peregrine
LegalDemo

Draft — pending legal review. This document has not been reviewed by a lawyer and is not yet in effect. Bracketed [TBD] items are still open.

Legal

Data Processing Agreement

Effective date: [TBD — set on publication]

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (the “Customer”) and Peregrine (“Peregrine”, “we”). You accept it by accepting the Terms or using Peregrine; there is nothing separate to sign. Where this DPA and the Terms conflict on the processing of personal data, this DPA prevails.

1. Definitions

“Data Protection Law” means the law that applies to the processing of Customer Personal Data, which may include the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and Israel’s Protection of Privacy Law, 5741-1981 and the regulations under it, as amended. “Customer Personal Data” means the personal data described in section 3 that Peregrine processes on your behalf. Terms such as controller, processor, data subject, personal data breach and supervisory authority have the meaning given in the GDPR.

2. Roles

For Customer Personal Data, you are the controller and Peregrine is your processor. Peregrine is a controller only for its own account and billing data about you, which the Privacy Policy covers and this DPA does not.

3. Details of the processing

Subject matter
Providing Peregrine’s analytics and revenue attribution for the websites you register.
Duration
For as long as your subscription is active, and afterwards until deletion under section 9 (30 days after the subscription ends, 7 days after a trial ends without converting, or 7 days after a site was added if no subscription was ever started).
Nature of the processing
Collection through a script on your website and through your payment provider; storage; aggregation into reports; display to you on your dashboard; deletion.
Purpose
To show you how visitors reach your website and which channels led to paid orders, crediting each order to the visitor’s first recorded visit.
Categories of data subjects
(a) Visitors to your websites. (b) Your buyers, as pseudonymous order records linked (where attribution succeeds) to a visitor id.
Categories of personal data

Visitor data, per event: a random visitor id (stored in the visitor’s browser in localStorage and a two-year first-party cookie) and a random session id (sessionStorage and a session cookie); event name; page path; referring host name; UTM source, medium and campaign; country, region and city, derived by our host from the IP address at its edge; device type and browser name, derived from the user-agent; for outbound clicks, the destination host and path; up to 1 KB of custom metadata you choose to send; the time received. Per visitor, the first-seen referrer, UTM tags, landing path and location.

Order data: for each paid order, the order id, amount, currency, creation time, the visitor id carried by the checkout (if any), and a test-mode flag for Lemon Squeezy and Dodo Payments test orders.

Not processed: IP addresses are never stored; neither is the user-agent string itself. No buyer names, email addresses or billing addresses are stored.

Special categories
None are intended. You must not send special-category data, or any data that directly identifies a person, in custom event metadata.
Frequency
Continuous, for as long as the tracker is installed or a provider is connected.

4. Your instructions and obligations

The Terms, this DPA and your configuration of Peregrine (the sites you register, the events you send, the providers you connect) are your complete instructions. You are responsible for:

  • having a lawful basis for the processing, including any consent Data Protection Law or the rules on storing information on a user’s device require for the tracker’s cookie and browser storage;
  • telling your visitors about the processing in your own privacy notice;
  • not sending personal data in custom event metadata; and
  • the accuracy and lawfulness of anything else you send to Peregrine or instruct it to collect.

5. Our obligations

Peregrine will:

  • process Customer Personal Data only on your documented instructions, unless the law requires otherwise (in which case we will tell you first, unless the law forbids it), and tell you if we believe an instruction breaks Data Protection Law;
  • ensure that anyone authorised to process Customer Personal Data is bound by confidentiality — today that is the operator alone;
  • apply the security measures in Annex 1;
  • help you, taking into account the nature of the processing, to respond to data subjects exercising their rights (see section 6);
  • give you the information you reasonably need for a data protection impact assessment or a prior consultation with a supervisory authority;
  • notify you of a personal data breach as set out in section 7; and
  • delete Customer Personal Data at the end of the processing as set out in section 9.

6. Data subject requests

If a data subject contacts us directly about Customer Personal Data, we will pass the request to you and not answer it ourselves, except to tell them we have done so. To help you answer a request, we will, on your instruction, find, provide or delete the events and visitor record for a given visitor id. The visitor id is the value of the peregrine_vid cookie on the visitor’s browser; the tracker holds no other identifier. You can also delete an entire site’s data yourself, at any time, from Settings.

7. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, at the email address on your account. The notice will describe, as far as we then know, what happened, the data and approximate number of data subjects involved, the likely consequences, and what we have done and propose to do. We will add information as it becomes available and will not delay the first notice to complete it.

8. Sub-processors

You give general authorisation for Peregrine to use sub-processors. The current ones are listed in Annex 2. We impose on each one data protection obligations that offer at least the protection this DPA requires, and remain responsible to you for their performance.

Before adding or replacing a sub-processor, we will update Annex 2 on this page and email you at least 14 days in advance. If you object on reasonable data-protection grounds, tell us within that period. If we cannot address the objection, you may terminate your subscription before the change takes effect, and we will refund the unused part of any prepaid period.

The payment providers you connect (Polar, Lemon Squeezy, Dodo Payments) are not our sub-processors. They are your own providers; Peregrine reads orders from them on your instruction.

9. Deletion at the end

Customer Personal Data is deleted 30 days after your subscription ends (cancelled and past its end date, or payment finally failed), 7 days after a trial ends without converting, or 7 days after a site was added if no subscription was ever started. Deleting a site in Settings deletes that site’s data immediately. There is currently no export function to return the data before deletion. [TBD — data export not yet available] Copies in backups are overwritten as the backup window rolls forward [TBD — confirm Neon backup retention].

10. Information and audits

On written request, we will provide the information reasonably necessary to demonstrate compliance with this DPA, including answers to a reasonable security questionnaire. Where Data Protection Law or a supervisory authority requires an audit beyond that, it will be carried out at your cost, on at least 30 days’ notice, no more than once a year, and in a way that does not expose other customers’ data.

11. International transfers

Peregrine is operated from Israel, which the European Commission recognises as providing adequate protection. Our sub-processors store and process data in the United States. For those onward transfers we rely on the EU–US Data Privacy Framework (and its UK extension) where the sub-processor is certified, and otherwise on the Standard Contractual Clauses in the sub-processor’s data processing terms. [TBD — confirm, per sub-processor, DPF certification or SCCs]

To the extent a transfer of Customer Personal Data from you to Peregrine requires them, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA by reference, with section 3 as their Annex I, Annex 1 as their Annex II, and Annex 2 as their list of sub-processors (Clause 9 option 2, with the notice period in section 8). [TBD — choose the governing law and courts for Clauses 17 and 18, and whether the UK Addendum is needed]

12. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms, to the extent Data Protection Law permits.

13. Term

This DPA applies for as long as Peregrine processes Customer Personal Data, and ends automatically once that data has been deleted.

Annex 1 — Security measures

  • Data minimisation at collection: IP addresses and user-agent strings are never stored; referrers are reduced to a host name; field lengths are capped; custom metadata is limited to 1 KB per event.
  • Encryption in transit: HTTPS for all traffic to Peregrine; TLS between the application and the database.
  • Encryption at rest of credentials: payment-provider access tokens and API keys are sealed with AES-256-GCM under a key held only in the production environment. Storage-level encryption of the database is provided by Neon [TBD — confirm Neon encryption at rest].
  • Tenant isolation: every dashboard query is scoped to sites owned by the signed-in account, enforced at a single function all queries depend on, and covered by an automated test against the real database.
  • Inbound deliveries: webhook deliveries are matched to a site by a per-site URL token and verified by signature against that site’s own secret before their content is read; each order is recorded once, so a replayed delivery is not counted twice.
  • Abuse controls: automated clients are filtered by user-agent; per-visitor and per-site rate limits on the collection endpoint.
  • Access: production data and secrets are accessible only to the operator; authentication to Peregrine’s dashboard is provided by Clerk.
  • Backups: [TBD — confirm Neon point-in-time recovery and window].

Annex 2 — Sub-processors

Sub-processorProcessingLocation
VercelHosting and serverless functions for the collection endpoint and dashboard; derives country, region and city from the IP address at its edgeUnited States (edge locations worldwide)
NeonPostgres database storing all Customer Personal DataUnited States (AWS us-east-2, Ohio)
[TBD — email delivery provider]Usage and service emails to you (only if they include Customer Personal Data)[TBD — location]

Contact

Questions about this DPA, and notices under it: support@justperegrine.com.

peregrine
Demo
© 2026
Privacy
hello@justperegrine.com