What is recorded when you visit

Some sites run by SHMAPLEX customers use our software to record which pages people open. This page explains what that software can and cannot collect, what it never collects, and the control you have over it.

Visiting a site does not sign you up for anything. Nothing here adds you to a mailing list, and nothing here is permission for anyone to contact you.

No signal on this request

This request did not carry a Global Privacy Control signal.

That is not a record of a choice you made — it only means the signal was not on this request. Most browsers do not send it unless you turn it on, and it can also be dropped by a network in between.

Most browsers offer Global Privacy Control in their privacy settings, and some need an extension. Once it is on, this site stops attempting to match your visits to a named person, and records that it did not.

What applies to your visit

Your connection was reported as coming from the region US-OH. Nobody has reviewed the rules for it, which is what the levels below reflect.

That region comes from the network your request arrived on, not from anything you told us, and it is not always exact. If it is wrong, it was still the reading the software acted on for this visit — it uses the same one you are looking at.

  • Matching your visit to a named person

    Not attempted — region unreviewed

    No attempt is made to match your visit to a named person. Nobody has reviewed the rules for the region your connection was reported from, and this software refuses the higher level rather than assume it is fine — an unreviewed region means unchecked, not known to be off-limits.

  • Working out which organisation your network belongs to

    May be looked up

    Which organisation your network belongs to may be looked up. That names a company, not you: it reads the network your request arrived on, sets no cookie, and does not fingerprint your browser. Two people at the same employer look identical to it.

The owner of the site you visited can choose to collect less than this describes — they can switch any of it off, or hold it to the lower level everywhere. What they cannot do is collect more than the rules above allow.

What can be collected

Three levels are possible. Which one applies depends on the visitor's region, and the site's owner can also choose a stricter level than their region allows.

Underneath all three, the same basic record is kept: which page was opened and when, along with your network address and the identifier your browser sends describing itself. Those last two are used to work out roughly where the visit came from and to tell real visits apart from automated traffic.

  1. No identification

    No permission is asked for
    What is recorded
    We record which pages are opened and when, so the site's owner can see what people find useful.
    What is not
    We do not try to work out who you are, and we do not try to work out which organisation you are visiting from.
    Your control
    There is nothing here to turn off: no identification is attempted for visits from your region.
    Why there is no banner
    Nothing is collected here that identifies a person or an organisation, so there is no permission to ask for.
  2. Company-level

    No permission is asked for
    What is recorded
    We record which pages are opened and when. From the network your visit arrives on, we also look up the name of the organisation that network belongs to — for example, a company's office internet connection.
    What is not
    We do not use cookies for this. We do not fingerprint your browser. We do not work out who you are as an individual, and we do not learn your name, your email address, or your job.
    Your control
    The organisation lookup uses the network you are on, not anything stored on your device, so clearing cookies will not change it. If you would rather it did not happen at all, the site's owner can switch it off for their whole site — the contact details for that are in their privacy notice.
    Why there is no banner
    This looks up an organisation, not a person, so there is no consent banner. Asking you for permission we do not need would be a false choice.
  3. Person-level

    What is recorded
    We record which pages are opened and when. For visits from the United States, we also ask a third-party data provider whether it can match this visit to a named individual, and record what it says.
    What is not
    We do not read anything you type, we do not record your screen, and we do not collect passwords or payment details. A match is a claim from a data provider, not something we have verified about you.
    Your control
    If your browser sends a Global Privacy Control signal, we do not attempt to match your visit to a named person, and we record that we did not. Most browsers offer this in their privacy settings, or through an extension. We honour it on every visit, from everywhere, without needing to work out where you are.

What is actually happening today

No outside data provider is connected to this software at the moment, so no visit is currently being matched to a named person anywhere. The levels above describe what the rules permit if one is connected later — this page is written to stay accurate when that changes, rather than to be rewritten afterwards.

What is never collected

These are not settings. The software has nowhere to put any of them.

  • Anything you type — form fields, search boxes, and message bodies are never sent.
  • Passwords and payment details.
  • A recording of your screen or the contents of the page you are looking at.
  • The web address you arrived from, beyond the site name itself. If you arrived from a search, the words you searched for are not kept.
  • Anything after the question mark in a page address, which is where sites often put an email address or a one-time link.

Cookieless, but not identifier-less

No cookie is set and your browser is not fingerprinted. The software does store a random identifier in your browser's own storage so that repeat visits to the same site can be counted as one visitor rather than several. It is a random string. It carries no name, no email address, and nothing about you.

That identifier belongs to the site you were visiting, not to this page, so no button here could remove it. Clearing site data for that site in your browser's settings clears it, and the next visit starts a fresh one.

Where you are visiting from matters

Matching a visit to a named person is only ever attempted for visitors in United States states whose rules have been reviewed for it. Everywhere else — including every European Union country, the United Kingdom, and any region nobody has reviewed — it is not attempted at all, and only the organisation behind the network may be looked up.

For visitors from South Korea, the software attempts no identification from traffic at all, at either level. Whether the law there allows an organisation to be worked out from a network address without asking first is an open legal question we have not had answered, and the system is set to the stricter reading until it is.

A region nobody has reviewed is treated the same way as one where person-level matching is not allowed: it is not attempted. An unreviewed region means nobody has checked it yet, not that anything there is known to be off-limits.

What you can control

  • Turn on Global Privacy Control

    This is the control with the most behind it. When your browser sends this signal, no attempt is made to match your visit to a named person — and the refusal is written down, so the site's owner can show it happened. It is in most browsers' privacy settings, and available as an extension for the rest.

  • Clear the site's stored identifier

    Clearing site data for the site you visited removes the random identifier described above. Your visits stop being connected to each other from that point on.

  • Ask the site's owner directly

    The owner of the site you visited decides whether to use any of this, and can switch it off for their whole site. They are the ones who can act on a request about your visit, and their own privacy notice says how to reach them. We run the software; they decide how it is used.

What this page deliberately does not offer

  • There is no consent banner here

    Working out which organisation a visit came from reads the network the visit arrived on — it identifies a company, not a person, and it uses no cookie. Asking your permission for something that does not need it would be a false choice, so we do not ask.

  • There is no button here that clears your identifier

    The identifier is stored by the site you visited, under that site's own address, and a page on this address cannot reach it. A button here would look like it worked and would not. Your browser's settings for that site can clear it.

  • There is no form here to request that you are never identified

    A standing request like that would need to be stored and checked on every future visit, and that is not built. Saying so is better than a form that accepts a request nothing acts on. Global Privacy Control is the control that works today, and the site's owner can act on a direct request.