Privacy Policy
Effective date: July 1, 2026
1. Who We Are
ProductMetrics (productmetrics.org) is operated by Roarke Clinton. It is two things: a free content reference site providing definitions, formulas, benchmarks, and examples for product metrics, and an invite-only metrics platform (currently in beta) that account holders use to measure visitor behavior on their own websites. This policy covers both.
2. What We Collect
Analytics (with consent)
With your consent, we use UserActivity to understand how visitors interact with the site. UserActivity tracks scroll depth, click patterns, page navigation, and engagement signals. It sets a first-party cookie (__ua_vid, 1 year) for anonymous visitor identification, and stores approximate country and region (ISO codes) derived at the network edge from the request IP — the IP itself is not stored. It also receives the browser’s IANA timezone (e.g. America/Los_Angeles) reported by the browser’s Intl API. UserActivity also stores a daily-rotating one-way hash of IP + User-Agent + site ID to count same-day unique visitors; the hash changes every 24 hours and cannot be used to trace visitors across days. It respects Do Not Track browser settings. See the Cookies and local storage section below for details.
Our own tracker (with consent)
productmetrics.org also runs the platform’s own tracker, pm.js — we use our own product. It loads under the same consent banner and collects the same data described in “Tracking data we process for platform customers” below: event type, a session id, and the page path only — no query strings, no form values, and no raw IP address stored. It sets no cookies; it keeps a 30-minute session id in browser sessionStorage (pm_sid), which is transmitted with events as the session identifier.
Analytics are only loaded after you accept cookies via the consent banner. If you decline, no analytics data is collected.
Feedback widget
This site includes a feedback widget operated by Communications (comms.roarke.io). The widget does not set cookies and does not collect data unless you actively submit feedback. See the widget privacy policy for full details.
Server logs
Our hosting provider (Vercel) logs IP addresses, request timestamps, URLs accessed, and HTTP headers for security and debugging. We do not access these logs for marketing purposes.
Platform accounts (invite-only beta)
The metrics platform uses email-and-password accounts, handled by Supabase Auth. Signup is invite-only during the beta. There is no open registration. Access is granted by emailing team@productmetrics.org. For account holders we store your account email and the sites you create (site name and an optional domain).
Tracking data we process for platform customers
Platform customers install our tracker (pm.js) on their own websites. (productmetrics.org itself runs pm.js too, under the same consent banner — see the Analytics section above.) For each customer site we store the event type, a session id, and the page path only (query strings are stripped server-side), plus a small set of size-clamped event and context fields and the referrer reduced to host and path. To count same-day unique visitors we store a daily-rotating HMAC hash. The hash key rotates at UTC midnight, so visitors cannot be re-identified across days. The raw IP address is not stored. A persistent visitor id exists only if the customer’s integration provides one.
Our servers drop event batches that are not marked consent-granted, and the documented install pattern for pm.js is to load it after your consent gate. The customer is responsible for obtaining their visitors’ consent and for their own site’s privacy disclosures. We process this data on the customer’s behalf. For visitors to productmetrics.org itself, we remain the party responsible, as described in the Analytics section above.
4. What We Do Not Collect
- No advertising or marketing tracking
- No data sold to third parties
- No raw IP addresses stored in analytics or platform event data
- No query strings in platform event data (stripped server-side)
5. Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| UserActivity | Behavioral analytics | Browsing patterns (with consent) |
| Communications | Feedback collection | Only data you submit |
| Supabase | Database and authentication | Account data and platform event data (US region) |
| Vercel | Hosting | Request metadata in server logs |
6. Your Rights
You have the right to:
- Decline analytics cookies via the consent banner
- Access your feedback submissions
- Delete your feedback submissions
- Access, export, or delete your account, your sites, and your platform event data (account holders)
To exercise any of these rights, email team@productmetrics.org.
7. Data Retention
Platform event data and account data are retained while your account is active. We delete your account, your sites, or your event data on request. Email team@productmetrics.org.
8. International Data Transfers
Our infrastructure is hosted in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States.
9. Changes
We may update this policy from time to time. Changes will be reflected in the effective date at the top.
10. Contact
Privacy questions? Email team@productmetrics.org.