peregrine
LegalDemo

Draft — pending legal review. This document has not been reviewed by a lawyer and is not yet in effect. Bracketed [TBD] items are still open.

Legal

Privacy Policy

Effective date: [TBD — set on publication]

Peregrine is web analytics at justperegrine.com ([TBD — postal address]). This policy explains what personal data Peregrine handles, why, who else touches it, and what you can ask us to do with it.

1. Two roles

Peregrine handles personal data in two different capacities, and the difference matters:

  • As controller — for data about our own customers (the people who hold a Peregrine account) and about visitors to justperegrine.com. We decide why and how that data is used, and this policy is the notice for it.
  • As processor — for data the Peregrine tracker collects on our customers’ websites, and for sales data read from our customers’ payment providers. There, each customer is the controller and we act on their instructions under the Data Processing Agreement. Section 6 describes that data so anyone can see what is collected.

Visited a website that uses Peregrine? That website’s owner decides what is collected about you and is the one to ask for access or deletion. Their privacy notice should say how. We will help them answer you. If you cannot reach them, write to support@justperegrine.com and we will pass your request on.

2. The short version

  • We never store IP addresses. Not in the analytics, not in the rate limiter. Our host uses the address at the edge to derive a country, region and city, and only those reach our code.
  • The tracker identifies a browser by a random id it generates, not by who the person is.
  • Sales data is stored without buyer names or email addresses.
  • We do not sell personal data and do not use it for advertising.

3. Data about our customers

If you have a Peregrine account, we handle:

  • Account data: your email address and an internal account id. Sign-in is provided by Clerk, which holds your sign-in credentials (for example a password, or the link to a Google account you sign in with). We never see your password.
  • Subscription data: your plan, its status, when the current period ends, and the Polar subscription id. Polar, as Merchant of Record, holds your card, billing address, and invoices. We never see your card number. When you subscribe, we send Polar your email address and account id so the subscription is attached to you.
  • Site settings: the domains you register and, if you connect a payment provider, the credential you paste (encrypted — see section 11) and the store you choose.
  • Correspondence: anything you send to support.
  • Waitlist: if you join the waitlist before an account is open to you, your email address, held by Clerk, so we can invite you.

4. Visitors to justperegrine.com

We measure our own public pages (the home page, the demo, the waitlist and these legal pages) with Peregrine’s own tracker, the same one our customers install. It records the data described in section 6. The dashboard and settings pages are not measured.

If you subscribe after visiting, the random visitor id from our tracker is attached to your Polar checkout, so we can see which channel brought you — the same thing Peregrine does for its customers.

5. Cookies and browser storage on justperegrine.com

NameSet byPurposeLasts
peregrine_vid (cookie and localStorage)Peregrine, first partyA random visitor id, so a return visit is recognised as the same browser and a purchase can be credited to the first visit. Mirrored to a cookie because a server cannot read localStorage.Cookie: 2 years. localStorage: until cleared.
peregrine_sid (cookie and sessionStorage)Peregrine, first partyA random session id, to group one visit’s pageviews.Until the browser session ends.
__session, __client_uat, __client and suffixed variantsClerk, for usSign-in state. Needed for signing in and for keeping you signed in; set on every page because the sign-in library loads site-wide.[TBD — confirm exact names and lifetimes against the production Clerk instance]

We do not use advertising or third-party analytics cookies. Fonts are served from our own domain, so loading a page does not contact Google. [TBD — decide whether EU/UK visitors must consent before peregrine_vid is set on justperegrine.com; no consent banner is shown today]

6. What the tracker records on a customer’s website

For each event — a pageview, an outbound link click, or a custom event — Peregrine stores:

  • the visitor id and session id described in section 5 (random values generated in the browser);
  • the event name and the page path (not the query string);
  • the referring site’s host name (for example reddit.com), not the full referring URL;
  • the UTM source, medium and campaign tags, if the page address carried them;
  • country, region and city, which our host (Vercel) derives from the IP address at its edge and passes to us as headers;
  • a device type (desktop, mobile or tablet) and browser name, derived from the user-agent string and the window width;
  • for outbound clicks, the destination host and path; for custom events, up to 1 KB of metadata the website sends — which customers must not use for personal data;
  • the time the event was received, set by our server.

For each visitor, Peregrine also keeps the first referrer, UTM tags, landing page and location it saw, which is what first-touch attribution is built on.

Never stored: the IP address; the user-agent string itself (only the device type and browser name derived from it); the window width; the full referring URL; and the gclid/fbclid/ref click ids, which the tracker sends but the server discards.

Requests from automated clients are discarded on arrival, identified by their user-agent. Excess traffic from a single visitor id is discarded by a rate limit held in memory, keyed on the visitor id, not the IP address.

Sales data from a customer’s payment provider

When a customer connects Polar (read with an orders:read token), Lemon Squeezy (delivered to a webhook Peregrine creates with the customer’s API key) or Dodo Payments (read with the customer’s API key), Peregrine stores, for each paid order: the order id, the amount, the currency, when it was created, the visitor id the checkout carried (if any), and, for Lemon Squeezy and Dodo Payments, whether it was a test-mode order. Orders that are not paid are not stored. No buyer name, email address or billing address is stored.

