Last updated: 11 August 2026
This Privacy Policy explains how Tyga.Cloud Ltd ("we", "us", "our") handles personal data in connection with socialgraffa (the "Service"). socialgraffa is a division of Tyga.Cloud Ltd. socialgraffa is cookieless by design: the tracking script sets no cookie of its own and persists no raw identifier.
Tyga.Cloud Ltd is the operator of socialgraffa. For questions about this policy or to exercise your rights, contact us at privacy@tyga.cloud.
For account data (your tenant, users, API keys, and billing) we act as a data controller. For analytics data you collect about visitors to your own websites and services, you are the controller and we act as a processor on your behalf. You are responsible for having a lawful basis and for informing your own visitors.
Anonymous visitor identity is derived from the visitor's IP address and user-agent, combined with a rotating daily salt, to produce a non-reversible identifier. We do not store the raw IP address as a persistent identifier and we set no tracking cookie. When you send server-side events, you may supply a stable --id; this is used only to attribute events to a consistent visitor and should not contain data you do not have a lawful basis to process.
We do not sell personal data, and we do not use your analytics data to build cross-site advertising profiles.
Where GDPR applies, we rely on: contract (to provide the Service to you), legitimate interests (to secure and improve the Service), and legal obligation (to comply with law). For analytics you collect from your own visitors, establishing a legal basis is your responsibility as controller.
Analytics data is retained according to your plan's data-retention window (for example, 30 days on Free, longer on paid plans). Account data is retained for the life of your tenant and for a reasonable period afterwards to meet legal and accounting obligations. You can delete data via the dashboard or CLI.
| Sub-processor | Purpose |
|---|---|
| Stripe | Payment processing for paid plans |
| Tyga.Cloud infrastructure | Hosting, storage, and delivery of the Service |
We may process data in locations outside your country. Where we transfer personal data internationally, we use appropriate safeguards such as Standard Contractual Clauses.
Subject to applicable law, you may have the right to access, correct, delete, or port your personal data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. To exercise these rights, contact privacy@tyga.cloud. If your request concerns analytics data we process on behalf of one of our customers, we will refer you to that customer as the controller.
We use full tenant isolation, password hashing, key hashing (only key hashes are stored), transport encryption, and least-privilege scoped ingest keys. No system is perfectly secure, but we work to protect your data with industry-standard measures.
Tyga.Cloud Ltd — privacy@tyga.cloud. See also our Cookie Policy and Terms of Service.