Insight Multiply Privacy Policy

Last updated: 25 June 2026 (draft — not yet published at production URL)

This privacy policy explains how Insight Multiply collects, uses, and protects personal data in connection with the Insight Multiply service. We take privacy seriously. This policy is written to be read, not to hide things in legal language.

1. Who we are

Insight Multiply is a website analytics and consent management tool that helps agencies and website owners understand how their sites are used, while giving their visitors meaningful control over tracking.

Business name: Insight Multiply
Country: United Kingdom
Contact email: dylancooper219@gmail.com

2. What the product does

Insight Multiply provides:

  • Analytics dashboards — page views, clicks, scroll depth, route changes, and engagement metrics
  • Consent management — a customisable consent banner for website visitors
  • Growth insights — summaries and patterns derived from analytics data
  • Session replay — recording of visitor sessions where explicitly enabled and consented to
  • Heatmaps — visual representations of where visitors click and scroll

3. Who this policy applies to

Insight Multiply account users— people who sign up to manage analytics for their own websites or their clients' websites.

Website visitors tracked through installed scripts — people who visit websites where the Insight Multiply tracking script has been installed by an account user. Website visitors should read the privacy policy of the website they are visiting, not this one. Account users are responsible for providing appropriate privacy information to their visitors (see Section 17).

Private beta users — during private beta, access is by invitation only. Features may change before public launch (see Section 15).

4. Data collected from account users

DataHow collectedWhy
Email addressVia Clerk at sign-upAccount creation and authentication
Name (if provided)Via Clerk at sign-upAccount management
Authentication session tokensVia ClerkKeeping you logged in
Project names and configurationEntered by you in the appTo store your analytics project settings
Centrally managed analytics configurationConfigured by Insight MultiplyTo power your analytics data
Consent banner configurationEntered by you in the appTo serve the right consent banner on your sites
Support messagesVia email or feedback channelTo respond to your queries
App usage dataVia Insight Multiply analytics infrastructure (if enabled)To understand how the product is being used

We do not collect payment information (no billing in the current beta). We do not intentionally collect special category data (health, race, religion, etc.) from account users.

5. Data collected from website visitors

When the Insight Multiply tracking script is active on a website and a visitor has given consent, the following data may be collected:

DataNotes
Page URL and page titleTo understand which pages are viewed
Click eventsTo understand what visitors interact with
Scroll depthTo understand how far down pages visitors read
Route changes (single-page apps)To track navigation within SPAs
Consent choiceWhether the visitor accepted or declined tracking
Session durationHow long a visitor is active
Approximate location (country/region)Derived from IP address by managed analytics infrastructure - exact IP is not stored long-term
Browser type and screen sizeTechnical context for analytics
Session replay dataOnly where explicitly enabled by the account user and consented to by the visitor
Heatmap interaction dataOnly where heatmaps are enabled

Data not intentionally collected: passwords, payment card details, special category data (health, religion, ethnicity), or form field contents. The data is processed through managed analytics infrastructure.

6. Cookies, localStorage, and local storage

On the Insight Multiply app: Clerk (our authentication provider) sets session cookies to keep you logged in. These are necessary for the app to function and are set when you sign in.

On websites where the tracking script is installed:The tracking script may use localStorage or cookies to remember a visitor's consent choice and to associate page views within a session. Account users should describe this usage in their own websites' privacy policies.

7. How we use your data

  • Provide the Insight Multiply service to you
  • Authenticate you and maintain your session
  • Store and serve your analytics project configuration
  • Generate insights and dashboards from your analytics data
  • Respond to support requests
  • Improve the reliability and quality of the product
  • Investigate security issues or errors
  • Understand how the product is used (via internal analytics, if enabled)

We do not sell your data. We do not use your data to serve advertising.

8. Lawful basis for processing

Processing activityLawful basis
Creating and managing your accountPerformance of a contract (Art. 6(1)(b))
Storing your project configurationPerformance of a contract (Art. 6(1)(b))
Providing analytics dashboardsPerformance of a contract (Art. 6(1)(b))
Security and fraud preventionLegitimate interests (Art. 6(1)(f))
Understanding app usage for product improvementLegitimate interests (Art. 6(1)(f))
Tracking website visitorsConsent (Art. 6(1)(a)) — via the consent banner
Session replay of website visitorsConsent (Art. 6(1)(a)) — explicit, when enabled

Where we rely on legitimate interests, we have considered that our interests do not override users' rights. You may object to processing based on legitimate interests (see Section 13).

