More in Privacy and compliance
Still have a question?
Could not find it? A person reads every message, usually within a few hours on business days.
Chat with usWhere it is and who can edit it
Open Compliance center from the site menu (the project path is settings/privacy). Owners and Admins can edit; everyone else can read. After a save, the collector picks up the new rules on the next hit — there is no deploy.
The page notes that compliance mode is always on. Address truncation, personal-data stripping and expiry deletion run for every site; this screen decides how strict each one is.
Tier, consent and opt-out
The top section sets the project default collection tier (1, 2 or 3, explained in the cookieless guide) and whether consent is required. Consent has three purposes — analytics, functional, marketing — and a before-consent behavior: queue (default) or drop.
Opt-out is a collection switch a visitor can flip from your site; its scope defaults to every device of that person and can be limited to the current device. It is not the same as a data-subject restrict request, which has a cooling-off period and is described in export and deletion.
Regional rules
Regions are derived from the country of the address before it is discarded (and for the US, whether the state is California). Each region rule can override the tier, the consent requirement, how many address bytes to truncate, and the geography granularity:
| Region | Default rule |
|---|---|
| EEA, UK | Tier 2, consent required, city geography |
| US-California | Inherits project default; opt-out honored |
| Rest of US | Inherits project default |
| China (CN) | Inherits project default; China mode adds further rules (below) |
| Other | Inherits project default |
A blank field inherits the project default. Global Privacy Control and Do Not Track are honored in every region and force tier 1 for that hit.
China mode
China mode is added on top of regional rules; it does not replace the EEA rule. When it is on, the SDKs wait for explicit consent before initializing, the cooling-off period for erasure requests defaults to 7 days instead of 3, and the China export counter, data-subject deadline and child-related fields become available. Child mode forces tier 1, writes no identifier and shortens raw-row retention.
Address truncation, stripping and retention
- Address truncation — the default removes 2 bytes (the last two IPv4 octets; IPv6 drops the matching tail) before the city lookup. Geography can be city, country or none. The address itself is never written to the event.
- Stripping — strings that look like an email or a phone number in event properties are replaced with a placeholder. On by default. Autocapture does not capture visible text by default. Email and phone passed at login stay out of the profile unless encrypted contact storage is enabled.
- Retention — defaults inside the compliance config are 12 months for events, 90 days for autocapture, 24 months for profiles and consent receipts. The effective value is capped by your plan: 6 months on Free, 12 on Pro, 24 or more on VIP. A scheduled job deletes expired rows.
Presets and member masking
Two presets set several fields at once: pseudonymous statistics without consent and identified collection with full consent. Fields set by a preset are locked until you release it, so an Admin cannot accidentally weaken one switch.
Separately from collection, what each member sees on reports is controlled by display masking — none, partial or full — per role and per member. That lives on the Members page and is covered in Team and roles. The product overview is on Privacy and security.