Privacy Policy
This website sets no cookies, has no accounts or forms, and does not store your IP address in its analytics. We measure anonymous page statistics so we can tell which pages are useful — nothing that identifies you.
Effective:
What this policy covers
This policy covers the website ombratattoo.com only. The Ombra Tattoo iOS app is a separate product that handles photos, subscriptions and an in-app identity, none of which exist on this website — it has its own policy, linked at the end of this page.
What we collect
When you open a page, our own analytics records:
- the page path and its language
- the site that linked you here. Most browsers send only the domain, and that is normally all we get — but if a site chooses to send the full address, we store it, capped at 200 characters
- campaign parameters in the link you followed (utm_source, utm_medium, utm_campaign, utm_content), when present
- your country, resolved by Cloudflare (see "Tools we use") — we receive the country code, not your IP address
- a short-lived visit id: it is not a cookie and is never written to your device's storage — it lives in the page's memory and is gone the moment you reload or close the tab. It is sent with each pageview so a visit counts as one visit, and it is stored next to those pageviews and next to the App Store tap that visit produced, if any — and to nothing else
- a coarse classification of your browser (human, search crawler, link-preview bot), derived from the user-agent and then discarded — the raw user-agent string is never stored
What we do not collect
- No cookies, no localStorage, and no persistent device fingerprint that follows you between sites.
- No IP addresses in our analytics database.
- No names, emails or accounts — the site has no login and no forms.
- No advertising trackers and no cross-site tracking. If we ever run ads that link here, the ad platform's click id would arrive in the link and be recorded with the pageview — we will say so here before that happens.
- We do not sell, rent or share this data with data brokers or advertisers.
Why we collect it
To answer two questions: which pages people find useful, and which ones lead people to the app. What we look at is aggregate — we can see that a page was viewed 40 times, not who viewed it. We could not identify you from it if we tried.
Tools we use
- Our own first-party analytics, running on our servers. Nothing is sent to a third-party analytics company.
- Umami, a cookie-free analytics tool we self-host at analytics.ombratattoo.com — its database is on our own server. Alongside the page and referrer it also records your browser, operating system, device type, screen size and language, plus one action: tapping a button that opens the App Store. It identifies a visit by a one-way hash of your IP address and browser rather than by a cookie. What is stored is that hash, never your IP address itself, and because our own site id is part of it, it cannot be matched to you anywhere else — but it does stay the same for as long as your IP address and browser do, which is how a repeat visit is recognised as the same visitor.
- Cloudflare, which serves and protects the site. Like any provider that routes traffic, it necessarily sees the request — including your IP address — in order to deliver the page. We receive only the resulting country code from it.
- Standard web-server access logs, which contain IP addresses — unavoidable for any server on the internet. They exist only for security and troubleshooting, are never joined to the analytics above, and are never used to build a profile of you. They are kept in a rolling window capped by size rather than by date: once the cap is reached the oldest entries are discarded automatically. At the traffic this site currently sees that window is roughly the last month, and it gets shorter as traffic grows.
Links to the App Store
Buttons that open the App Store go through a redirect on our own domain so we can count how many people tapped. The redirect records which page the tap came from, and a temporary random number for your current visit so we can tell whether the people who arrive from search behave differently from those who arrive from social — not who you are. That number is made up fresh each time you load the site and is never stored on your device; it disappears from your browser when you leave, and the copy we recorded is kept with the pageviews of that same visit. Once you reach the App Store, Apple's own privacy policy applies.
Your choices
If your browser sends Do Not Track or Global Privacy Control, both of the analytics tools above stop: no pageview is recorded, and no visit id is created or attached to anything. One count survives, because it happens on our server rather than in your browser: a tap on an App Store button is still tallied against the page it came from, with no visit id — only the address of the page the tap came from. A content blocker or privacy extension will also block Umami. The site works exactly the same either way. There is no consent banner because there is nothing to consent to: no cookies are set and nothing that identifies you is collected.
Retention and changes
We keep one row per pageview, and one per App Store tap, so we can compare periods over time. Those rows carry no name, no email, no account and no IP address, so there is nothing we could look up to identify you — and correspondingly no personal record to delete. If we ever change what this site collects, we will update this page and its effective date in the same change.
Contact
Questions about this policy: [email protected]