7. Why we use data, and the legal basis

PurposeDataBasis (GDPR)
Providing your account, dashboard and subscriptionAccount, subscription and site dataPerforming our contract with you
Service messages: billing, usage limits, changes to termsEmail address, plan and usagePerforming our contract with you
Keeping the service secure and working; preventing abuseAccount data, server logsOur legitimate interest in running a reliable service
Measuring our own website and which channels bring customersTracker data (section 6) for justperegrine.comOur legitimate interest in understanding our own marketing [TBD — or consent, per the cookie decision in section 5]
Keeping business and tax recordsSubscription recordsLegal obligation

We do not send marketing email without your agreement. We do not make automated decisions about you that have legal or similarly significant effects.

8. Who else handles the data

These providers process personal data for us:

ProviderWhat forWhere
VercelHosting and serverless functions; derives location from IP addresses at its edgeUnited States (edge locations worldwide)
NeonThe Postgres database that stores all of the aboveUnited States (AWS us-east-2, Ohio)
ClerkSign-in, account email, waitlistUnited States
PolarMerchant of Record for Peregrine subscriptions: payment, tax, invoices, customer portal[TBD — confirm Polar’s processing location]
[TBD — email delivery provider]Sending usage and service emails[TBD — location]

Polar and Lemon Squeezy also appear in Peregrine, alongside Dodo Payments, as integrations a customer chooses to connect for their own sales. In that case they are the customer’s providers, not ours: Peregrine reads orders from them on the customer’s behalf.

Apart from these, we disclose personal data only when required by law, or to protect against fraud or a security threat. If Peregrine is ever transferred to someone else, the data would go with it, under this policy, and we would tell you first.

9. International transfers

Peregrine is operated from Israel, and the providers above process data in the United States. For transfers of personal data from the EU or UK: Israel is covered by an EU adequacy decision; for transfers to the United States, we rely on the EU–US Data Privacy Framework (and its UK extension) for providers certified under it, and otherwise on the European Commission’s Standard Contractual Clauses in the provider’s data processing terms. [TBD — confirm, per provider, DPF certification or SCCs in their DPA]

10. How long we keep it

  • Analytics and sales data (section 6): for as long as the customer’s subscription is active, with no fixed limit; deleted 30 days after the subscription ends, or 7 days after a trial ends without converting, or 7 days after a site was added if no subscription was ever started. A customer can delete a site and all of its data at any time.
  • Account data: until you ask us to delete your account.
  • Subscription records: as long as tax and accounting law requires [TBD — confirm the statutory record-keeping period]. Polar keeps its own records as Merchant of Record.
  • Server logs at Vercel, which can include order ids, amounts and visitor ids from payment processing: [TBD — confirm Vercel log retention on our plan].
  • Waitlist emails: until the waitlist closes or you ask us to remove yours.

11. Security

  • All traffic to Peregrine and between Peregrine and its database is encrypted (HTTPS/TLS).
  • Payment-provider credentials are encrypted at rest with AES-256-GCM, under a key held only in the production environment.
  • Every dashboard query is scoped to sites owned by the signed-in account, so one customer cannot read another’s data.
  • Deliveries from payment providers are verified by signature against a secret specific to that customer’s site before anything in them is read, and each order is recorded once.
  • Access to production data is limited to the person who runs Peregrine.
  • Backups: [TBD — confirm Neon point-in-time recovery and its retention window].

No system is perfectly secure, and we do not claim this one is.

12. If something goes wrong

If we become aware of a personal data breach, we will notify the relevant supervisory authority where the law requires it (under the GDPR, within 72 hours where feasible), and affected customers without undue delay. For data we process for a customer, we notify that customer, who decides whether their visitors need to be told; the DPA sets out what we provide.

13. Your rights

Depending on where you live, you have rights over personal data we hold about you as controller. Under the GDPR (and UK GDPR) these include the right to access it, correct it, delete it, restrict or object to its use, receive it in a portable form, and withdraw consent where consent is the basis. Under Israel’s Protection of Privacy Law, 5741-1981, as amended (including by Amendment 13, in force since August 2025), you have the right to inspect personal data about you in a database and to ask for it to be corrected or deleted.

To use any of these rights, write to support@justperegrine.com. We may ask you to confirm your identity. We answer within one month, or sooner where the law requires.

You can also complain to a supervisory authority: in Israel, the Privacy Protection Authority; in the EU, the authority in your country; in the UK, the ICO. We would appreciate the chance to fix the problem first.

If you are a visitor to a customer’s website, see the note in section 1: that website’s owner is the one to ask. Because the tracker identifies you only by a random id, the owner will need the value of the peregrine_vid cookie from your browser to find your data.

14. Children

Peregrine is a business tool and is not directed at children under 16. We do not knowingly hold account data about them. If you believe a child has given us their data, write to support@justperegrine.com and we will delete it.

15. Changes to this policy

When we change this policy we will update the effective date above. If a change is material, we will email customers before it takes effect.

16. Contact

Privacy questions and requests: support@justperegrine.com. Post: Peregrine, [TBD — postal address].

peregrine
Demo
© 2026
Privacy
hello@justperegrine.com