socialgraffa
Home Log in

Privacy Policy

Last updated: 11 August 2026

This Privacy Policy explains how Tyga.Cloud Ltd ("we", "us", "our") handles personal data in connection with socialgraffa (the "Service"). socialgraffa is a division of Tyga.Cloud Ltd. socialgraffa is cookieless by design: the tracking script sets no cookie of its own and persists no raw identifier.

Contents

  1. Who we are
  2. Controller & processor roles
  3. What we collect
  4. How identity is derived
  5. How we use data
  6. Legal bases
  7. Retention
  8. Sub-processors
  9. International transfers
  10. Your rights
  11. Security
  12. Contact

1. Who we are

Tyga.Cloud Ltd is the operator of socialgraffa. For questions about this policy or to exercise your rights, contact us at privacy@tyga.cloud.

2. Controller & processor roles

For account data (your tenant, users, API keys, and billing) we act as a data controller. For analytics data you collect about visitors to your own websites and services, you are the controller and we act as a processor on your behalf. You are responsible for having a lawful basis and for informing your own visitors.

3. What we collect

  • Account data: tenant name and slug, username, hashed password, email (if provided for the dashboard or billing), and API key hashes.
  • Analytics events: page views and custom events you send, including the website id, event name, timestamp, referrer, page path, and any event properties you attach.
  • Derived visitor signals: approximate location, browser, device, and operating system inferred from the request.
  • Billing data: handled by Stripe; we do not store full card details.

4. How identity is derived

Anonymous visitor identity is derived from the visitor's IP address and user-agent, combined with a rotating daily salt, to produce a non-reversible identifier. We do not store the raw IP address as a persistent identifier and we set no tracking cookie. When you send server-side events, you may supply a stable --id; this is used only to attribute events to a consistent visitor and should not contain data you do not have a lawful basis to process.

5. How we use data

  • to provide analytics, funnels, and network rollups to you;
  • to authenticate requests and enforce plan quotas and rate limits;
  • to process billing via Stripe;
  • to secure, maintain, and improve the Service.

We do not sell personal data, and we do not use your analytics data to build cross-site advertising profiles.

6. Legal bases

Where GDPR applies, we rely on: contract (to provide the Service to you), legitimate interests (to secure and improve the Service), and legal obligation (to comply with law). For analytics you collect from your own visitors, establishing a legal basis is your responsibility as controller.

7. Retention

Analytics data is retained according to your plan's data-retention window (for example, 30 days on Free, longer on paid plans). Account data is retained for the life of your tenant and for a reasonable period afterwards to meet legal and accounting obligations. You can delete data via the dashboard or CLI.

8. Sub-processors

Sub-processorPurpose
StripePayment processing for paid plans
Tyga.Cloud infrastructureHosting, storage, and delivery of the Service

9. International transfers

We may process data in locations outside your country. Where we transfer personal data internationally, we use appropriate safeguards such as Standard Contractual Clauses.

10. Your rights

Subject to applicable law, you may have the right to access, correct, delete, or port your personal data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. To exercise these rights, contact privacy@tyga.cloud. If your request concerns analytics data we process on behalf of one of our customers, we will refer you to that customer as the controller.

11. Security

We use full tenant isolation, password hashing, key hashing (only key hashes are stored), transport encryption, and least-privilege scoped ingest keys. No system is perfectly secure, but we work to protect your data with industry-standard measures.

12. Contact

Tyga.Cloud Ltd — privacy@tyga.cloud. See also our Cookie Policy and Terms of Service.

socialgraffa

Agent-first analytics for MCP + web traffic.

Legal

Privacy Policy Terms of Service Cookie Policy Manage Cookies

Product

Features Pricing npm GitHub
© Tyga.Cloud Ltd. SocialGraffa is a division of Tyga.Cloud Ltd. All rights reserved. Built for agents.