# What Site Tracking sends and stores

> Exactly what your server sends to Ranqo for each page view, what Ranqo stores, how visitor IP addresses are handled, and what is never collected.

Source: https://ranqo.ai/docs/integrations/site-tracking/privacy

Site Tracking runs on your server, not in your visitors' browsers, so you decide exactly what leaves your site. This page lists every value that is sent, what Ranqo keeps from it, and what happens to IP addresses.

## What your server sends

For each page view it reports, the install code sends five values in one `GET` request, and nothing else about the visit:

| Value | What it is |
| --- | --- |
| `url` | The full address of the page requested, including any query string. |
| `userAgent` | The `User-Agent` header of the request. |
| `ref` | The `Referer` header: the page the visitor came from, if their browser sent one. |
| `ip` | The visitor's IP address. |
| `websiteKey` | Your site key, which tells Ranqo which brand the visit belongs to. |

No cookies, request bodies, form data or other headers are sent. The report travels from your server to Ranqo, so the visitor's browser never contacts Ranqo. There is no script on your pages and Site Tracking sets no cookie, so nothing is stored on your visitors' devices.

## What Ranqo stores for each visit

| Stored | Detail |
| --- | --- |
| Page | The full URL as sent, plus its host and path. |
| User agent | The user agent as sent. |
| Classification | The bot's name, operator and type, or that the visit was a person; and the AI assistant that referred it, if any. |
| Referrer | The referrer as sent, and its host. |
| IP address | A hash, not the address. See below. |
| Country | A two-letter country code for where the server or edge that sent the report is. See below. |
| Verification | Whether the address matched the bot operator's published ranges. |
| Time | When Ranqo recorded the visit. |

Visits belong to the brand the key belongs to.

## How IP addresses are handled

Ranqo uses the visitor's IP address for two things, and the visit record keeps a hash in its place:

1. **Verification.** For a request whose user agent claims to be a known crawler, Ranqo checks the address against the IP ranges that crawler's operator publishes, and stores the result.
2. **A hash.** Ranqo stores a SHA-256 hash of the address combined with your brand's identifier. The same address produces the same hash within your brand, which is how unique and returning visitors are counted, and a different hash in every other brand.

The hash is pseudonymous, not anonymous. Anyone holding it and your brand's identifier could recover an IPv4 address by hashing every possible address until one matches.

A raw address is also held in these places:

- **The site key's record.** It keeps the IP address and user agent of the most recent recorded visit, replaced by each new one. The dashboard's site key and traffic data requests return the address to people signed in to your account, though no page displays it.
- **Processing.** The report, raw address included, passes through Ranqo's processing queue before it is stored as a visit.
- **Request logs.** The address, like your site key, travels in the query string of each report, so it can appear in the request logs of Ranqo's hosting provider.

If you would rather not send addresses at all, send `ip` empty. Visits are still recorded and classified, but no bot visit can then be verified, and every visit carries the same hash, so unique and returning visitor counts treat them all as one visitor.

## Where the country comes from

The country is not derived from the visitor's IP address. Ranqo reads it from the location headers on the report's own request, so it is where the machine that sent the report is: your server or edge function. When the install code runs on an edge network close to the visitor, that is often the visitor's country. When it runs on one server, every visit carries that server's country.

This is the country shown in the **Live Feed**, in the install page's confirmation and on the **Countries** card of a channel's detail on the Traffic page, although that card's caption reads *Where visitors are coming from*.

## What you control

- **Query strings.** The install code sends the full URL. If your URLs can carry personal data in the query string, such as an email address in a sign-up link, send the URL without its query string: Ranqo only needs the host and path.
- **Which hosts are reported.** Add hosts you do not want tracked, such as your signed-in product, to `SKIP_HOSTS` in the install code.
- **Which pages are reported.** The install code is yours to change. Anything it does not send, Ranqo never sees.

## How long visits are kept

Recorded visits stay with the brand. The Traffic page shows as far back as your plan's history window; see [Plans and limits](https://ranqo.ai/docs/guides/plans-and-limits). To have a brand's recorded visits deleted, [contact us](https://ranqo.ai/contact).

## Related

- [Intake API](https://ranqo.ai/docs/integrations/site-tracking/intake-api): Every parameter the endpoint accepts.
- [Site Tracking](https://ranqo.ai/docs/integrations/site-tracking): How visits are classified.
