Privacy & compliance

Handling visitor rights requests

A visitor asks you to access or delete “their analytics data.” With BobRay the honest answer is short, and here is how to give it properly.

5 min read Updated June 2026 Privacy & compliance
NO COOKIES · NO IDs

Why there is usually nothing to return

BobRay stores no identifiers: no IPs, no cookies, no names. Given an email address or IP, there is no lookup that can find “their” rows, the data is anonymous aggregates plus day-scoped tokens whose inputs were destroyed. Under GDPR Article 11, when data cannot be attributed to a person, access and erasure duties are correspondingly limited.

How to respond

  1. Acknowledge the request within your normal DSAR timeline.
  2. Explain that your analytics provider collects no personal data and holds nothing attributable to them; feel free to link Exactly what BobRay collects.
  3. If they insist on a processor confirmation, forward the request to privacy@bobray.com and we will provide a written statement for your records.

Account holders are different

Your own account (name, email, billing) is real personal data with full rights, export or deletion of that is handled any time via privacy@bobray.com.

Common pitfalls

The mistakes we see most often on this topic, so you can skip them entirely.

Quick reference

Lookup possibleNo, nothing identifiable
Legal hookGDPR Art. 11
Statementprivacy@bobray.com
Account holdersFull rights, separate flow
Did this solve it? If not, write to support with your site ID, a real person replies within one business day.