Privacy Policy
Last updated: August 27, 2026
GeoVisit is a web analytics service that provides aggregated, approximate information about the countries and cities from which visits to a website or link originate, together with navigation and campaign metrics.
1. Data we process
Depending on how the service is used, we may process customer account and billing data as well as technical visit data: page viewed, date and time, referrer, UTM parameters, device type, browser, operating system, country, region and approximate city. When the customer uses the WooCommerce integration, aggregated commerce events such as product view, add to cart, checkout start, purchase, amount, currency and technical product or order identifiers may also be recorded. GeoVisit does not need the buyer's name, email address, postal address or payment details for these metrics.
If you choose Google sign-in, Google provides GeoVisit with the unique account identifier (sub), name, email address and confirmation that the email has been verified. GeoVisit requests only the OpenID Connect scopes needed for sign-in (openid, profile and email), does not request access to Google Drive, Contacts or Gmail, and does not retain the Google access token after the sign-in operation.
2. IP address and identifiers
The visitor's IP address is used temporarily to obtain an approximate location and generate an irreversible daily identifier used to estimate unique visitors. The full IP address is not stored in each visit record. GeoVisit may retain an irreversible HMAC of the IP, protected with a private service key, so that a project owner can exclude internal traffic and, when requested, remove earlier records attributable to the same connection. This value is not displayed as an IP address and does not allow the original address to be recovered without the service key. If device exclusion is enabled, GeoVisit also stores an irreversible HMAC of a technical browser/device signature solely to avoid counting the owner's own traffic; it is not used for cross-project tracking.
3. Approximate geolocation
GeoVisit does not request access to GPS or precise browser location. Location is derived from the IP address and may be inaccurate. It must not be interpreted as a physical address or used to locate a specific person.
4. Cookies and local storage
The GeoVisit tracker is designed to work without tracking cookies and without localStorage used to identify visitors. The WordPress/WooCommerce integration does not itself add GeoVisit identification cookies; WooCommerce or the customer's website may use their own cookies or sessions, which remain the responsibility of the site owner.
If an account user explicitly enables system notifications, GeoVisit stores the Web Push subscription endpoint and the cryptographic keys supplied by the browser for the sole purpose of delivering those notifications. The permission can be withdrawn from GeoVisit or from the browser/device settings, and the subscription is removed when it is disabled in GeoVisit.
5. Purposes and legal basis
Account data is processed to provide the service, manage registration, security, support, billing and communications required by the contractual relationship. When a customer installs the tracker on their own website, that customer is responsible for determining the appropriate legal basis for visitor analytics and for providing any information required by applicable law.
6. Role of GeoVisit regarding visits
In general, the customer decides which website or link is analysed and for what purpose, while GeoVisit provides the technical measurement infrastructure. Where legally required, this relationship should be formalised through the applicable terms or data-processing agreement.
7. Technical providers
Hosting, email and payment providers may be involved in delivering the service. For approximate IP geolocation, the current version may query ipwho.is / ipwhois.io when an IP is not yet present in GeoVisit's geographic cache. GeoVisit does not store the full IP address in the individual visit record. Providers and their terms should be reviewed whenever the service infrastructure changes.
8. Retention
Visits are retained for the period configured by the service administrator and may be deleted automatically by the included cleanup task. Account and billing data is retained for as long as necessary to provide the service and comply with applicable legal obligations. Operational email delivery diagnostics may record the recipient address, subject, delivery method, server status and error detail for troubleshooting and are automatically deleted after 90 days.
9. Rights
Where applicable, individuals may request access, rectification, deletion, objection, restriction or portability of their data. Requests concerning a GeoVisit account may be sent to contacto@onebizness.com. If a request concerns data collected by a customer website, it may also be necessary to contact that website owner.
10. Security
Technical and organisational measures are applied to limit unauthorised access, minimise stored information and protect sessions and credentials. No Internet-connected system can guarantee zero risk.
11. Changes to this policy
This policy may be updated when features, providers or legal requirements change. The date of the current version is shown at the top of this page.