9. Who we share data with

We do not sell or share personal data with third parties for their own marketing purposes. We use the following services, which process data on our behalf:

ServicePurposePrivacy policy
ClerkUser authentication and identity managementPrivacy policy
NeonPostgreSQL database hosting (UK, AWS eu-west-2 London)Privacy policy
Managed analytics infrastructureProduct analytics, session replay, heatmapsPrivacy policy
HostingerVPS application hostingPrivacy policy
GitHubSource code hosting (code only, not end-user data)Privacy policy

We may also disclose data where required by law or to protect our legal rights.

10. International data transfers

Our service providers may store and process data outside the United Kingdom. Where data is transferred outside the UK, we rely on Standard Contractual Clauses or equivalent transfer mechanisms under UK GDPR.

  • Clerk: headquartered in the United States. Data transferred under SCCs.
  • Neon: database hosted in the United Kingdom (AWS eu-west-2, London). No international transfer for data stored in Neon.
  • Managed analytics infrastructure: hosted according to Insight Multiply's configured analytics environment. Where international transfer applies, SCCs are used.
  • Hostinger VPS: hosting region TBD — confirm data centre location in Hostinger control panel.

11. Data retention

Data typeRetention period
Account and project dataRetained while your account is active. Deleted within 30 days of account deletion on request.
Authentication session dataManaged by Clerk — sessions expire automatically.
Analytics event dataRetained according to Insight Multiply analytics retention settings.
Support messagesRetained for 12 months after the query is resolved, then deleted.
Server/application logsRetained on Hostinger VPS — purged according to server log rotation configuration (typically 30 days).

To request deletion of your data, email dylancooper219@gmail.com.

12. Security

We take reasonable steps to protect personal data from unauthorised access, loss, or misuse. These include:

  • All connections to the app are encrypted via HTTPS
  • Authentication is handled by Clerk, a specialist identity provider
  • Database credentials and API keys are stored as environment variables, not in source code
  • The source code repository is private

No system is completely secure. If you become aware of a security issue, please contact us at dylancooper219@gmail.com.

13. Your rights

If you are in the UK or EEA, you have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — ask us to correct inaccurate data
  • Deletion — ask us to delete your data (“right to be forgotten”)
  • Restriction — ask us to limit how we use your data in certain circumstances
  • Objection — object to processing based on legitimate interests
  • Portability — request your data in a machine-readable format where technically feasible
  • Withdraw consent — where we process data based on your consent, you can withdraw it at any time
  • Complaint — you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk

To exercise any of these rights, email dylancooper219@gmail.com. We will respond within 30 days.

14. Contact us

For any questions about this policy or to exercise your rights:
Email: dylancooper219@gmail.com
Response time: We aim to respond within 5 business days. For rights requests, we will respond within 30 days as required by law.

15. Private beta limitations

Insight Multiply is currently in private beta. This means:

  • The product is not publicly available — access is by invitation only
  • Features may change significantly before public launch
  • Data handling practices may evolve as the product matures
  • We recommend not using Insight Multiply on high-risk or sensitive websites during the beta period
  • This privacy policy may be updated before public launch

We will notify beta users of material changes to this policy by email.

16. Session replay and heatmaps

Insight Multiply supports session replay and heatmap features through managed analytics infrastructure.

Session replay is disabled by default. It must be explicitly enabled by the account user for each project.

When session replay is enabled:

  • Visitors are shown the consent banner before any tracking begins
  • Recording only starts if the visitor gives consent
  • Input fields (passwords, form entries) should be masked by default in the recorder. Account users are responsible for verifying their replay configuration masks any sensitive inputs
  • Recordings are stored in managed analytics infrastructure and are subject to Insight Multiply analytics retention settings

Account users are responsible for:

  • Disclosing to their own site visitors that session recordings may be made
  • Describing session replay in their own sites' privacy policies
  • Ensuring their replay settings are configured to mask sensitive data appropriately

Heatmaps are subject to the same consent requirement. Heatmap data shows aggregate interaction patterns and does not store individual visitor sessions separately.

17. Customer responsibility

When you install the Insight Multiply tracking script on a website, you become the data controller for the analytics data collected from that site's visitors. Insight Multiply acts as a data processor on your behalf.

This means you are responsible for:

  • Providing your website visitors with clear privacy information, including disclosing that analytics tracking, session replay, and/or heatmaps may be used
  • Ensuring you have a valid lawful basis (typically consent) for collecting analytics data from your visitors
  • Configuring the consent banner correctly and linking it to your own privacy policy
  • Ensuring session replay is configured to mask sensitive form inputs on your site

If you are unsure whether your use of Insight Multiply is compliant with the privacy laws applicable to your sites and visitors, please seek independent legal advice.

18. Changes to this policy

We may update this policy from time to time. When we make material changes, we will notify active users by email and update the “Last updated” date at the top of this page. We encourage you to review this policy periodically.

This policy was prepared as a starting-point for Insight Multiply's private beta. It is not legal advice. If in doubt, seek independent review before public launch.