Privacy Policy
Last updated: not yet published
Who we are
Spectra is run by Rahul Kumar, a sole proprietor in India rather than a company. For anything in this policy you can write to privacy@spectra-trace.com.
Our representatives in the EU and the UK
We are established in India, and on our customers' behalf we record how people in the European Economic Area and the United Kingdom behave on their websites. Article 27 of the GDPR and of the UK GDPR therefore require us to appoint a representative in each, who may be contacted on any matter relating to our processing as an alternative to contacting us.
We have not appointed either representative yet. Until we do, write to privacy@spectra-trace.com and we will answer you directly, and we will name them here as soon as they are in place. We would rather say so than leave the question open.
What this policy covers
There are two different groups of people in this document and the distinction matters.
- Our customers. People and companies who sign up for Spectra. For their account information we are the data controller.
- Visitors to our customers' websites. People whose sessions are recorded because a customer installed Spectra. For those recordings our customer is the controller and we are their processor: we act on their instructions, and questions about why a recording exists are properly answered by the website that made it.
Data we collect as a controller
- Account details: the email address used to sign in, and the workspace name.
- Billing contact and payment status. We never see or store card numbers; those go to our payment provider.
- Support correspondence you send us.
- Operational logs of requests made to our API, used to run and secure the service.
Data we process for customers
Session recordings: what changed on the page, where a visitor clicked and scrolled, page addresses, browser and device characteristics, and errors the page reported. Recordings are grouped by a visitor identifier, which is either an identifier the customer supplies or a random value we generate and store in the visitor's browser.
Behaviour measurements, where the customer has enabled them: one summary for each page a visitor sees, containing counts and timings rather than content. Which elements were clicked and how often, how far the page was scrolled, how long the visit lasted, how fast the page loaded, the page address with any query removed, the name of the referring website, any campaign tags in the address, and a device category. Elements carry the visible text of buttons and links so the customer can recognise them; the contents of form fields are never included, and the masking rules below apply to these labels exactly as they apply to a recording.
We do not sell this data, we do not use it to build profiles across different customers' websites, and we do not use it to train models.
What we never collect at all
We do not collect visitor IP addresses. Not masked, not truncated, not held briefly and discarded: there is nowhere in the system that stores one. Most of this industry records the IP of every visitor to a customer's website and then works out how to defend it. We decided not to take it, so the most common piece of personal data in web analytics is one we cannot lose, cannot be compelled to hand over, and never have to delete.
We also place no advertising or cross-site tracking cookie, and we do not build profiles of people across different customers' websites.
What is masked before it leaves the browser
Masking happens on the visitor's own device, before anything is sent, so the masked content never reaches our servers at all.
- The contents of form fields are masked by default. Passwords are never transmitted.
- Text that matches common patterns for email addresses, card numbers and similar identifiers is redacted.
- Page addresses have the values of parameters that carry credentials removed, such as tokens, one-time codes and API keys.
- A customer can mark any element to be masked, or switch to masking all text.
Masking cannot be perfect. A website that renders a person's data as ordinary page text will have that text recorded, which is why customers choose what to mask and are the controller for what they record.
Do Not Track, Global Privacy Control and consent
Our recorder can be configured to stop recording any visitor whose browser sends Do Not Track or Global Privacy Control, and to wait for a consent platform before recording at all. Whether those are switched on is the website owner's decision, because they are the controller and they know what they told their visitors.
Why we process it
For account data, to perform our contract with the customer and for our legitimate interest in running and securing the service. For recordings, on the instructions of the customer, who is responsible for having a lawful basis for the recording they have chosen to carry out.
We are established in India, so the Digital Personal Data Protection Act 2023 governs our own processing. Where a customer or a visitor is in the European Economic Area or the United Kingdom the GDPR applies as well: for account data we rely on performance of our contract and on our legitimate interest in running and securing the service, and for recordings we act only as a processor on the customer's documented instructions, on the terms set out in our data processing agreement.
