Security and data protection at Modovisa
The commitments and controls behind your account and your visitors' data — what we protect, what you can control yourself, and how to reach us if something looks wrong.
Account protection
Access to a workspace requires an authenticated session, and every account can enable two-factor authentication. Sessions can be signed out, passwords can be reset from the login screen, and administrative capability inside our own organisation is scoped to the people who need it rather than shared across the team.
- Two-factor authentication available on every plan
- All traffic served over HTTPS
- Internal access limited to what a role requires
Privacy by default, not by configuration
Modovisa is built to be useful without following people around the internet. Your visitors' data belongs to you: we do not sell it, we do not share it with advertising networks, and we do not use it to build cross-site profiles or to train models. Analytics data is processed to deliver the product you are paying for, and nothing else.
- No selling or sharing of visitor data
- No cross-site profiles and no advertising networks
- First-party data, reported back only to your workspace
Retention you choose
How long we keep analytics data is set by your plan rather than by us: the Free plan holds 30 days of history, and paid plans keep it for as long as your account is active. If you want data gone sooner, deleting a site or your account removes it — you do not need to open a ticket and wait for someone to action it.
- 30 days of history on Free, unlimited on paid plans
- Self-serve deletion of a site or the whole account
- Deletion removes the underlying analytics data, not just its display
Paperwork for teams that need it
If your organisation needs a Data Processing Agreement on file before rolling out analytics, one is published and ready to reference rather than negotiated case by case. The Privacy Policy sets out exactly what is collected and why, who processes it on our behalf, and the rights your visitors have. Both are public, so procurement can read them before you talk to us.
- Data Processing Agreement — /legal/dpa
- Privacy Policy, including processors — /legal/privacy-policy
- Delete your account and data — /legal/delete-account
Reporting a vulnerability
If you believe you have found a security problem, email [email protected] with enough detail to reproduce it. We aim to acknowledge reports within two business days and will tell you what we intend to do about it. We would rather hear about a problem early from you than late from someone else, and we will not pursue researchers who report in good faith.
Frequently asked questions
Is two-factor authentication available?
Yes. Two-factor authentication can be enabled on any account, on every plan, from your profile settings.
Do you sell or share visitor data?
No. We do not sell visitor data, share it with advertising networks, or use it to build cross-site profiles or train models. It is reported back to your workspace and used to deliver the product.
How long is analytics data kept?
30 days on the Free plan and unlimited on paid plans while your account is active. Deleting a site or your account removes the data, and both are self-serve.
Is a Data Processing Agreement available?
Yes. The DPA is published at /legal/dpa for customers who process personal data through the platform, alongside the Privacy Policy, which lists the processors involved.
Can I delete my data myself?
Yes. Account and data deletion is self-serve from your account settings, and is documented at /legal/delete-account.
How do I report a security issue?
Email [email protected] with steps to reproduce. We aim to acknowledge within two business days and will not pursue good-faith researchers.