01Who this policy covers
This policy explains how SC WORDPRESS CODE SRL, fiscal code RO41034515, trade register J40/5716/2019, registered office at Str. Grigore Cobălcescu nr. 3, corp C2, Sector 1, București 010191, Romania, the legal operator of Visiroll (“Visiroll”, “we”), handles personal data in the Visiroll video hosting, delivery, and analytics service.
It covers two different groups of people, and our role is different for each:
- Workspace members — the people who sign in to Visiroll to upload, publish, and measure video. For their account data we are the controller.
- Website visitors — the people who watch a video embedded on one of our customers’ websites. For their playback data we are a processor, acting on the instructions of the customer who published the video. That customer is the controller.
02Workspace account data
When you create a workspace or accept an invitation, we store:
- Your name, email address, and workspace name.
- Your role in the workspace: Owner, Admin, or Viewer.
- A salted scrypt hash of your password. We never store the password itself and cannot recover it.
- Sessions. Your browser receives a random token in an HttpOnly cookie; our database stores only a SHA-256 hash of it, with an expiry. Signing out or being removed from a workspace destroys the session immediately.
- Invitations, stored as a hashed single-use token with a seven-day expiry.
We use this data only to operate your workspace, authenticate you, and contact you about the service. We do not use it for advertising and we do not sell it.
03What the player records about viewers
When someone plays a video published through Visiroll, the player records playback events so the publisher can understand engagement. For each playback session we store:
- A daily pseudonymous playback identifier: a one-way value derived on our server from the website, network address, browser signature, and current UTC day. It is never written to cookies, local storage, or session storage, rotates daily, and cannot follow a viewer between client websites.
- The page address the video was embedded on, and any UTM campaign values present in that address.
- Device type, browser, and operating system, derived from the browser’s user-agent string.
- A two-letter country code, derived from trusted proxy country headers when enabled, or from a local IP-to-country lookup.
- Playback events and timings: impression, play, pause, resume, seek, heartbeats, percentage milestones, completion, replays, and fullscreen.
We use these events to produce audience statistics, not advertising profiles, and make no attempt to re-identify viewers. Pseudonymous data is not the same as anonymous data. Publishers should avoid putting personal information in page addresses or campaign values sent with playback events.
04Analytics on visiroll.com
On the Visiroll website and, only if enabled by the operator, authenticated product pages, we may use Google Analytics 4 to understand visits and improve the service. Google Analytics is an optional category and is not loaded before you consent.
- Analytics storage is denied until you choose to allow it.
- Advertising storage, advertising user data, ad personalization, Google Signals, and ad-personalization signals remain disabled.
- You can withdraw consent at any time through Cookie preferences in the footer.
- The embedded Visiroll player is excluded and remains cookie-free.
See the Cookie Policy for the specific cookies and durations.
05How playback analytics limits tracking
These safeguards apply to embedded playback analytics. Account data, uploaded content, and supporting providers are described separately in this policy.
- No raw IP addresses in playback analytics or rate-limit records. IP addresses are processed in memory for abuse prevention, country lookup, and daily pseudonymous playback identifiers. Rate-limit keys use a keyed one-way digest instead of the raw IP address.
- No cookies are set on the publisher’s website by the player, and no third-party advertising or tracking scripts are loaded.
- No cross-site or cross-client audience profiles. Daily playback identifiers are scoped to one website and rotate every UTC day. We do not link these identifiers across websites.
- No advertising profiles, no data sales, and no data sharing with ad networks or data brokers.
- No names, payment details, or biometric identifiers are requested by playback analytics. Uploaded videos may contain personal data; billing information is handled separately through Stripe.
Automated traffic — bots, crawlers, link previews, and monitoring tools — is filtered out of reporting rather than recorded as an audience.
06Video you upload
Videos, posters, thumbnails, and titles you upload remain yours. We process them only to deliver the service: validating the file, producing web-ready renditions, generating a poster and thumbnail, storing them, and serving them to the websites you authorize.
Original source files and generated playback files are private objects. Authorized player sessions receive short-lived signed media URLs; embedding remains restricted to the domains you allow.
If a video you upload contains personal data — faces, voices, names — you remain responsible for having a lawful basis to publish it.
07Where your data is stored
Primary account data, video files, and playback analytics are stored in the European Union. Our application, database, and media storage run in Frankfurt, Germany. The supporting processors listed below receive only the data necessary for their function and may apply their own documented international-transfer safeguards.
We use a small number of processors to run the service:
DigitalOceanApplication and primary media storage in Frankfurt, Germany; CDN delivery to viewers.
SimplenetTransactional email infrastructure for invitations and account notices. No marketing lists.
StripeSubscription checkout, billing, invoices, and the customer billing portal. Visiroll does not store complete payment-card details.
SentryError monitoring for the web application and worker. Default personal-data collection is disabled.
Google AnalyticsOptional measurement on Visiroll pages, loaded only after analytics consent.
Core account, video, and analytics data remains in the European Union. Optional measurement, billing, email, and error-monitoring providers process their limited service data under their own privacy terms and applicable international-transfer safeguards.
08How long we keep things
90 daysIndividual playback events
24 monthsAggregated daily and hourly statistics
7 daysOriginal uploaded source files, after successful processing
30 daysSign-in sessions, unless you sign out sooner
Deleting a video removes its stored media and its analytics data. Closing a workspace removes its accounts, clients, websites, videos, and analytics. Aggregated statistics that can no longer be connected to a person or a video may be retained for service capacity planning.
09How we protect it
- Passwords are hashed with salted scrypt; session tokens are stored only as hashes.
- Every page, action, and API call is scoped to the signed-in member’s workspace, so one customer cannot read another’s data.
- Authorized Visiroll personnel may access workspace data only when necessary for support, security, abuse investigation, legal compliance, backup recovery, or service operation, on a need-to-know basis.
- Embedding is restricted to the exact and wildcard domains each publisher configures, enforced both by the player and by frame policies.
- Uploaded originals and playback renditions remain private and require an authorized or short-lived signed request.
- Traffic is served over HTTPS with strict transport security in production.
No system is perfect. If we discover a breach affecting personal data, we will notify affected workspace owners and the competent supervisory authority as required by the GDPR.
10Your rights
Under the GDPR you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or receive it in a portable format. You can also withdraw consent where processing relies on it, and complain to your national data protection authority.
Workspace members can exercise most of these directly in the product: account details are editable in workspace settings, and Owners can remove members or permanently delete videos, clients, websites, and the workspace. A paid Stripe subscription must be cancelled and ended before self-service workspace deletion.
If you are a website visitor and want playback data about you removed, contact the website that published the video — they control that data, and we will assist them promptly. The player leaves no identifier behind in browser storage.
Write to privacy@visiroll.com for any request. We respond within 30 days.
11If you publish video with Visiroll
You decide what to publish, where it may be embedded, and how long it stays online. We process viewer data only to produce the reporting described above, and only for you.
The embedded player sets no cookies, but its analytics still processes pseudonymous playback data. Cookie-free playback is not a blanket exemption from privacy or consent requirements. Confirming what your privacy notice and consent flow must say for your jurisdiction and audience remains your responsibility — we cannot give legal advice about your website.
12Changes and contact
If we change how the service handles personal data, we will update this page and move the “last updated” date. Material changes will be announced to workspace Owners by email before they take effect.
SC WORDPRESS CODE SRL, Str. Grigore Cobălcescu nr. 3, corp C2, Sector 1, București 010191, Romania. Questions, requests, or complaints: privacy@visiroll.com. See also our Terms of Service.