Visit and acquisition
Visit time, returning-visitor and browser-session identifiers, landing page, referring site, and campaign tags such as UTM source, medium, campaign, and content.
Signal policy / 01
Club Agartha operates private visitor analytics by default to understand how people discover and use the website. Analytics records are visible only through the password-protected administrator dashboard and are not sold or shared for advertising.
Visit time, returning-visitor and browser-session identifiers, landing page, referring site, and campaign tags such as UTM source, medium, campaign, and content.
IP address, approximate city/region/country, postal area and rounded coordinates, timezone, network provider, ASN, and probabilistic VPN, proxy, Tor, datacenter, or abuse-list signals. The full IP is sent server-side to the enrichment providers named below.
User agent, browser client hints, platform, language, display and viewport dimensions, pixel ratio, orientation, CPU cores, approximate memory and heap use, touch support, WebGL GPU details, battery, connection quality, plugin names, and history length when exposed.
Color scheme, reduced-motion and contrast preferences, storage and cookie availability, data-saver state, Do Not Track, Global Privacy Control, and basic browser capabilities.
Sections viewed, labeled link and button activations, scroll milestones, visible time on site, page exits, page-load timing, Core Web Vitals, and sanitized script-error locations.
Typed text, passwords, form contents, precise GPS location, microphone or camera data, browsing activity on other sites, rendered canvas or audio fingerprint hashes, or the contents of browser storage.
The web server necessarily receives an IP address to answer a request. Before the analytics database stores its copy, the address is sealed with a public encryption key; the collection path cannot decrypt it, and decryption is available only inside the authenticated administrator path. Routine Club Agartha access logs omit client IP addresses, URL query strings, and referring URLs. Administrator sessions use secure cookies, CSRF protection, lockouts, and finite lifetimes.
A secure first-party visitor identifier can remain for up to one year, while the page-session identifier expires with the browser session. These random identifiers do not contain a name, email address, or IP address.
Detailed records are automatically deleted after 180 days. Cached IP-enrichment data is removed after 30 days. Approximate location and network enrichment is provided by ipwho.is and ipapi.is; both receive the IP address over HTTPS and apply their own privacy practices. A one-way identifier tombstone may be retained for one year to enforce an opt-out.
Your control
Checking this browser's preference...
Disabling analytics immediately records a one-year browser preference and requests deletion of records associated with the current visitor identifier. If deletion cannot be confirmed, the status above will ask you to retry while collection remains disabled locally. Global Privacy Control is honored automatically.For privacy questions or deletion requests that cannot be completed from this browser, contact Club Agartha through Instagram or TikTok.