SiteStats Privacy Policy

Last updated: 10 December 2025

SiteStats (“we”, “our”, “us”) provides a WordPress analytics dashboard plugin that allows website owners to connect Google Analytics 4 (GA4), Google Search Console, WooCommerce, WordPress data, Tutor LMS, Gravity Forms, and other data sources to view insights directly inside their WordPress dashboard. This Privacy Policy explains how SiteStats handles data, including any data retrieved through Google APIs.

1. Information We Collect

SiteStats may collect or access the following categories of information strictly for the purpose of displaying analytics within your WordPress dashboard.

1.1 Google Analytics Data

If you connect GA4, SiteStats may access:

  • Traffic and session metrics
  • Page views and engagement statistics
  • Events and conversions
  • Traffic sources
  • Device and geography breakdowns
  • Any other read-only metrics or dimensions you explicitly select

SiteStats does not have permission to edit, delete, or modify your Google Analytics account or data.

1.2 Google Search Console Data

If connected, SiteStats may access:

  • Search queries (keywords)
  • Clicks, impressions, and click-through rate (CTR)
  • Average position metrics
  • URL-level search performance data

All data is retrieved using read-only scopes.

1.3 WordPress Site Data

SiteStats may read:

  • Post, page, and custom post type performance
  • User counts and basic WordPress statistics
  • Comments, authors, taxonomies, and related content metrics
  • Plugin or theme metadata relevant to analytics and reporting

No data is sent outside your website unless explicitly stated in this policy.

1.4 WooCommerce Data (If Enabled)

If you enable WooCommerce integration, SiteStats may access:

  • Orders and revenue data
  • Product performance and sales volume
  • Customer counts and basic purchase statistics
  • Checkout and conversion-related metrics

This data remains stored within your WordPress installation.

1.5 LMS and Form Data (If Enabled)

If you enable LMS and form integrations, SiteStats may access:

  • Tutor LMS course progress and completion metrics
  • Enrollment, lesson, and activity statistics
  • Gravity Forms views, submissions, and conversion rates
  • Basic performance metrics from other supported plugins

This data remains stored locally on your site.

1.6 Technical & Log Data

SiteStats may store the following technical information:

  • OAuth tokens (stored securely and, where possible, encrypted)
  • API request logs and error logs (stored locally for debugging)
  • Plugin configuration and settings

SiteStats does not collect personal information about your site visitors beyond what is already collected and stored by your website and your connected services.

2. How We Use Your Data

Data accessed by SiteStats is used solely for:

  • Displaying analytics inside your WordPress admin dashboard
  • Creating charts, tables, dashboards, and reports
  • Improving plugin functionality and user experience
  • Debugging and troubleshooting when necessary

We do not:

  • Sell your data
  • Share your analytics data with unrelated third parties
  • Use your data for targeted advertising or profiling
  • Modify or delete your Google Analytics or Search Console data

SiteStats uses read-only Google scopes, meaning it cannot change or modify your Google data in any way.

3. How Your Data Is Stored

All data retrieved by SiteStats is stored locally on your WordPress site, typically in the WordPress database (such as options, transients, or custom tables).

In particular:

  • Analytics data is cached for performance and faster dashboard loading.
  • OAuth tokens are stored securely and may be encrypted depending on server capabilities.
  • Configuration and settings are stored in the WordPress database.

SiteStats developers do not have access to your site data unless you explicitly grant temporary access for support or troubleshooting.

4. Google User Data Disclosure

SiteStats’ use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • SiteStats only uses Google data to provide analytics features requested by the user.
  • SiteStats does not transfer Google data to external servers unless explicitly enabled by you.
  • SiteStats does not use Google data for advertising or marketing.
  • SiteStats does not combine Google data with non-user data to build profiles or for use outside of your analytics context.
  • Human access to your Google data is not permitted unless:
    • You explicitly grant consent (for example, for support purposes).
    • Access is required for security, abuse prevention, or debugging with your knowledge.
    • Access is required to comply with applicable law.

5. Data Sharing

We do not sell or rent your data to third parties.

Data may only be shared in the following situations:

  • When you explicitly grant temporary access to your WordPress admin area for support or debugging.
  • When we are required to do so by law, court order, or other legal process.

SiteStats does not share Google Analytics, Search Console, WooCommerce, LMS, or forms data with third-party marketers or analytics platforms.

6. Data Security

We take reasonable measures to protect data handled by SiteStats, including:

  • Using secure OAuth 2.0 authentication for Google services
  • Storing tokens securely and, where possible, in encrypted form
  • Minimising data collection and retention to what is necessary for functionality
  • Following WordPress development best practices

You are responsible for securing your WordPress installation, hosting environment, passwords, and admin access.

7. User Control and Data Removal

You can revoke SiteStats’ access to your Google data at any time by:

  • Disconnecting GA4 or Search Console within the SiteStats settings in WordPress.
  • Removing SiteStats’ access in your Google Account security settings.
  • Deactivating and deleting the SiteStats plugin from your WordPress site.

When you remove the plugin, SiteStats-related tokens, cached data, and settings stored in your WordPress database will be removed or rendered unusable as part of the uninstall process (subject to your uninstall settings).

8. Children’s Privacy

SiteStats is intended for use by website owners and administrators. It is not directed at children, and we do not knowingly collect information from individuals under 13 years of age. If you believe that a child has provided information through the use of SiteStats, please contact us so that we can investigate and take appropriate action.

9. International Data Transfers

By default, SiteStats operates entirely within your WordPress installation and does not transfer your analytics data across borders to external servers controlled by us, unless explicitly configured to do so in future optional cloud features (if offered).

Any such features, if enabled by you, will clearly explain how and where data is processed and stored.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our plugin, or legal requirements. When we do, we will update the “Last updated” date at the top of this page.

We encourage you to review this Privacy Policy periodically to stay informed about how SiteStats handles data.

11. Contact Us

If you have any questions about this Privacy Policy or how SiteStats handles data, please contact us:

SiteStats Support
Email: info@sitestatswp.com
Website: https://sitestatswp.com
Support Page: https://sitestatswp.com/support