Weaver
ProduitTarifsÀ proposBlog
Se connecterRejoindre
ProduitTarifsÀ proposBlog
Se connecterRejoindre

Data, storage and consent

For website owners · Last updated: September 26, 2026

When you add Weaver to your website, Weaver measures your visitors on your behalf. This page tells you exactly what that involves: what is collected, what is placed in your visitors' browsers, where the data is kept and for how long, how Weaver treats your consent banner, and what you are responsible for. It is written so you can copy from it into your own privacy notice and cookie policy. Our privacy policy is the formal document; this page is the practical one.

Who is responsible for what

You decide to measure your website and what to switch on, so for your visitors' data you are the controller. Weaver collects, stores and processes that data only to provide the service to you, so Weaver is your processor. In practice: you tell your visitors that you use Weaver and ask for their consent where the law requires it; Weaver keeps the data safe, uses it for nothing else, and helps you answer your visitors' requests.

What Weaver collects

On every page view

  • A random visitor identifier that Weaver creates and stores in the visitor's browser (see the list below).
  • A session identifier that lasts until the browser tab is closed.
  • The IP address the request came from.
  • The browser's description of itself (user agent), its language, time zone, and screen and window size.
  • The address of the page, including its query string, and the address of the page the visitor came from (without its query string).
  • Campaign parameters already present in the link, such as UTM tags and advertising click identifiers.
  • The answer your consent banner gave at that moment: accepted, refused, or not answered yet.
  • Error messages from the Weaver script itself, so we can fix problems.

Only if you switch it on

  • Orders — the total, currency, shipping and the items of an order, read from your order confirmation page. To read the total, Weaver may keep a copy of that page for up to thirty days; order confirmation pages usually contain the buyer's name and address.
  • Leads — values from forms you choose to track. Password fields are never read, email fields are not stored as typed, and phone numbers are cut to their last four digits; other fields you track are stored as the visitor typed them, up to 100 characters. Track only the fields you need.
  • Signed-in visitors — the email address of a visitor, but only when your own site passes it to Weaver. Weaver never reads an email address off the page by itself.
  • Custom events — clicks, form steps and similar actions you define, with the details you choose to attach to them.

What Weaver never does

  • Sell or rent data, or share it with advertisers.
  • Follow your visitors to other companies' websites, or combine one customer's data with another's.
  • Build advertising profiles.
  • Record keystrokes or screen recordings of your visitors, or read password fields.

What Weaver stores in the visitor's browser

You can use this table for your cookie policy. All of it is analytics storage: none of it is needed for your website to work, so Weaver belongs in your banner's analytics (or “statistics”) category, not the essential one.

NameTypeSet byPurposeDuration
visitor_logger_user_uuidCookieYour domainRecognise a returning visitor2 years
visitor_logger_user_uuidCookieapi.weaverall.comSame identifier, kept by Weaver's server2 years
visitor_logger_user_uuidLocal storage, session storage and IndexedDB (weaver_tracker)Your domainCopies of the same identifier, so it survives if one copy is clearedUntil cleared by the visitor
weaver_session_idSession storageYour domainGroup page views into one visitUntil the tab is closed
weaver_tracker_order_configSession storageYour domainRemember where your order pages are (order tracking only)1 hour
weaver_cart_snapshot, weaver_prepay_*Local storageYour domainCarry the basket across an external payment page (order tracking only)1 hour and 24 hours

Where the data is stored

Your visitors' data is stored in Israel, in Amazon Web Services' Tel Aviv region. The European Commission recognises Israel as providing an adequate level of data protection. Storage disks and backups are encrypted, and data travels to and from Weaver over encrypted connections. Each website's records are kept separate and are visible only to the people you give access to.

These are the only other companies that process data for Weaver:

SupplierPurposeLocationReceives visitor data?
Amazon Web ServicesHosting, databases, file storage; delivery of the emails we send youIsrael; email delivery from the United StatesYes, stored in Israel
xAIThe language model behind the dashboard assistant and some monitoring featuresUnited StatesOnly the rows needed to answer a question you ask; if you ask about individual visitors, those rows are sent
SentryError monitoring of our own softwareUnited StatesNo — configured not to send visitor data
CreemSubscription billing—No — your billing details only
TelegramOperational alerts to our own team—No — at most your account's name and email

Transfers to suppliers in the United States rely on Standard Contractual Clauses or an equivalent safeguard. Our own marketing website also uses Contentsquare/Hotjar (only after you accept our banner) and Cloudflare; they receive nothing about your visitors.

How long it is kept

  • Individual visit records — three years, then removed automatically.
  • Copies of order confirmation pages — thirty days.
  • Records of traffic identified as automated — ninety days.
  • Everything built from the visits (visitor, conversion, lead, order and campaign records) — while your account is open. When you close your account, write to us and we delete it.

You cannot set a shorter retention period yourself yet; if you need one, write to us.

How Weaver handles your consent banner

Weaver reads the consent tool already running on your site, on every page, and records the visitor's answer with each visit. It recognises:

  • Cookiebot, OneTrust, Usercentrics, CookieYes and Complianz
  • The WordPress Consent API and Shopify's Customer Privacy API
  • Google Consent Mode (the analytics_storage signal most consent tools also send)
  • The browser's Global Privacy Control signal, which Weaver treats as a refusal

If you use a different tool, tell Weaver the answer from your own code once the Weaver script has loaded:

window.weaverTracker.consent({ analytics: true });  // or false

Important — what this does today. Weaver currently records your banner's answer but does not yet stop measuring when a visitor refuses. A setting that switches Weaver to cookie-free measurement when a visitor says no is being built and will be announced here. Until then, if your visitors must consent before analytics runs, set up your consent tool to load the Weaver script only after analytics consent — every consent tool listed above can hold a script back until the visitor accepts.

What you are responsible for

These are the conditions of using Weaver on a website:

  1. Consent. Where the law requires your visitors' consent for analytics — for example for visitors in the European Union or the United Kingdom — you collect it with your own consent banner, and you configure it so Weaver runs only with that consent. Weaver does not provide a banner for your site.
  2. The right category. Put Weaver in your banner's analytics or statistics category. Do not classify it as essential or strictly necessary.
  3. Tell your visitors. Name Weaver in your privacy notice as your analytics provider, and list the storage above in your cookie policy. You may link to this page.
  4. Switch on only what you need. Order, lead, signed-in-visitor and custom-event tracking collect more personal data. Enable them only when you have a reason and a legal basis, and never track form fields that ask for health, financial, identity-document or similarly sensitive information.
  5. No data about children. Do not use Weaver to identify visitors under 16, or on sites directed at children, without a legal basis.
  6. Forward visitor requests. If a visitor asks you to see, export or delete what Weaver holds about them, send the request to privacy@weaverall.com with their email address or visitor identifier and we will act on it. Today this is done by our team rather than a button in the dashboard.

Whether your site needs a consent banner at all depends on where your visitors are and what else your site runs. That is a question for your own advisers; this page is not legal advice.

Agreements

Our terms of service and privacy policy apply to every account. A standard data processing agreement for customers is being prepared; if you need one now, write to privacy@weaverall.com.

Contact

Questions about this page, or a request about a visitor's data: privacy@weaverall.com

Weaver

© 2026 Weaver · Vos données. Des réponses claires. Preuves à l'appui.

TarifsPolitique de confidentialitéDonnées et consentementConditions d'utilisationContactez-nous — support@weaverall.com