01Who this policy covers
This policy explains how Visiroll (“Visiroll”, “we”) handles personal data in the Visiroll video hosting, delivery, and analytics service.
It covers two different groups of people, and our role is different for each:
- Workspace members — the people who sign in to Visiroll to upload, publish, and measure video. For their account data we are the controller.
- Website visitors — the people who watch a video embedded on one of our customers’ websites. For their playback data we are a processor, acting on the instructions of the customer who published the video. That customer is the controller.
02Workspace account data
When you create a workspace or accept an invitation, we store:
- Your name, email address, and workspace name.
- Your role in the workspace: Owner, Admin, or Viewer.
- A salted scrypt hash of your password. We never store the password itself and cannot recover it.
- Sessions. Your browser receives a random token in an HttpOnly cookie; our database stores only a SHA-256 hash of it, with an expiry. Signing out or being removed from a workspace destroys the session immediately.
- Invitations, stored as a hashed single-use token with a seven-day expiry.
We use this data only to operate your workspace, authenticate you, and contact you about the service. We do not use it for advertising and we do not sell it.
03What the player records about viewers
When someone plays a video published through Visiroll, the player records playback events so the publisher can understand engagement. For each playback session we store:
- An anonymous visitor identifier: a random value generated in the viewer’s browser, held in browser storage, and scoped to a single website. The same person visiting two different customers’ websites is never linked across them.
- The page address the video was embedded on, and any UTM campaign values present in that address.
- Device type, browser, and operating system, derived from the browser’s user-agent string.
- A two-letter country code, derived at the network edge.
- Playback events and timings: impression, play, pause, resume, seek, heartbeats, percentage milestones, completion, replays, and fullscreen.
This produces audience statistics, not profiles. Nothing here identifies a person by name, and we make no attempt to re-identify anyone.
04What we never collect
These are properties of how the product is built, not promises about future intent.
- No IP addresses are stored. A visitor’s IP address is used in memory only to rate-limit abusive requests and is never written to our database.
- No cookies are set on the publisher’s website by the player, and no third-party advertising or tracking scripts are loaded.
- No cross-site or cross-client tracking. Visitor identifiers are scoped per website by design, so viewing behaviour cannot be correlated between customers.
- No advertising profiles, no data sales, and no data sharing with ad networks or data brokers.
- No biometric, financial, or special-category data is requested or processed by the service.
Automated traffic — bots, crawlers, link previews, and monitoring tools — is filtered out of reporting rather than recorded as an audience.
05Video you upload
Videos, posters, thumbnails, and titles you upload remain yours. We process them only to deliver the service: validating the file, producing web-ready renditions, generating a poster and thumbnail, storing them, and serving them to the websites you authorize.
Original source files are stored privately and are never publicly readable. Generated playback files are served publicly through a CDN so that browsers can play them, with embedding restricted to the domains you allow.
If a video you upload contains personal data — faces, voices, names — you remain responsible for having a lawful basis to publish it.
06Where your data is stored
All account data, video files, and analytics are stored in the European Union. Our application, database, and media storage run in Frankfurt, Germany.
We use a small number of processors to run the service:
DigitalOceanApplication hosting, media storage, and CDN delivery — EU region (Frankfurt).
Email deliveryTransactional messages only: invitations and account notices. No marketing lists.
We do not transfer personal data outside the European Economic Area for the operation of the service. If that ever changes, this page will be updated before the transfer begins.
07How long we keep things
90 daysIndividual playback events
24 monthsAggregated daily and hourly statistics
7 daysOriginal uploaded source files, after successful processing
30 daysSign-in sessions, unless you sign out sooner
Deleting a video removes its stored media and its analytics data. Closing a workspace removes its accounts, clients, websites, videos, and analytics. Aggregated statistics that can no longer be connected to a person or a video may be retained for service capacity planning.
08How we protect it
- Passwords are hashed with salted scrypt; session tokens are stored only as hashes.
- Every page, action, and API call is scoped to the signed-in member’s workspace, so one customer cannot read another’s data.
- Embedding is restricted to the exact and wildcard domains each publisher configures, enforced both by the player and by frame policies.
- Uploaded originals are private; only verified playback renditions are made public.
- Traffic is served over HTTPS with strict transport security in production.
No system is perfect. If we discover a breach affecting personal data, we will notify affected workspace owners and the competent supervisory authority as required by the GDPR.
09Your rights
Under the GDPR you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or receive it in a portable format. You can also withdraw consent where processing relies on it, and complain to your national data protection authority.
Workspace members can exercise most of these directly in the product: account details are editable in workspace settings, and Owners can remove members and delete videos, clients, and websites at any time.
If you are a website visitor and want playback data about you removed, contact the website that published the video — they control that data, and we will assist them promptly. You can also clear the anonymous identifier yourself by clearing your browser storage for that site.
Write to privacy@visiroll.com for any request. We respond within 30 days.
10If you publish video with Visiroll
You decide what to publish, where it may be embedded, and how long it stays online. We process viewer data only to produce the reporting described above, and only for you.
Because the player sets no cookies and stores no IP addresses, Visiroll is designed to be as light as possible on your consent obligations. Confirming what your own privacy notice and consent flow must say for your jurisdiction and audience remains your responsibility — we cannot give legal advice about your website.
11Changes and contact
If we change how the service handles personal data, we will update this page and move the “last updated” date. Material changes will be announced to workspace Owners by email before they take effect.
Questions, requests, or complaints: privacy@visiroll.com. See also our Terms of Service.