Pivty

What this site measures

Last updated: 13 July 2026

This site uses Pivty, a privacy-friendly analytics tool. This page transparently explains what is measured — and what is not.

Who is responsible for what

The operator of the site you visited is the controller responsible for processing your data under the GDPR. Pivty is the analytics tool they use and processes the data solely on that operator's behalf and instructions (processing under Art. 28 GDPR). For the visited site's full privacy policy and legal notice, please contact its operator.

Provider of the analytics tool

The tool is provided by:

SSL Fruitly AI GmbH & Co. KG
Inkustraße 1–7 / Stiege 2 / Haus C / 1. OG / Top 2109
3400 Klosterneuburg, Österreich
E-Mail: info@fruitly.net · Tel.: +43 650 37 50 530

By default (without consent)

Without storing anything on your device — no cookies — the following is recorded:

  • the page you view (path) and the time
  • where your visit came from (referrer domain, UTM parameters)
  • a coarse location (country, region, city and an approximately 40–80 km grid cell), derived locally from your IP address — neither the IP address nor the original coordinates are stored
  • browser, operating system, device type, screen size and language
  • interactions as events without their content (clicks, rage clicks, scroll depth, time on page)
  • frustration signals as content-free events (e.g. hectic scrolling, quickly navigating back, zoom gestures, hesitation in form fields — counts and times only, never inputs)
  • click positions on the page as anonymous coordinates for aggregated heatmaps
  • terms you type into this site's own search (taken from the address bar, e.g. ?q=…) — inputs that look like personal data are discarded
  • hits on non-existing pages (404) including the referring page
  • form interactions: start, submit attempt, confirmed success, validation/processing error and abandonment; only form/field names and timing/counts — never what you typed
  • short text snippets you copy from the page content (never from input fields; selections that look like personal data are discarded)
  • technical quality metrics (document load time, SPA route-settle time, layout stability and aggregated long tasks), JavaScript errors with redacted release context, and failed or slow server requests (normalized path, method, status and duration — never query strings, headers, request or response contents)
  • whether the consent dialog was shown, accepted, declined or withdrawn — as a content-free coverage/accountability counter
  • connection type (e.g. 4G) and your browser's preferred color scheme (light/dark)
  • events and revenue defined by the site operator

To recognise you within a single day we build a short-lived hash from a daily-rotating random value, your IP and browser signature. Raw IP and browser signature are never stored, and the random value is deleted every day — so no cross-day or cross-site tracking is possible.

Legal basis: the site operator's legitimate interest in privacy-friendly audience measurement (Art. 6(1)(f) GDPR). As no access to your device takes place, no consent under § 25(1) TDDDG (Germany) or § 165(3) TKG 2021 (Austria) is required.

Only with your consent

If you actively accept in the banner, this is added:

  • a stable random identifier in your browser (localStorage) to recognise you across days on this site — never across sites
  • a recording of your visit (session replay) so bugs can be found — everything you type stays masked and is never sent
  • a link to your account, if the operator identifies logged-in users

Legal basis: your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG / § 165(1) TKG 2021). You can withdraw it at any time with effect for the future — via the “tracking settings” link in the site's privacy policy (opens a panel with a withdraw button), by declining in the banner, or by deleting this site's data in your browser. Recognition then stops immediately.

Managing & withdrawing your consent

Withdrawing is as easy as consenting — and happens directly on the website you visited (not on this page):

  1. Look for the “tracking settings” link in the site's privacy policy or footer — it opens a small panel showing your current status.
  2. Click “Withdraw consent” there. The identifier in your browser is deleted immediately and any running recording stops.
  3. Alternatively, delete the site's data in your browser at any time — recognition ends immediately as well.

Withdrawal takes effect for the future; the lawfulness of processing before it remains unaffected (Art. 7(3) GDPR). Afterwards you count as an anonymous visitor again.

What is never collected

  • no raw IP addresses or browser signatures
  • no form inputs, passwords or payment data
  • no cross-site tracking, no ad networks, no data selling
  • no fingerprinting beyond the daily-expiring short-lived hash described above
  • no automated decision-making or profiling within the meaning of Art. 22 GDPR

Data & retention at a glance

DataStored whereFor how long
Data-minimised, pseudonymous statistics (pages, origin, coarse location, device and content-free interactions)the analytics tool's servers (EU)until the retention period set by the site operator expires (automatic deletion), or until they delete them manually — at most for the duration of their contract
Daily random value (salt) for anonymous countingservers (EU)24 hours, then irreversibly deleted
Random identifier after your consentyour browser (localStorage)until you withdraw or delete your browser data
Session recordings (inputs masked)the analytics tool's servers (EU)until the retention period set by the site operator expires (automatic deletion), or until they delete them manually — at most for the duration of their contract
Your banner decision (yes/no)your browser (localStorage)until you delete your browser data — required so the banner doesn't reappear

Security of processing (Art. 32 GDPR)

  • All transfers are TLS-encrypted; processing and storage happen exclusively on servers in the EU.
  • Raw IP addresses, full browser signatures and original GeoIP coordinates are not stored. Before persistence, the location is reduced to an approximately 40–80 km grid cell; only two integer grid IDs are retained.
  • Inputs are masked in your browser already (privacy by design, Art. 25 GDPR) — not just on the server.
  • Only the site operator can access the analyses, via an access-protected area.

Recipients & storage

  • Processing and storage take place on servers within the European Union. No transfer to third countries takes place.
  • The daily random value (salt) used for visitor recognition is irreversibly deleted after 24 hours.
  • Analytics data and any session recordings are stored for the duration of the site operator's contract with Pivty, or until the operator deletes them.

Frequently asked questions

Am I tracked across different websites?

No. The identifier applies exclusively to the one website you consented to. Without consent, the anonymous short-lived hash expires daily — cross-site tracking is technically impossible.

Can anyone see what I type?

No. In session recordings all inputs are technically masked before anything is transmitted. Password fields are ignored entirely; form statistics capture field names only, never contents.

Are cookies set?

No, no cookies are used. Without consent nothing at all is stored on your device; with consent, a single random identifier in your browser's localStorage.

Is my data sold or used for advertising?

No. There are no ad networks, no data selling and no merging with other sources. The data serves only the operator of the visited website to improve their offering.

Who can see the data?

Only the operator of the website you visited, via an access-protected area. Pivty processes the data solely on their behalf and does not use it for its own purposes.

What exactly is a session recording?

A technical reconstruction of what was visible on the page and where clicks and scrolling happened — comparable to a video of the page, but with masked inputs. It helps the operator understand errors and usability problems.

Your rights

Under the GDPR you have the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), as well as to object (Art. 21) and to withdraw consent given (Art. 7(3)).

As the site operator is the controller, please address these requests to them in the first instance; Pivty supports them. You also have the right to lodge a complaint with a data protection authority, e.g. the authority of your place of residence or the Austrian Data Protection Authority (Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at).

Declining is as easy as accepting — the site works the same either way.

Pivty·Legal notice·Privacy·Terms