Trust & Compliance

Privacy compliance, by design

SnipForm was built cookieless from the first line of code. This page explains exactly how visitors are counted, where data lives, and how that maps to GDPR, POPIA, and the other major privacy laws - so you can answer your own compliance questions with specifics, not slogans.

Zero
Cookies & storage

Nothing is stored on your visitors' devices. No cookies, no localStorage, no sessionStorage - verifiable in the tracker source.

24h
Identifier lifetime

Visitors are counted with a salted hash that rotates every 24 hours and is scoped to your site. Linking a visitor across days, or across sites, is cryptographically impossible.

No IPs
Stored anywhere

The visitor's IP is used transiently to derive the session hash and locate the request, then discarded. Analytics records store no IP at all; form spam checks keep only a one-way hash.

EU
Data residency

All primary infrastructure runs in the European Union (Google Cloud europe-west1, Belgium). Analytics data doesn't leave the EU by default.

How Signals counts a visitor

When a page loads, the tracker sends the request to our EU servers. There, a session identifier is derived by hashing the request's characteristics with a secret salt that is unique to your site and rotates every 24 hours. The raw inputs, including the visitor's IP address, are discarded immediately - only the unrecoverable hash is kept, and it expires with the day.

That gives you accurate same-day sessions with nothing stored on the visitor's device, no IP addresses on analytics records, and no way to follow a person across days or across websites. It is the same architecture used by the leading privacy-first analytics tools, and it is verifiable: the tracker script is unminified on our CDN, and the behaviour described on this page is how the product is built.

Where you stand, law by law

For visitor data collected on your site, you are the controller (POPIA calls this the responsible party) and SnipForm is your processor (POPIA: operator). Here is what the design gives you under each regime.

GDPR

European Union
  • Data minimisation is structural, not a setting: analytics records contain no cookies, no IP addresses, no names, no emails.
  • For visitor analytics you act as the data controller and SnipForm processes on your instructions. Most customers rely on legitimate interest for cookieless, non-identifying measurement.
  • All primary processing happens inside the EU (Google Cloud europe-west1, Belgium), so there is no international transfer to explain for analytics data.
  • Erasure and access are supported at every level: submission, form, contact, property, and full account deletion - in the dashboard and via API.

ePrivacy & cookie banners

EU cookie rules
  • The consent rules for cookies apply to information stored on or read from a visitor's device. Signals stores nothing on the device, so its default configuration is designed to run without a cookie banner.
  • There is no cross-site tracking and no advertising use of visitor data - the measurement-only posture that EU regulators' analytics exemptions are built around.
  • Whether any banner is needed remains your call as the site owner: it depends on your jurisdiction and on everything else running on your site.

POPIA

South Africa
  • POPIA holds you, the responsible party, accountable for the operators you use. SnipForm acts as your operator: we process visitor data only with your authorisation, treat it as confidential, and notify you of any suspected unauthorised access.
  • Cross-border transfers (section 72): SnipForm processes data in the EU under GDPR-level protection - a legal regime that upholds principles substantially similar to POPIA's conditions for lawful processing.
  • POPIA has no cookie-banner regime, but online identifiers count as personal information. Signals' no-cookie, no-stored-IP design keeps your analytics footprint minimal from the start.
  • Direct marketing under section 69 (consent or existing-customer basis for electronic marketing) remains your responsibility as the responsible party.

UK GDPR & PECR

United Kingdom
  • SnipForm is operated by Silver Apple Studios LTD, a company registered in England, with EU hosting - clean under UK adequacy in both directions.
  • The GDPR and cookie-banner positions above apply identically under UK GDPR and PECR.

CCPA / CPRA & US state laws

United States
  • SnipForm does not sell personal information and does not share it for cross-context behavioural advertising - there is nothing for a visitor to opt out of.
  • We operate as your service provider under CCPA/CPRA and the comprehensive privacy laws now in effect across 19 states. Conversion uploads to ad platforms happen only on your explicit instruction.

PIPEDA · LGPD · Swiss FADP

Canada · Brazil · Switzerland
  • The same posture carries: SnipForm processes as your provider, stores data in the EU under GDPR-level safeguards, and supports access and deletion rights end to end.

Two kinds of data, one owner: you

Anonymous analytics is the default: sessions and events with no cookies, no stored IPs, and no identity. It stays anonymous unless you decide otherwise.

Identified data exists only where your visitors hand it over or you connect it: form submissions, and contacts you identify through the API. That data is personal data, you are its controller, and every record of it can be deleted - individually or in cascade.

Deletion level What happens
Submission Delete any individual form submission from the dashboard.
Contact Delete a contact in the dashboard or via the API - every identifying field (email, name, phone, external id, metadata) is destroyed and related event records are scrubbed; sessions keep only an anonymous reference.
Form Deleting a form removes every submission, request log, and related event.
Property Deleting a property removes all of its sessions, events, forms, and submissions.
Account Deleting your account cascades through every property, with a full audit of what will be removed shown before you confirm.

Data is retained for the life of your account and removed by these deletion tools - when you delete a property or your account, its data goes with it.

Where your data lives

Primary storage and processing is EU-resident. These are the sub-processors involved in running SnipForm and what each one sees.

Provider Role Location Data involved
Google Cloud Platform Hosting & storage EU (europe-west1, Belgium) All application data
Elastic Cloud Analytics storage EU (GCP europe-west1) Session & event data
Cloudflare Network, CDN & geolocation Global edge Request routing; supplies geo lookups at the edge
Stripe Payments EU / US Billing details (card data never touches SnipForm)
Zoho ZeptoMail Transactional email EU Notification emails
Sentry Error monitoring EU (Germany) Diagnostic data
Anthropic AI report insights (paid tiers) US Aggregate metrics only - never visitor-level data
Slack, Zapier & your webhooks Optional automations As configured Only the data you choose to route there

The fine print, plainly

This page describes how SnipForm is engineered - it isn't legal advice, and your obligations as a controller depend on how you use the platform and where your visitors are. For our formal terms see the Privacy Notice and Terms. Need a data processing agreement or a security questionnaire completed? Get in touch - we answer these directly.