
- Website events in our reporting warehouse: up to 365 days.
- Events that failed to process: up to 30 days, so we can retry them.
- Project data (conversions, visits, spend, reports and connections): while the project exists.
When a project owner deletes a project, access and data collection stop at once, and we delete the project’s data from our database in stages. Website events in the reporting warehouse are not removed at the same time. They expire after 365 days, or the owner can ask us to remove them sooner. Data already sent to an ad platform is controlled by that platform.
We keep billing records for as long as tax law requires.
How we protect data
We protect data with measures that include:
- encrypted connections (HTTPS) for all sites and APIs;
- AES-256-GCM encryption for the credentials of connected ad and CRM accounts;
- hashed storage of deploy keys, conversion keys and invitation links;
- signature checks on incoming webhooks;
- rate limits on sign-in, event collection and conversion requests;
- separate test and live traffic: test conversions are never sent to ad platforms.
No system is perfectly secure. If a breach affects your data, we will tell you as the law requires.
Your rights
Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or move it to another service. Email hello@realanalytics.dev. We will reply within one month.
If your data came to us through one of our customers, we will pass your request to that customer, or help it respond.
You can also complain to your data protection authority, such as the Information Commissioner’s Office in the UK.
The service is for businesses. It is not for anyone under 18, and we do not knowingly collect children’s data.
Changes to this policy
When we change this policy, we update the date at the top. If a change is significant, we will also tell account holders before it takes effect. See also our terms.