Privacy policy
Last updated September 29, 2026
This policy explains what personal data Peekbird handles and why. Peekbird is operated by Levan Tchubabria, Individual Entrepreneur (identification number 01005029894), Mirian Mepe Str. #80, Tbilisi, Georgia ("we"). Questions, and requests about your data: [email protected].
1. Data about our customers
When you create an account or buy a plan, we handle:
- Account details: your name, username, email address, and your password (stored only as a secure hash).
- Workspace details: your workspace, its members and their roles, and your sites and settings.
- Billing: your plan and its status. Payments are handled by Paddle, our reseller and merchant of record; we never see or store your card details.
- Security: sign-in sessions and, if you use it, two-factor authentication.
We use this to provide Peekbird and your account (a contract with you), to keep it secure, and to meet legal duties such as accounting.
2. Data about your website's visitors
When a customer installs Peekbird on their website, Peekbird collects data about that website's visitors on the customer's behalf. The customer is the controller of that data and we are their processor: we use it only to provide Peekbird to them. If you visited a website that uses Peekbird, contact that website about your data. It includes:
- the pages visited, where the visit came from, device, browser and country (from the connection, not stored as an address);
- how pages were used: clicks, scrolling, errors and loading speed, and which experiment variations were shown;
- for recorded visits, a recording of the page and what happened on it. What visitors type into forms is always masked, and websites can leave any part of a page out;
- goals, orders and events the website sends, and, only if the website sends them, a user ID, name or email address.
Peekbird identifies a browser with first-party cookies set on the customer's website (such as _peekbird_uid and _peekbird_sid). Websites can make Peekbird wait for their visitors' consent before it runs.
3. Visitors to peekbird.com
- We use Peekbird itself on this website, with the cookies above, to see how the site is used and to improve it, including recordings of visits with anything typed hidden. In the EU and EEA, the UK (with Jersey, Guernsey, the Isle of Man and Gibraltar), Quebec, California, Pennsylvania, Florida, Massachusetts, Washington, South Korea, Turkey, Brazil, India and China, it runs only if you accept in the cookie banner. Elsewhere it runs unless you decline in the notice, and we treat your browser's Global Privacy Control signal as declining. "Cookie settings" at the bottom of every page changes your answer.
- When you're signed in to Peekbird, it sets a cookie here named
peekbird_signed_in, holding no personal data, so this website's menu can take you to your dashboard. Signing out removes it. - If you write to us, we keep the conversation to answer you.
4. Where data is stored, and who helps us
Data is stored in the European Union. We use these providers, each bound to protect it:
- Hetzner Online (Germany): the servers that run Peekbird and its databases.
- Cloudflare: the network in front of Peekbird, and storage for recordings and backups in its EU-only region.
- Paddle: payments, taxes and invoices, as merchant of record.
- Google Workspace: our email, for support.
- Resend: sending account emails, such as password resets, invitations and security notices.
We don't sell personal data, and we don't use your or your visitors' data for advertising.
5. How long it's kept
- Recordings: as long as each site chooses, up to its plan's limit (30 days on Free, 13 months on paid plans), then deleted.
- Other visitor data: as long as the site exists, unless the customer erases it sooner. Deleting a site deletes its recordings.
- Account data: while the account exists; billing records as long as tax law requires.
6. Your rights
You can ask us for a copy of your personal data, to correct or delete it, to restrict or object to how we use it, or to receive it in a portable form, and you can complain to your data protection authority. For data collected on a customer's website, we pass requests to that customer, who decides. Write to [email protected].
7. Security
Connections are encrypted, access is limited to what's needed, passwords are hashed, and two-factor sign-in is available (and enforceable per workspace). Shared recordings never show who the visitor was.
To help with a support request, or to keep Peekbird running, our staff can view an account as its owner sees it. They can only look, never change anything, they sign in with two-factor authentication, and every view is logged with who looked and when.
8. Changes
If we change this policy, we'll post the new version here, with the date at the top.