Privacy at Mouseflow: Our Commitment to Trust & Transparency
Privacy by design & by default
At Mouseflow, we believe privacy is a fundamental right. We are committed to transparency, security, and compliance, ensuring that our customers and their end users have full confidence in how data is handled.
How we handle data
1. What data we collect & why
We only process behavioral analytics data, helping companies improve their websites based on user interactions – without compromising personal privacy. We follow a data minimization principle, meaning we only collect and process the absolute minimum data necessary for analytics purposes.
Session replay & heatmaps – to analyze user behavior, improve UX, and detect friction points.
Performance analytics – to optimize website responsiveness and content effectiveness.
Form analytics – to help businesses improve online conversions.
To achieve these goals, we rely solely on anonymized sessions and aggregated data, without identifying individual visitors.
What we do not collect:
Data that would enable us to identify an individual website visitor.
Keystroke logging or intrusive tracking.
Data beyond what is needed for analytics purposes.
2. Compliance with Global Privacy Laws
We adhere to international privacy frameworks, helping our customers stay compliant:
🇪🇺 GDPR (EEA, UK) – We provide a Data Processing Agreement (DPA), enforce strict policies for vetting sub-processors, comply with cross-border data transfer requirements, support privacy-by-design solutions and implement robust security measures. For more details, visit our dedicated GDPR compliance page.
🇺🇸 CCPA/CPRA (California) & other U.S. Privacy Laws – We do not sell or share personal data as defined under the CCPA and other applicable U.S. privacy laws. We implement strict controls to prevent unauthorized data sharing, offer Do Not Track (DNT) feature and ensure compliance with consumer privacy rights. For more details, visit our dedicated US Privacy compliance page.
🌍 LGPD, PIPEDA, POPIA & Global Privacy – We take a global-first approach to privacy, ensuring compliance with Brazil’s LGPD, Canada’s PIPEDA, South Africa’s POPIA, and other applicable privacy laws.
Where is data stored?
-
Secure cloud environments with ISO 27001 and SOC 2 Type II-certified infrastructure.
-
Data residency options available in EU or US.
3. Security & Data Protection
Keeping your data secure is our top priority.
🔒 End-to-end security – Encryption in transit and at rest.
🔒 Access controls – Strict policies ensure only authorized personnel can handle data.
🔒 Anonymization & masking – IPs and keystrokes are masked by default.
🔒 Data minimization – We store only what’s necessary for the shortest time needed.
🛠️ Your control: Customers can customize privacy settings, define retention periods, and delete data upon request. They must exclude website elements that may contain or display personal data.
📌 More questions? Visit our Security Pages.
Your rights & choices
👤 For website visitors:
✅ Opt-out of analytics tracking via cookie settings or by enabling Do Not Track (DNT) signals in your browser.
🏢 For customers:
Use our Visual Privacy Tool to configure tracking policies.
Set data retention rules according to your compliance needs.
🌍 Data residency in EU or US.