Public service policy
Webcounter.ca Privacy Notice
Version 2026-08-06-1
Operator and contact
guardianmesh Inc. operates Counter in Canada and is the registrant and administrator of webcounter.ca. The service is independently operated. A mailing address for legal service is available on request.
Use these contacts for privacy and data-rights requests, security or abuse reports, and general support: privacy@webcounter.ca · security@webcounter.ca · support@webcounter.ca
Controller and processor roles
guardianmesh Inc. is the controller of account-holder information because it determines how and why that information is processed. The site owner is the controller of analytics visitor data because it installs and configures Counter and determines the purpose and lawful basis. guardianmesh Inc. processes visitor data for the site owner, on documented instructions, to operate the service.
The Webcounter.ca Data Processing Agreement forms part of the Terms for processing visitor data. Site owners remain responsible for visitor notices, consent choices, rights requests, and jurisdiction-specific duties. Counter provides controls to help, but it does not determine whether a site's collection is lawful.
Account and analytics data
We store account email addresses; password and credential hashes; MFA records; policy-acceptance evidence; site, monitor, and report settings; verified report-recipient addresses; aggregate report snapshots; probe summaries; incident and delivery history; encrypted browser push subscriptions; quotas; lifecycle audit records; and analytics events from configured sites. We use raw visitor IP addresses temporarily for coarse location, rate limiting, and keyed daily identifiers, but do not store them in analytics events.
Cookies and the optional consent identifier
Counter sets no visitor cookie by default. It identifies a visitor with a daily-rotating HMAC of a salt, IP address, user agent, and site. A site owner may enable cookie-based identity to measure returning visitors. After affirmative visitor consent, the tracking snippet writes the first-party _cnt_consent and _cnt_cid cookies for up to two years. The server re-keys that identifier per site to prevent cross-site matching. Calling counter('consent', false), or using browser controls, deletes the cookies and returns to cookieless measurement.
Purposes, legal grounds, and disclosure
We process account data to provide and secure the service, enforce limits, prevent abuse, deliver account messages and confirmed reports, answer support requests, and meet legal obligations. Where consent is required, we rely on it and allow it to be withdrawn. We do not sell personal information, use it for advertising, or combine visitor data across unrelated sites. The operator's shared first-party email service handles verification, recovery, and report mail without open or click tracking. The configured map-tile provider can receive the viewed map region and the signed-in user's network address; OpenStreetMap is the default.
Subprocessors
The providers below process data for the operator and are not used for advertising. The DPA governs notice and objections before a new subprocessor receives visitor personal data.
| Provider | Role | Data categories |
|---|---|---|
| OVH (OVHcloud) | Dedicated-server infrastructure in Montréal, Canada; the operator manages the operating system and application | Account, site, and analytics data at rest on hosted hardware; encrypted backup archives; network traffic |
| The operator's shared first-party email service | Account verification, password reset, and recipient-confirmed scheduled-report email | Recipient email address, message subject and body, and delivery metadata; untracked and retained no more than seven days |
| OpenStreetMap (tile.openstreetmap.org) | Dashboard visitor-map tiles when the default provider is configured | Requested tile coordinates and the signed-in operator's network address; no analytics event payload |
Government and legal requests
We review every court, regulator, or government request for a valid legal basis before disclosing account or analytics data. A valid disclosure is limited to the minimum data necessary. Unless legally prohibited or an imminent safety risk exists, the affected account is notified before or promptly after disclosure. No government or private party receives standing or bulk access to hosted data.
Hosting and international transfers
Production, staging, backups, and monitoring run in one Canadian region on one operator-managed dedicated server hosted by OVH in Montréal. Data submitted from outside Canada is transferred to Canada. Site owners are responsible for any transfer mechanism their visitor data requires. The Webcounter.ca Data Processing Agreement provides processor terms and EU, UK, and other safeguards where applicable. Before processing personal information outside Canada in the future, we will assess the transfer and update this notice and the subprocessor terms.
Retention and deletion
Uptime probes download no response body and keep summaries for 30 days. Incident and delivery history is kept for up to 400 days. Push endpoints and keys are encrypted; a separate one-way endpoint hash supports deduplication. Raw analytics events default to 400 days, while aggregate rollups may remain longer. Untracked account and report mail is kept for no more than seven days. Report snapshots and CSV links expire after 90 days. Requested raw-data exports expire after 7 days or earlier if cancelled or deleted. Account and site deletion is recoverable for 30 days before verified purge. Encrypted local backups expire after another 14 days, for a maximum expected erasure window of 44 days.
Control and rights
Account owners can change their email and password, manage MFA and sessions, control scheduled reports, export analytics, and delete sites or the account. Report recipients must confirm delivery and can unsubscribe from every report. Send requests that cannot be completed in the product to the privacy contact above. We may verify your identity before disclosing or changing account data. Applicable law may also provide rights to access, correct, delete, object, restrict, transfer, withdraw consent, or complain to a regulator.
Safeguards and incident response
Security and abuse logs contain limited metadata, not customer analytics payloads. Platform operators can manage lifecycle metadata but cannot impersonate customers or open their analytics. Safeguards include access controls, hashed credentials, optional account MFA, encrypted backups, HTTPS, keyed site-scoped identifiers, and limited retention. If we detect or reasonably suspect an incident involving account credentials or analytics data, we contain it, assess affected data and accounts, correct the cause, notify affected controllers without undue delay where required, and notify regulators when legally responsible. Material availability incidents appear at /status.