Site Analytics
Privacy and data boundaries
See what the beacon excludes and how origin authorization and sessions work.
Optimly is designed to measure website behavior without collecting the contents of a visitor's form or building a persistent cross-site identity.
The beacon does not collect
- form field values;
- page text or arbitrary DOM content;
- email addresses or phone numbers;
- full referrer URLs;
- query strings or URL fragments;
- raw visitor IP addresses as report data;
- account or organization identifiers supplied by the browser;
- persistent identity across unrelated domains.
Origin authorization
Every browser event requires a public site key and an exact allowed request origin. The collector derives the origin from the request and resolves the organization, brand, and site on the server.
Sessions
Browser reporting uses an opaque anonymous session identifier with an inactivity boundary. Approved sibling subdomains may share a first-party session only when they are configured as related origins for the same site. Optimly does not silently link unrelated domains.
Candidate discovery
Goal setup can temporarily enable bounded interaction discovery on an authorized site. The test window expires automatically and returns only safe link, form, destination, or explicit-event candidates.
Customer obligations
Customers are responsible for describing their use of analytics and similar technologies in their privacy notice and for obtaining consent where applicable. Do not paste event payloads, site keys, session identifiers, or visitor information into support tickets.