Privacy policy

Last updated

This policy explains what personal data Obelism collects through Obelism Improve (https://improve.obelism.studio), why, and what you can do about it. It covers two groups: people who use the Improve website and dashboard, and the visitors of websites that use Improve.

Who is responsible

Obelism is the controller for data about Improve's own users: people who sign up for the beta, create an account or use the dashboard. For the visitors of our customers' websites, the customer is the controller and Obelism processes that data on the customer's behalf.

Data we collect about Improve users

  • Beta sign-up: your name, email address and company, so we can review the request and invite you.
  • Account: your email address, first and last name, and a password stored only as an Argon2 hash. We also store whether your email address is verified, and short-lived verification codes.
  • Sessions: a session record linked to your account that expires after 30 days.
  • Organization membership: which organizations you belong to and your role in each.
  • Email: we send account, invitation and sign-up emails through Cloudflare Email Service.

Data we process about visitors of our customers

When a website uses the Improve SDK, we receive an anonymous visitor id (a random token, not derived from any personal data), which test or flag variant the visitor saw, coarse device categories (device type, browser family, operating system family, a screen size bucket and pointer type), the country derived from the hosting edge, and the events the website chooses to send.

We never read or store the visitor's IP address, the raw user-agent string or the exact screen resolution. The documentation page "Privacy & GDPR" describes these data flows in technical detail for our customers.

Cookies on improve.obelism.studio

We do not use advertising or third-party tracking cookies on this site.

  • auth_session: keeps you signed in to the dashboard. Strictly necessary, HttpOnly, up to 30 days.
  • has_session: a non-sensitive marker telling the page you are probably signed in. Same lifetime as the session.
  • organization and environment: remember which organization and environment you are editing in the dashboard.
  • tz: your time zone, so dashboard charts use your local time.
  • visitorId and homepage-hero-test: we run an A/B test on our own homepage with our own SDK. These keep you on the same variant for 7 days.

Why we process it

  • To provide the service you signed up for (performance of a contract): accounts, sessions, organizations, sending emails.
  • To review beta sign-ups and keep the service secure (legitimate interest): rate limiting, abuse prevention.
  • To process visitor data on behalf of our customers, under their instructions.

Where it is stored and who processes it

We do not sell personal data and do not share it with anyone else, except when the law requires it.

  • Cloudflare runs the application (Workers), its caches, queues and email sending.
  • PlanetScale hosts the PostgreSQL database in Frankfurt, Germany (AWS eu-central-1), so the data is stored in the EU.

How long we keep it

Account data is kept while your account exists. Sessions and verification codes expire automatically. Analytics and exposure data have no automatic retention limit today: they are kept until the customer deletes them or asks us to. If your contract commits to a retention period, contact us and we will enforce it.

Your rights

You can ask to see, correct, export or delete your personal data, object to its processing, or withdraw consent. Email development@obelism.studio. If you are a visitor of a website that uses Improve, contact that website first: it decides what happens with your data, and we help it carry out your request. You can also complain to the data protection authority in your country.

Changes to this policy

When this policy changes we update the date at the top of the page.