Lawful basisLawful basis documentation
A practical summary of the processing purposes and lawful bases relevant to UserTrail.
Last updated: June 6, 2026Overview
This page documents the typical lawful bases UserTrail may rely on for its own processing and the lawful basis considerations customers should assess when using UserTrail on their websites. It is not legal advice.
Customer visitor analytics
For visitor analytics on customer websites, customers are typically the controller and must determine the lawful basis for collecting visitor behaviour data. Depending on jurisdiction and tracking configuration, this may require consent, especially where cookies or similar technologies are used for non-essential analytics.
UserTrail account and dashboard data
- Contract: to create accounts, authenticate users, provide dashboard access, manage sites, and deliver the UserTrail service.
- Legitimate interests: to secure the platform, prevent abuse, improve reliability, debug issues, and understand product usage.
- Legal obligation: to keep records required by tax, accounting, security, or legal obligations.
- Consent: where required for optional communications, optional tracking, or other processing that needs consent.
Payment and billing
- Contract: to process subscriptions, invoices, payment status, and account access.
- Legal obligation: to keep accounting, tax, and billing records.
- Legitimate interests: to prevent fraud and resolve payment disputes.
Support and contact messages
- Contract or legitimate interests: to respond to customer questions, troubleshoot issues, and maintain customer relationships.
- Legal obligation: where support records are needed to comply with legal or regulatory duties.
Security logs
- Legitimate interests: to protect accounts, detect abuse, investigate incidents, and maintain service integrity.
- Legal obligation: where security records are required by applicable law.
Customer action required
- Document your lawful basis before installing UserTrail on your website.
- Update your privacy and cookie notices to explain UserTrail tracking.
- Load tracker.js only after consent where consent is required.
- Keep records of consent and configuration decisions where applicable.
Contact
For lawful basis questions about UserTrail processing, contact info@usertrail.io.