Sub-processors
We use a small number of other companies to run the service. We name each of them, and what they do, to any customer who asks: write to privacy@spectra-trace.com and we will send you the current list. We give 30 days' notice by email before a new one starts, and a customer may object.
By category, they are:
- A hosting provider, which holds recordings and runs the service. Your recordings stay in France.
- A provider for sign-in and the account records behind it.
- A provider that delivers the dashboard and this website.
- An email provider, for messages such as sign-in and billing.
- A payments company, which is the merchant of record for your subscription and invoices.
- For workspaces that have the weekly brief, a provider of the model that writes its summary. One request a day for each of those workspaces, carrying counts, dates and a short list of problems whose page paths and control labels have been stripped of anything identifying first. No recording, no address, no identifier and no part of a page is sent.
If we ever keep a copy of recordings with another provider, we will say so here and give notice first.
International transfers
Recordings are stored in France, inside the European Economic Area, and running the service does not move them out of it.
We are based in India and administer the service from there, so operating it means reaching data held in France from outside the EEA. That access relies on the European Commission's Standard Contractual Clauses (Decision 2021/914), which form part of our data processing agreement, alongside the measures described below: recordings are scoped to one workspace, nobody can open one without a time-limited grant that names the individual, and every grant is recorded and visible to the customer.
Our other providers may process data outside the EEA under their own data processing terms, which incorporate those same clauses or rely on an adequacy decision. A list of provider locations is available on request.
Retention
Recordings are kept for the retention window of the plan in force when the recording was made, and are deleted automatically afterwards. Every recording is measured against the window that applied on the day it was made, so buying a longer window does not extend the life of older recordings and moving to a shorter one does not shorten recordings already made under a longer plan.
Account and billing records are kept for as long as the account exists and then for six years, to meet the accounting and tax obligations that apply to us in India.
Your rights
Depending on where you live you may have the right to access, correct, delete or export your data, to object to or restrict processing, and to complain to a supervisory authority.
If you are a visitor to a website that uses Spectra, contact that website first: they decide what is recorded and they can have it deleted. If you cannot reach them, write to us and we will identify the customer and pass the request on.
Customers can delete an individual visitor's recordings, delete a whole site and its recordings, or ask us to close their account. Deletion removes the recordings, everywhere they are listed or searched, and every other copy we hold.
Cookies and browser storage
Our own website and dashboard store your sign-in session in your browser so you stay signed in. We do not use advertising or cross-site tracking cookies.
On a customer's website, our recorder stores a random visitor identifier so that a visitor's pages group into one session. It contains no personal information and is not shared between customers. If a customer has enabled a consent gate, nothing is stored until consent is given.
Security
- All traffic to our service is encrypted in transit.
- Ingest keys are stored only as hashes, so a copy of our database does not yield a working key.
- Access to a workspace is limited by role, and every recording is scoped to the workspace that made it.
- Nobody can open a customer's recordings without a time-limited grant that names the individual, is recorded, and is visible to the customer. Everybody who operates the service is bound by confidentiality.
- The account database is encrypted at rest by our database provider.
- Recordings are held on provider-managed storage in France. They are not separately encrypted by the application, and we would rather say so than imply otherwise.
- If a personal data breach affects a customer's data we tell them without undue delay, and in any event within 72 hours of becoming aware of it.
Children
Spectra is a business product and is not directed at children. We do not knowingly collect data from children. Under Indian law that means anybody under 18. In the European Economic Area and the United Kingdom the age at which a child can consent for themselves to an online service is between 13 and 16 depending on the country. A customer who records a site aimed at children is the controller for those recordings and is responsible for the consent they require.
Changes to this policy
We will post any change here and update the date at the top. If a change materially affects how we handle personal data we will tell customers by email before it takes effect.
Contact and complaints
Write to privacy@spectra-trace.com. If you are not satisfied you may complain to the Data Protection Board of India. If you are in the European Economic Area or the United Kingdom you may instead complain to the supervisory authority where you live, where you work, or where the matter arose; in the United Kingdom that is the Information Commissioner's Office.